TorrentTrader check.php information disclosure

torrenttrader-check-info-disclosure (51148) The risk level is classified as LowLow Risk

Description:

TorrentTrader could allow a remote attacker to obtain sensitive information, caused by missing access controls on the check.php script. By sending a direct request, a remote attacker could exploit this vulnerability to obtain the full path, directory permissions and other sensitive information.


Consequences:

Obtain Information

Remedy:

No remedy available as of May 1, 2013.

References:

  • TorrentTrader Web site: TorrentTrader.
  • [waraxe-2009-SA#074]: Multiple Vulnerabilities in TorrentTrader Classic 1.09.
  • BID-35369: TorrentTrader Classic Multiple Remote Vulnerabilities
  • CVE-2009-2160: TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote attackers to (2) obtain other potentially sensitive information via a direct request to check.php.
  • SA35456: TorrentTrader Classic Multiple Vulnerabilities

Platforms Affected:

  • TorrentTrader TorrentTrader 1.03 Classic
  • TorrentTrader TorrentTrader 1.04 Classic
  • TorrentTrader TorrentTrader 1.06 Classic
  • TorrentTrader TorrentTrader 1.07 Classic
  • TorrentTrader TorrentTrader 1.08 Classic
  • TorrentTrader TorrentTrader 1.09 Classic

Reported:

Jun 15, 2009

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email ignore thisxforceignore this@ignore thisus.ignore thisibm.comignore this

Return to the main page