Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2006-6328
Disclosure Date: December 06, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the alias_file parameter.
0
Attacker Value
Unknown
CVE-2006-6330
Disclosure Date: December 06, 2006 (last updated October 04, 2023)
index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter.
0
Attacker Value
Unknown
CVE-2006-6331
Disclosure Date: December 06, 2006 (last updated October 04, 2023)
metaInfo.php in TorrentFlux 2.2, when $cfg["enable_file_priority"] is false, allows remote attackers to execute arbitrary commands via shell metacharacters (backticks) in the torrent parameter to (1) details.php and (2) startpop.php.
0
Attacker Value
Unknown
CVE-2006-6329
Disclosure Date: December 06, 2006 (last updated October 04, 2023)
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter.
0
Attacker Value
Unknown
CVE-2006-5609
Disclosure Date: October 30, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.
0
Attacker Value
Unknown
CVE-2006-5451
Disclosure Date: October 23, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) file, and (3) users array variables in (a) admin.php, which are not properly handled when the administrator views the Activity Log; and the (4) torrent parameter, as used by the displayName variable, in (b) startpop.php, different vectors than CVE-2006-5227.
0
Attacker Value
Unknown
CVE-2006-5227
Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin.php in TorrentFlux 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the $user_agent variable, probably obtained from the User-Agent HTTP header, and possibly (2) the $ip_resolved variable.
0