CVE-2006-6598: Medium severity torrentflux torrentflux-b4rt vulnerability

Published Dec 15, 2006
·
Updated

Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-972 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the path parameter, a different vector than CVE-2006-6328.

Affected Software

27 affected components
TorrentFlux torrentflux-b4rt=2.1_b4rt91
TorrentFlux torrentflux-b4rt=2.1_b4rt8
TorrentFlux torrentflux-b4rt=2.1_b4rt95
TorrentFlux torrentflux-b4rt=2.1_b4rt84
TorrentFlux torrentflux-b4rt=2.1_b4rt85
TorrentFlux torrentflux-b4rt=2.1_b4rt953
TorrentFlux torrentflux-b4rt=2.1_b4rt96
TorrentFlux torrentflux-b4rt=2.1_b4rt3
TorrentFlux torrentflux-b4rt=2.1_b4rt802
TorrentFlux torrentflux-b4rt=2.1_b4rt5
TorrentFlux TorrentFlux<=2.2
TorrentFlux torrentflux-b4rt=2.1_b4rt94
TorrentFlux torrentflux-b4rt=2.1_b4rt83
TorrentFlux torrentflux-b4rt=2.1_b4rt82
TorrentFlux torrentflux-b4rt=2.1_b4rt93
TorrentFlux torrentflux-b4rt=2.1_b4rt801
TorrentFlux torrentflux-b4rt=2.1_b4rt9
TorrentFlux torrentflux-b4rt=2.1_b4rt7
TorrentFlux torrentflux-b4rt=2.1_b4rt6
TorrentFlux torrentflux-b4rt=2.1_b4rt951
TorrentFlux torrentflux-b4rt=2.1_b4rt952
TorrentFlux torrentflux-b4rt<=2.1_b4rt971
TorrentFlux torrentflux-b4rt=2.1_b4rt4
TorrentFlux torrentflux-b4rt=2.1_b4rt81
TorrentFlux torrentflux-b4rt=2.1_b4rt61
TorrentFlux torrentflux-b4rt=2.1_b4rt92
TorrentFlux torrentflux-b4rt=2.1_b4rt97

Event History

Dec 15, 2006
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:28 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2006-6598?

CVE-2006-6598 is classified as a moderate severity vulnerability due to its potential to allow remote authenticated users to read arbitrary files.

2

How do I fix CVE-2006-6598?

To mitigate CVE-2006-6598, upgrade to TorrentFlux version 2.2 or later or apply any available security patches.

3

Who is affected by CVE-2006-6598?

CVE-2006-6598 affects versions of TorrentFlux prior to 2.2 and certain versions of torrentflux-b4rt before 2.1-b4rt-972.

4

What type of vulnerability is CVE-2006-6598?

CVE-2006-6598 is a directory traversal vulnerability that can lead to unauthorized file access.

5

Can CVE-2006-6598 be exploited remotely?

Yes, CVE-2006-6598 can be exploited remotely by authenticated users who can manipulate the path parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203