CVE-2009-2161: Path Traversal
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ssuri parameter, in conjunction with a modified component name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2161?
CVE-2009-2161 is considered a high severity vulnerability due to its potential to allow remote file inclusion.
How do I fix CVE-2009-2161?
To fix CVE-2009-2161, upgrade to a newer version of TorrentTrader that addresses this vulnerability.
What is affected by CVE-2009-2161?
CVE-2009-2161 affects TorrentTrader Classic version 1.09 when used on case-insensitive file systems.
What type of attack is possible through CVE-2009-2161?
CVE-2009-2161 allows attackers to execute arbitrary local files via directory traversal techniques.
Is CVE-2009-2161 a common vulnerability?
CVE-2009-2161 is documented in several security databases, indicating that it is recognized and potentially exploited in the wild.