7.5
CVSSv2

CVE-2012-4996

Published: 19/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in RivetTracker 1.03 and previous versions allow remote malicious users to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.

Vulnerable Product Search on Vulmon Subscribe to Product

rivetcode rivettracker 0.1

rivetcode rivettracker

rivetcode rivettracker 0.8

Exploits

# Exploit Title: Multiple SQL injections in rivettracker <=103 # Date: 2/3/2012 # Author: Ali Raheem # Software Link: wwwrivetcodecom/software/rivettracker/ # Version: <=103 # Tested on: Linux guruplug-debian 317 #2 PREEMPT Tue Jan 3 20:19:54 MST 2012 armv5tel GNU/Linux # Greets: spyware, dividead RivetTracker is a php base torr ...