TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote attackers to (2) obtain other potentially sensitive information via a direct request to check.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Torrenttrader_classic | Torrenttrader | 1.09 (including) | 1.09 (including) |