Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the alias parameter, a different vector than CVE-2006-6328.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Torrentflux | Torrentflux | 2.2 (including) | 2.2 (including) |
Torrentflux | Ubuntu | devel | * |
Torrentflux | Ubuntu | edgy | * |
Torrentflux | Ubuntu | feisty | * |
Torrentflux | Ubuntu | gutsy | * |