CVE-2008-1069
Quantum Game Library 0.7.2c - Remote Code Execution via CONFIG[gameroot] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1069. PoCs published by RoMaNcYxHaCkEr.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Quantum Game Library 0.7.2c. The vulnerability allows an attacker to include arbitrary remote files via the CONFIG[gameroot] parameter in server_request.php and smarty.inc.php.
Description
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) server_request.php and (2) qlib/smarty.inc.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Quantum Game Library 0.7.2c. The vulnerability allows an attacker to include arbitrary remote files via the CONFIG[gameroot] parameter in server_request.php and smarty.inc.php.