PT-2014-7011 · Torrentflux · Torrentflux
Nicolas Guigo
·
Published
2014-09-05
·
Updated
2020-01-30
·
CVE-2014-6028
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
TorrentFlux version 2.4
Description
The issue allows remote authenticated users to obtain other users' cookies via the
cid parameter in an "editCookies action" to "profile.php".Recommendations
For TorrentFlux version 2.4, consider restricting access to the "profile.php" endpoint or avoiding the use of the
cid parameter in the editCookies action until a fix is available.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Torrentflux