Exploit Title: Joomla spider calendar lite Remote Exploit dork: inurl:com_spidercalendar Date: [29-08-2012] Author: Daniel Barragan "D4NB4R" Twitter: @D4NB4R site: http://poisonsecurity.wordpress.com/ Vendor: http://web-dorado.com/products/spider-calendar-lite.html Version: Last License: Non-Commercial Demo: http://web-dorado.com/products/spider-calendar-lite.html Download: http://web-dorado.com/products/spider-calendar-lite.html Tested on: [Linux(bt5)-Windows(7ultimate)] Especial greetz: _84kur10_, dedalo, nav Descripcion: Spider Calendar Lite is a highly configurable Joomla extension which allows you to have multiple organized events in a calendar. You can create as many events as you need for a day. With a simple click on the date you will see the events and their descriptions recorded for that day. Usage: http:127.0.0.1/exploit.php note: Copy the following code completely and paste it in your file exploit.php Exploit: _____________________________________________________ Daniel Barragan "D4NB4R" 2012