Re: Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability

2006-08-15 Thread Carsten Eilers
Hey Steve, Steven M. Christey schrieb am Mon, 14 Aug 2006 17:54:59 -0400: >Carsten Eilers said: > >> Take a look at the top of cal_config.inc.php: >> >> # adjust the '$calpath'. >> # hardcode it if detection does not work and comment out the remaining >> # code. >> # >> # $calpath = "C:\\PHP\\ca

Re: Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability

2006-08-14 Thread Steven M. Christey
Carsten Eilers said: > Take a look at the top of cal_config.inc.php: > > # adjust the '$calpath'. > # hardcode it if detection does not work and comment out the remaining > # code. > # > # $calpath = "C:\\PHP\\calendarix\\demo\\" ; > > $calpath = dirname(__FILE__) ; When doing post-disclosure

Re: Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability

2006-08-14 Thread Carsten Eilers
[EMAIL PROTECTED] schrieb am Sat, 12 Aug 2006 09:59:20 +: > >Solution: > > > >Sanitize Variabel $calpath in cal_config.inc.php > >- Take a look at the top of cal_config.inc.php: # adjust the '$calpath'. # hardcode it if detection does not work and

Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability

2006-08-12 Thread sh3ll
--- Calendarix 0.7 calpath Remote File Inclusion --- Author : Sh3ll Date : 2006/08/11 HomePage : http://www.sh3ll.ir Co