CVE-2009-2159: Medium severity torrenttrader classic vulnerability
backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .gz file from backups/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2159?
CVE-2009-2159 is considered a high severity vulnerability due to the lack of authentication allowing unauthorized access to sensitive data.
How do I fix CVE-2009-2159?
To fix CVE-2009-2159, ensure that administrative authentication is required for access to the backup-database.php file and restrict access to the backups directory.
What software is affected by CVE-2009-2159?
CVE-2009-2159 affects TorrentTrader Classic version 1.09.
What type of attack is associated with CVE-2009-2159?
CVE-2009-2159 allows remote attackers to perform unauthorized database backup and retrieval attacks.
What is the potential impact of exploiting CVE-2009-2159?
Exploiting CVE-2009-2159 can lead to unauthorized download of sensitive database backups, compromising user data.