Vulnerabilities > CVE-2007-3505 - Local File Include vulnerability in Qt-Cute Quicktalk Forum 1.3
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php. Successful exploitation requires that "magic_quotes_gpc" is disabled.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | QuickTalk forum 1.3 (lang) Local File Inclusion Vulnerabilities. CVE-2007-3505. Webapps exploit for php platform |
file | exploits/php/webapps/4115.txt |
id | EDB-ID:4115 |
last seen | 2016-01-31 |
modified | 2007-06-27 |
platform | php |
port | |
published | 2007-06-27 |
reporter | Katatafish |
source | https://www.exploit-db.com/download/4115/ |
title | QuickTalk forum 1.3 lang Local File Inclusion Vulnerabilities |
type | webapps |