BtitTracker Arbitrary File Deletion Vulnerabilities
BID:20422
Info
BtitTracker Arbitrary File Deletion Vulnerabilities
| Bugtraq ID: | 20422 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-7159 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Discovery is credited to Gu1ll4um3r0m41n. |
| Vulnerable: |
BtitTracker BtitTracker 1.3.2 |
| Not Vulnerable: | |
Discussion
BtitTracker Arbitrary File Deletion Vulnerabilities
BtitTracker is affected by arbitrary file deletion vulnerabilities. The issues arise due to input validation errors allowing an attacker to delete files in the context of a Web server running the application
It is reported that by passing malicious input to various parameters of the 'prune_torrents.php' and 'prune_users.php' scripts an attacker can delete arbitrary files.
BtitTracker version 1.3.2 is affected by this issue. Other versions may be affected as well.
BtitTracker is affected by arbitrary file deletion vulnerabilities. The issues arise due to input validation errors allowing an attacker to delete files in the context of a Web server running the application
It is reported that by passing malicious input to various parameters of the 'prune_torrents.php' and 'prune_users.php' scripts an attacker can delete arbitrary files.
BtitTracker version 1.3.2 is affected by this issue. Other versions may be affected as well.
Exploit / POC
BtitTracker Arbitrary File Deletion Vulnerabilities
This vulnerability could be exploited though a web browser.
This vulnerability could be exploited though a web browser.
Solution / Fix
BtitTracker Arbitrary File Deletion Vulnerabilities
Solution:
The vendor has provided a fix to address this issue. Please see the references for more information.
Solution:
The vendor has provided a fix to address this issue. Please see the references for more information.
References
BtitTracker Arbitrary File Deletion Vulnerabilities
References:
References:
- [FIX] Security hole (BtitTracker)
- BtitTracker Homepage (BtitTracker)
- BtitTracker Security Issue (BtitTracker)