This is a technical writeup detailing a Remote File Inclusion (RFI) vulnerability in Fatwiki (fwiki) version 1.0. The vulnerability exists in the 'datumscalc.php' and 'monatsblatt.php' files due to improper handling of the 'kal_class_path' parameter, allowing remote file inclusion.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:Fatwiki (fwiki) 1.0
No auth needed
Prerequisites:Access to the vulnerable files via HTTP · Ability to host a malicious file on a remote server