← Back

Rivettracker

rivettracker

Vendor: Rivetcode • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rivetcode
1Rivettracker
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.
1Rivetcode
1Rivettracker
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact.
1Rivetcode
1Rivettracker
Apr 23, 2026
Sep 11, 2009
N/A· v4
N/A· v3
2.1 LOW· v2
RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php.