Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbitrary files via .. sequences in the TORRENTSDIR parameter in a prune action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bti-tracker | Bti-tracker | 1.3.2 (including) | 1.3.2 (including) |
Btitracker | Btitracker | 1.3.2 (including) | 1.3.2 (including) |