Vulnerabilities > Torrentflux Project > Torrentflux > 2.4

DATE CVE VULNERABILITY TITLE RISK
2018-01-16 CVE-2014-6027 Cross-site Scripting vulnerability in Torrentflux Project Torrentflux 2.4
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML by leveraging failure to encode file contents when downloading a torrent file or (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a link to torrent details.
4.3
2014-09-05 CVE-2014-6029 Improper Input Validation vulnerability in Torrentflux Project Torrentflux 2.4
TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.
4.9
2014-09-05 CVE-2014-6028 Improper Input Validation vulnerability in Torrentflux Project Torrentflux 2.4
TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.
network
low complexity
torrentflux-project CWE-20
4.0