CVE-2014-6028: Input Validation
Published Aug 28, 2014
·Updated
TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.
Affected Software
1 affected component
Torrentflux Project Torrentflux=2.4
Event History
Aug 28, 2014
Data Sourced
05:48 PM
SeverityAffected Software
Sep 5, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6028?
CVE-2014-6028 is classified as a medium severity vulnerability due to its potential impact on user privacy.
2
How do I fix CVE-2014-6028?
To fix CVE-2014-6028, update to a newer version of TorrentFlux that addresses this vulnerability.
3
Who is affected by CVE-2014-6028?
CVE-2014-6028 affects users of TorrentFlux version 2.4 who are remotely authenticated.
4
What type of vulnerability is CVE-2014-6028?
CVE-2014-6028 is a vulnerability that allows remote authenticated users to access other users' cookies.
5
Is there a patch available for CVE-2014-6028?
A patch for CVE-2014-6028 can be obtained by upgrading to a version of TorrentFlux that fixes the issue.