5.1
CVSSv2

CVE-2009-2161

Published: 22/06/2009 Updated: 10/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name.

Vulnerable Product Search on Vulmon Subscribe to Product

torrenttrader torrenttrader classic 1.09

Exploits

[waraxe-2009-SA#074] - Multiple Vulnerabilities in TorrentTrader Classic 109 =============================================================================== Author: Janek Vind "waraxe" Date: 15 June 2009 Location: Estonia, Tartu Web: wwwwaraxeus/advisory-74html Description of vulnerable software: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ...