Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.
References
Configurations
History
20 Nov 2024, 23:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=112110868021563&w=2 - | |
References | () http://secunia.com/advisories/15983 - | |
References | () http://securitytracker.com/id?1014449 - Exploit |
Information
Published : 2005-07-12 04:00
Updated : 2024-11-20 23:59
NVD link : CVE-2005-2229
Mitre link : CVE-2005-2229
CVE.ORG link : CVE-2005-2229
JSON object : View
Products Affected
blog_torrent
- blog_torrent
CWE