CVE-2006-6604: Medium severity torrentflux torrentflux vulnerability
Published Dec 15, 2006
·Updated
Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the alias parameter, a different vector than CVE-2006-6328.
Affected Software
1 affected component
TorrentFlux TorrentFlux=2.2
Event History
Dec 15, 2006
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:28 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-6604?
CVE-2006-6604 has a moderate severity rating due to its potential for unauthorized file access.
2
How do I fix CVE-2006-6604?
To fix CVE-2006-6604, you should upgrade to a patched version of TorrentFlux or implement proper input validation to sanitize the alias parameter.
3
Who is affected by CVE-2006-6604?
CVE-2006-6604 affects users of TorrentFlux version 2.2 with remote authenticated access.
4
What type of vulnerability is CVE-2006-6604?
CVE-2006-6604 is categorized as a directory traversal vulnerability.
5
Can CVE-2006-6604 be exploited remotely?
Yes, CVE-2006-6604 can be exploited remotely by authenticated users to read arbitrary files on the server.