6.5
CVSSv2

CVE-2006-6598

Published: 15/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux prior to 2.2 and (2) torrentflux-b4rt prior to 2.1-b4rt-972 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the path parameter, a different vector than CVE-2006-6328.

Vulnerable Product Search on Vulmon Subscribe to Product

torrentflux torrentflux-b4rt 2.1_b4rt5

torrentflux torrentflux-b4rt 2.1_b4rt6

torrentflux torrentflux-b4rt 2.1_b4rt82

torrentflux torrentflux-b4rt 2.1_b4rt83

torrentflux torrentflux-b4rt 2.1_b4rt84

torrentflux torrentflux-b4rt 2.1_b4rt95

torrentflux torrentflux-b4rt 2.1_b4rt951

torrentflux torrentflux-b4rt 2.1_b4rt8

torrentflux torrentflux-b4rt 2.1_b4rt801

torrentflux torrentflux-b4rt 2.1_b4rt91

torrentflux torrentflux-b4rt 2.1_b4rt92

torrentflux torrentflux-b4rt 2.1_b4rt96

torrentflux torrentflux-b4rt 2.1_b4rt97

torrentflux torrentflux-b4rt 2.1_b4rt3

torrentflux torrentflux-b4rt 2.1_b4rt4

torrentflux torrentflux-b4rt 2.1_b4rt802

torrentflux torrentflux-b4rt 2.1_b4rt81

torrentflux torrentflux-b4rt 2.1_b4rt93

torrentflux torrentflux-b4rt 2.1_b4rt94

torrentflux torrentflux-b4rt

torrentflux torrentflux

torrentflux torrentflux-b4rt 2.1_b4rt61

torrentflux torrentflux-b4rt 2.1_b4rt7

torrentflux torrentflux-b4rt 2.1_b4rt85

torrentflux torrentflux-b4rt 2.1_b4rt9

torrentflux torrentflux-b4rt 2.1_b4rt952

torrentflux torrentflux-b4rt 2.1_b4rt953

Exploits

#Description: #TorrentFlux fails to sanitise the variable "alias" in downloaddetailsphp This allows an #attacker to include any file they want; the contents is displayed at in the spaces provided #and the remaning data is displayed as error messages on the page Overall Torrentflux makes it #look quite nice Solution use SecurityClean() of vie ...