Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3mm-v27g-fw8w

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.

details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.

EPSS

Процентиль: 64%
0.00469
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 18 лет назад

details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.

EPSS

Процентиль: 64%
0.00469
Низкий

Дефекты

CWE-287