vendor:
TotalCalendar
by:
Moudi
N/A
CVSS
N/A
bSQL/LFI
N/A
CWE
Product Name: TotalCalendar
Affected Version From: 2.4
Affected Version To: 2.4
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
TotalCalendar 2.4 (bSQL/LFI) Multiples Remote Vulnerability
TotalCalendar 2.4 is vulnerable to bSQL and LFI. The vulnerable code is present in rss.php (selectedCal) and box_display.php (box). The PoC for bSQL is http://127.0.0.1/rss.php?feedBox=Upcoming_Events&action=SwitchCal&selectedCal=[bSQL] and for LFI is http://127.0.0.1/box_display.php?box=[LFI].
Mitigation:
N/A