vendor:
phpMyBitTorrent
by:
#forkbombers@irc.smashthestack.org
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: phpMyBitTorrent
Affected Version From: 2.0.4
Affected Version To: 2.0.4
Patch Exists: Yes
Related CWE: N/A
CPE: a:phpmybittorrent:phpmybittorrent:2.0.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: *nix
2011
phpMyBitTorrent 2.0.4 SQL injection
The vulnerability exists in phpMyBitTorrent 2.0.4, which is an open source web-based BitTorrent tracker written in PHP and using a MySQL database. The vulnerability allows an attacker to inject arbitrary SQL commands via the 'id' parameter in the 'confirminvite.php' script. The attacker can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of phpMyBitTorrent.