6
CVSSv2

CVE-2006-6599

Published: 15/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the announce parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

torrentflux torrentflux 2.2

Exploits

# The variable announce in maketorrentphp is not sanitised before being used The announce # variable goes through various stages throughout the script, then it is passed as a into # an exec() function This occurs in the middle of the string which is passed to the exec() # function Therefore it is possible to stop the current stop by starting w ...