Vulnerabilities > CVE-2006-6328 - Directory Traversal vulnerability in Torrentflux 2.2

047910
CVSS 4.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
torrentflux
exploit available

Summary

Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the alias_file parameter.

Vulnerable Configurations

Part Description Count
Application
Torrentflux
1

Exploit-Db

descriptionTorrentFlux <= 2.2 (Create/Exec/Delete) Multiple Remote Vulnerabilities. CVE-2006-6328,CVE-2006-6329,CVE-2006-6330. Webapps exploit for php platform
fileexploits/php/webapps/2786.txt
idEDB-ID:2786
last seen2016-01-31
modified2006-11-15
platformphp
port
published2006-11-15
reporterr0ut3r
sourcehttps://www.exploit-db.com/download/2786/
titletorrentflux <= 2.2 create/exec/delete Multiple Vulnerabilities
typewebapps