6.5
CVSSv2

CVE-2006-6604

Published: 15/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the alias parameter, a different vector than CVE-2006-6328.

Vulnerable Product Search on Vulmon Subscribe to Product

torrentflux torrentflux 2.2

Exploits

#Description: #TorrentFlux fails to sanitise the variable "alias" in downloaddetailsphp This allows an #attacker to include any file they want; the contents is displayed at in the spaces provided #and the remaning data is displayed as error messages on the page Overall Torrentflux makes it #look quite nice Solution use SecurityClean() of vie ...