CVE-2009-1551

Qt-cute Quickteam - Code Injection

Title source: rule

Description

Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) qte_web_path parameter to qte_web.php and the (2) qte_root parameter to bin/qte_init.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ahmadbady · textwebappsphp
https://www.exploit-db.com/exploits/8602

Scores

EPSS 0.8524
EPSS Percentile 99.4%

Details

CWE
CWE-94
Status published
Products (1)
qt-cute/quickteam 2.0
Published May 06, 2009
Tracked Since Feb 18, 2026