TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2007-08-25T00:00:00
Updated: 2024-08-07T15:01:09.859Z
Reserved: 2007-08-24T00:00:00
Link: CVE-2007-4536
Vulnrichment
No data.
NVD
Status : Modified
Published: 2007-08-25T00:17:00.000
Modified: 2024-11-21T00:35:49.840
Link: CVE-2007-4536
Redhat
No data.