Vulnerabilities > Rivetcode

DATE CVE VULNERABILITY TITLE RISK
2012-09-19 CVE-2012-4996 SQL Injection vulnerability in Rivetcode Rivettracker 0.1/0.8/1.03
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.
network
low complexity
rivetcode CWE-89
7.5
2012-09-19 CVE-2012-4993 Permissions, Privileges, and Access Controls vulnerability in Rivetcode Rivettracker 1.03
torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact.
network
low complexity
rivetcode CWE-264
7.5
2009-09-11 CVE-2008-7207 Cryptographic Issues vulnerability in Rivetcode Rivettracker 0.1
RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php.
local
low complexity
rivetcode CWE-310
2.1