Torrentflux · Torrentflux · CVE-2006-5609
Name of the Vulnerable Software and Affected Versions:
TorrentFlux version 2.1
Description:
A directory traversal issue exists, allowing remote attackers to list arbitrary directories. This is achieved by using "../" sequences in the `dir` parameter of the `/dir.php` endpoint.
Recommendations:
For TorrentFlux version 2.1, consider restricting access to the `dir.php` file until a patch is available, or apply configuration changes to prevent directory traversal attacks.