CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Torrenttrader 1Torrenttrader Classic Apr 23, 2026 Jun 22, 2009 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot...Show more |
1Torrenttrader 1Torrenttrader Classic Apr 23, 2026 Jun 22, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote attackers to (2) obtain other potentiall...Show more |
1Torrenttrader 1Torrenttrader Classic Apr 23, 2026 Jun 22, 2009 N/A· v4 N/A· v3 6.4 MEDIUM· v2 backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .g...Show more |
1Torrenttrader 1Torrenttrader Classic Apr 23, 2026 Jun 22, 2009 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the origmsg parameter to account-inbox.php; the categ parameter to (2) delre...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Title field to requests.php, related to viewrequests.p...Show more |
1Torrenttrader 1Torrenttrader Classic Apr 23, 2026 Jun 18, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple SQL injection vulnerabilities in TorrentTrader 1.08 Classic allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) wantusername parameter to account-signup.php, or the (3) receiver par...Show more |
1Torrenttrader 2Torrenttrader Torrenttrader ClassicApr 23, 2026 Mar 6, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. |
1Torrenttrader 2Torrenttrader Torrenttrader ClassicApr 23, 2026 Mar 6, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerabilities in account-inbox.php in TorrentTrader Classic 1.08 allow remote attackers to perform certain actions as other users, as demonstrated by sending messages. |