PT-2006-6169 · Torrentflux · Torrentflux
Published
2006-10-23
·
Updated
2018-10-17
·
CVE-2006-5451
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
TorrentFlux version 2.1
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via specific variables in certain PHP files. The variables
action, file, and users array in admin.php are not properly handled when the administrator views the Activity Log. Additionally, the torrent parameter, used by the displayName variable in startpop.php, is vulnerable. This enables attackers to execute malicious scripts when these parameters are viewed by an administrator.Recommendations
For TorrentFlux version 2.1, update the software to a version that properly sanitizes user input in the
action, file, and users variables in admin.php and the torrent parameter in startpop.php. As a temporary workaround, consider restricting access to admin.php and startpop.php to minimize the risk of exploitation. Avoid using the action, file, and users variables in admin.php and the torrent parameter in startpop.php until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Torrentflux