6.4
CVSSv2

CVE-2006-7159

Published: 07/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote malicious users to delete arbitrary files via ".." sequences in the TORRENTSDIR parameter in a prune action.

Vulnerable Product Search on Vulmon Subscribe to Product

bti-tracker bti-tracker 1.3.2

btitracker btitracker 1.3.2