4.6
CVSSv2

CVE-2007-4536

Published: 25/08/2007 Updated: 05/02/2009
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

TorrentTrader 1.07 and previous versions sets insecure permissions for files in the root directory, which allows malicious users to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

torrenttrader torrenttrader