📦

torrentflux

Vendor: torrentflux

Actively Exploited 0 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 4 Remote Access
Total CVEs 37 Total Indexed
Avg. EPSS 2.05% Exploit Prob.
Latest CVE CVE-2014-6027 Jan 16

Security Vulnerability Index

Page 2 / 4
4.9 CVSS
CVE-2006-6329
Exploit Found

index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter.

EPSS: 2.49%
6.0 CVSS

metaInfo.php in TorrentFlux 2.2, when $cfg["enable_file_priority"] is false, allows remote attackers to execute arbitrary commands via shell metacharacters (backticks) in the torrent parameter to (1) details.php and (2) startpop.php.

EPSS: 1.23%
6.0 CVSS
CVE-2006-6330
RCE Exploit Found

index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter.

EPSS: 2.91%
4.9 CVSS
CVE-2006-6328
Exploit Found

Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the alias_file parameter.

EPSS: 2.49%
5.0 CVSS
CVE-2006-5609
Exploit Found

Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.

EPSS: 3.85%
2.6 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) file, and (3) users array variables in (a) admin.php, which are not properly handled when the administrator views the Activity Log; and the (4) torrent parameter, as used by the displayName variable, in (b) startpop.php, different vectors than CVE-2006-5227.

EPSS: 1.76%
6.8 CVSS

Cross-site scripting (XSS) vulnerability in admin.php in TorrentFlux 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the $user_agent variable, probably obtained from the User-Agent HTTP header, and possibly (2) the $ip_resolved variable.

EPSS: 1.65%