Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2014-6027

Disclosure Date: January 16, 2018 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML by leveraging failure to encode file contents when downloading a torrent file or (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a link to torrent details.
0
Attacker Value
Unknown

CVE-2014-6029

Disclosure Date: September 05, 2014 (last updated October 05, 2023)
TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.
0
Attacker Value
Unknown

CVE-2014-6028

Disclosure Date: September 05, 2014 (last updated October 05, 2023)
TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.
0