Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2018-15681
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged as HTTPOnly. Due to the weak and predictable salt that is in place, an attacker who successfully steals this cookie can efficiently brute-force it to retrieve the user's cleartext password.
0
Attacker Value
Unknown
CVE-2018-15680
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsalted MD5 hashes, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack.
0
Attacker Value
Unknown
CVE-2018-15684
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictable file names, which can lead to full path disclosure and leakage of sensitive data.
0
Attacker Value
Unknown
CVE-2008-3784
Disclosure Date: August 26, 2008 (last updated October 04, 2023)
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.
0