Vulnerabilities
Vulnerable Software
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML by leveraging failure to encode file contents when downloading a torrent file or (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a link to torrent details.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-01-16
TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.
CVSS Score
4.0
EPSS Score
0.003
Published
2014-09-05
TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.
CVSS Score
4.9
EPSS Score
0.006
Published
2014-09-05


Contact Us

Shodan ® - All rights reserved