|
|
| |
|
| |
ktorrent: arbitrary uploads, code execution
| Package(s): | ktorrent |
CVE #(s): | CVE-2008-5905
CVE-2008-5906
|
| Created: | January 27, 2009 |
Updated: | February 24, 2009 |
| Description: |
From the Ubuntu advisory:
It was discovered that KTorrent did not properly restrict access when using the
web interface plugin. A remote attacker could use a crafted http request and
upload arbitrary torrent files to trigger the start of downloads and seeding.
(CVE-2008-5905)
It was discovered that KTorrent did not properly handle certain parameters when
using the web interface plugin. A remote attacker could use crafted http
requests to execute arbitrary PHP code. (CVE-2008-5906)
|
| Alerts: |
|
( Log in to post comments)
|
|
|