PT-2007-5707 · Torrenttrader · Torrenttrader
Steven M. Christey
·
Published
2007-08-25
·
Updated
2009-02-05
·
CVE-2007-4536
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
TorrentTrader versions 1.07 and earlier
Description
The issue allows attackers to execute arbitrary PHP code by modifying certain files, specifically
disclaimer.txt, sponsors.txt, and banners.txt, which are used in an include call. These files are set with insecure permissions in the root directory. There is a possibility of local attack vectors that could extend the vulnerability to other files.Recommendations
For TorrentTrader versions 1.07 and earlier, consider restricting access to the
disclaimer.txt, sponsors.txt, and banners.txt files until a fix is available. As a temporary workaround, review and secure the permissions of these files to prevent unauthorized modifications. Additionally, monitor the system for any signs of local attack vectors that could exploit this issue.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Torrenttrader