Required CVE Record Information
Description
TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.
References 4 Total
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759573
- openwall.com: [oss-security] 20140829 RE: CVE requests for 2 separate vulns in torrentflux 2.4.5-1 (debian stable) mailing-list
- securitytracker.com: 1030791 vdb-entry
- openwall.com: [oss-security] 20140902 Re: CVE requests for 2 separate vulns in torrentflux 2.4.5-1 (debian stable) mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759573 x_transferred
- openwall.com: [oss-security] 20140829 RE: CVE requests for 2 separate vulns in torrentflux 2.4.5-1 (debian stable) mailing-listx_transferred
- securitytracker.com: 1030791 vdb-entryx_transferred
- openwall.com: [oss-security] 20140902 Re: CVE requests for 2 separate vulns in torrentflux 2.4.5-1 (debian stable) mailing-listx_transferred