TorrentTrader 1.07 and previous versions sets insecure permissions for files in the root directory, which allows malicious users to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
torrenttrader torrenttrader |