← Back

CVE-2006-6331

nvd nist
Published: Dec 6, 2006Modified: Apr 23, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

metaInfo.php in TorrentFlux 2.2, when $cfg["enable_file_priority"] is false, allows remote attackers to execute arbitrary commands via shell metacharacters (backticks) in the torrent parameter to (1) details.php and (2) startpop.php.

Affected (1)

1 product
Torrentflux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.2

Timeline

No history available yet.