6.4
CVSSv2

CVE-2009-2159

Published: 22/06/2009 Updated: 10/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote malicious users to create and download a backup database by making a direct request and then retrieving a .gz file from backups/.

Vulnerable Product Search on Vulmon Subscribe to Product

torrenttrader torrenttrader classic 1.09

Exploits

[waraxe-2009-SA#074] - Multiple Vulnerabilities in TorrentTrader Classic 109 =============================================================================== Author: Janek Vind "waraxe" Date: 15 June 2009 Location: Estonia, Tartu Web: wwwwaraxeus/advisory-74html Description of vulnerable software: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ...