Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-6418

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2008-6418
Last Modified 14 Apr 2009 01:40:42
Published 06 Mar 2009 01:30:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-6418

Summary

SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.

Vulnerable Systems

Application

  • Torrenttrader 1.0

  • Torrenttrader 1.06

  • Torrenttrader 1.07

  • Torrenttrader 1.08


References

BID - 29451

CONFIRM - http://sourceforge.net/project/shownotes.php?group_id=98584&release_id=545219

XF - torrenttrader-scrape-sql-injection(42785)

BUGTRAQ - 20080531 SQL Injection leading to authorization bypass in Torrent Trader Classic v1.08 and earlier

SECUNIA - 30480

OSVDB - 45858


Last Updated: 27 May 2016 10:49:10