CVE-2008-6586: CSRF
Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests that force the download of arbitrary torrent files via the add-url action and (2) hijack the authentication of administrators for requests that modify the administrator account via the setsetting action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6586?
CVE-2008-6586 is considered a moderate severity vulnerability due to its potential to allow unauthorized actions via cross-site request forgery.
How do I fix CVE-2008-6586?
To fix CVE-2008-6586, upgrade to a version of uTorrent WebUI that is not vulnerable to this CSRF attack.
What are the main risks associated with CVE-2008-6586?
The main risks of CVE-2008-6586 include unauthorized downloading of torrent files and potential access to administrative functions.
Who is affected by CVE-2008-6586?
CVE-2008-6586 affects users of uTorrent WebUI version 0.315.
What type of vulnerability is CVE-2008-6586?
CVE-2008-6586 is classified as a cross-site request forgery (CSRF) vulnerability.