CVE-2014-6027: XSS
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML by leveraging failure to encode file contents when downloading a torrent file or (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a link to torrent details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6027?
CVE-2014-6027 has a moderate severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-6027?
To fix CVE-2014-6027, update TorrentFlux to a version that addresses the known XSS vulnerabilities.
What versions of TorrentFlux are affected by CVE-2014-6027?
CVE-2014-6027 affects TorrentFlux version 2.4.
Who can exploit CVE-2014-6027?
Both remote attackers and authenticated users can exploit CVE-2014-6027 to inject malicious scripts.
What types of attacks can be performed using CVE-2014-6027?
CVE-2014-6027 can be used to perform cross-site scripting (XSS) attacks.