{"api_version":"1","generated_at":"2026-07-23T06:56:40+00:00","cve":"CVE-2005-2229","urls":{"html":"https://cve.report/CVE-2005-2229","api":"https://cve.report/api/cve/CVE-2005-2229.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2229","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2229"},"summary":{"title":"CVE-2005-2229","description":"Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-07-12 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=112110868021563&w=2","name":"http://marc.info/?l=bugtraq&m=112110868021563&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'blogtorrent remote/local user password disclosure' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/15983","name":"http://secunia.com/advisories/15983","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Blog Torrent User Credentials Disclosure Security Issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1014449","name":"http://securitytracker.com/id?1014449","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SecurityTracker.com Archives - Blog Torrent May Disclose Hashed Password to Remote Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2229","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2229","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2229","vulnerable":"1","versionEndIncluding":"0.92","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"blog_torrent","cpe5":"blog_torrent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:22:47.746Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15983","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15983"},{"name":"20050711 blogtorrent remote/local user password disclosure","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112110868021563&w=2"},{"name":"1014449","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014449"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15983","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15983"},{"name":"20050711 blogtorrent remote/local user password disclosure","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112110868021563&w=2"},{"name":"1014449","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014449"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2229","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15983","refsource":"SECUNIA","url":"http://secunia.com/advisories/15983"},{"name":"20050711 blogtorrent remote/local user password disclosure","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112110868021563&w=2"},{"name":"1014449","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014449"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2229","datePublished":"2005-07-12T04:00:00.000Z","dateReserved":"2005-07-12T00:00:00.000Z","dateUpdated":"2024-08-07T22:22:47.746Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-07-12 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:blog_torrent:blog_torrent:*:*:*:*:*:*:*:*","versionEndIncluding":"0.92","matchCriteriaId":"4939AA5A-D6D8-4DAA-91F8-D12C7CEAE37B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2229","Ordinal":"1","Title":"CVE-2005-2229","CVE":"CVE-2005-2229","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2229","Ordinal":"1","NoteData":"Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.","Type":"Description","Title":"CVE-2005-2229"},{"CveYear":"2005","CveId":"2229","Ordinal":"2","NoteData":"2005-07-12","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2229","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}