Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (comcalendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter to (1) comcalendar.php or (2) modcalendar.php.
PHP remote file inclusion vulnerability in comcalendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter.