CVE-2008-6103
a4desk Flash Event Calendar - Remote Code Execution via index.php v Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6103. PoCs published by Lo$er.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in A4Desk Event Calendar due to insufficient sanitization of user-supplied input in the 'v' parameter. An attacker can include remote files, potentially leading to remote code execution.
Description
PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the v parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in A4Desk Event Calendar due to insufficient sanitization of user-supplied input in the 'v' parameter. An attacker can include remote files, potentially leading to remote code execution.