Required CVE Record Information
Description
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the announce parameter.
References 4 Total
- secunia.com: 23270 third-party-advisory
- securityfocus.com: 21526 vdb-entry
- exploit-db.com: 2903 exploit
- exchange.xforce.ibmcloud.com: torrentflux-maketorrent-command-execution(30850) vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- secunia.com: 23270 third-party-advisoryx_transferred
- securityfocus.com: 21526 vdb-entryx_transferred
- exploit-db.com: 2903 exploitx_transferred
- exchange.xforce.ibmcloud.com: torrentflux-maketorrent-command-execution(30850) vdb-entryx_transferred