phpMyBitTorrent Multiple Security Vulnerabilities
BID:55784
Info
phpMyBitTorrent Multiple Security Vulnerabilities
| Bugtraq ID: | 55784 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2012 12:00AM |
| Updated: | Oct 01 2012 12:00AM |
| Credit: | Janek Vind |
| Vulnerable: |
phpMyBitTorrent phpMyBitTorrent 2.0.4 |
| Not Vulnerable: | |
Discussion
phpMyBitTorrent Multiple Security Vulnerabilities
phpMyBitTorrent is prone to multiple vulnerabilities, including a local file-include vulnerability, a remote file-disclosure vulnerability, a security bypass vulnerability, multiple SQL-injection vulnerabilities, and multiple cross-site-scripting vulnerabilities.
Exploiting these issues may allow an unauthorized user to view files and execute local scripts, execute arbitrary script code, bypass certain security restrictions, access or modify data, exploit latent vulnerabilities in the underlying database, gain administrative access, steal cookie-based authentication credentials, and launch other attacks.
phpMyBitTorrent 2.0.4 is vulnerable; other versions may also be affected.
phpMyBitTorrent is prone to multiple vulnerabilities, including a local file-include vulnerability, a remote file-disclosure vulnerability, a security bypass vulnerability, multiple SQL-injection vulnerabilities, and multiple cross-site-scripting vulnerabilities.
Exploiting these issues may allow an unauthorized user to view files and execute local scripts, execute arbitrary script code, bypass certain security restrictions, access or modify data, exploit latent vulnerabilities in the underlying database, gain administrative access, steal cookie-based authentication credentials, and launch other attacks.
phpMyBitTorrent 2.0.4 is vulnerable; other versions may also be affected.
Exploit / POC
phpMyBitTorrent Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser. To exploit the cross-site scripting issue, the attacker must trick a victim into following a malicious URI.
The following example URIs and inputs are available:
Attackers can exploit these issues through a browser. To exploit the cross-site scripting issue, the attacker must trick a victim into following a malicious URI.
The following example URIs and inputs are available:
References
phpMyBitTorrent Multiple Security Vulnerabilities
References:
References:
- [waraxe-2012-SA#091] - Multiple Vulnerabilities in phpMyBitTorrent 2.04 (Janek Vind)
- phpMyBitTorrent - The BitTorrent Tracker (Geeknet)
- phpMyBitTorrent Homepage (phpMyBitTorrent)