CVE-2009-4928
TotalCalendar 2.4 - Remote Code Execution via inc_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4928. PoCs published by DarKdewiL.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Simpoe Event Calendar 2.4. The vulnerability allows an attacker to include a remote shell by manipulating the 'inc_dir' parameter in the 'config.php' file.
Description
PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922 and CVE-2006-7055.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Simpoe Event Calendar 2.4. The vulnerability allows an attacker to include a remote shell by manipulating the 'inc_dir' parameter in the 'config.php' file.