PHP remote file inclusion vulnerability in comcalendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter.
Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (comcalendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter to (1) comcalendar.php or (2) modcalendar.php.