CVE-2007-4536: Medium severity TorrentTrader TorrentTrader vulnerability
TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4536?
CVE-2007-4536 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2007-4536?
To fix CVE-2007-4536, update to a version of TorrentTrader later than 1.07 that addresses the insecure file permissions.
What are the affected versions of TorrentTrader for CVE-2007-4536?
CVE-2007-4536 affects TorrentTrader versions 1.07 and earlier.
What files are involved in the CVE-2007-4536 vulnerability?
The files involved in CVE-2007-4536 include disclaimer.txt, sponsors.txt, and banners.txt.
Can CVE-2007-4536 be exploited locally?
Yes, there might be local attack vectors that can exploit CVE-2007-4536 in addition to remote attacks.