vendor:
Torrential
by:
Unknown
5.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Torrential
Affected Version From: 1.2
Affected Version To: 1.2 (other versions may also be vulnerable)
Patch Exists: NO
Related CWE: Unknown
CPE: a:torrential_project:torrential:1.2
Platforms Tested:
Unknown
Torrential Directory Traversal Vulnerability
The vulnerability allows an attacker to retrieve arbitrary remote PHP code on an affected computer with the privileges of the Web server process by exploiting a lack of proper sanitization of user-supplied input.
Mitigation:
Apply proper input validation and sanitization to prevent directory traversal attacks. Limit access to sensitive directories and files.