Multiple SQL injection vulnerabilities in TorrentTrader before 1.07 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) account-inbox.php, (2) account-settings.php, and possibly (3) backend/functions.php.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/36119 | vdb entry |
http://www.osvdb.org/36600 | vdb entry |
http://www.securityfocus.com/bid/25369 | vdb entry |
http://secunia.com/advisories/26504 | patch vendor advisory third party advisory |
http://www.torrenttrader.org/index.php?showtopic=6255 | |
http://www.torrenttrader.org/index.php?showtopic=5776 | |
http://www.osvdb.org/36598 | vdb entry |
http://www.osvdb.org/36599 | vdb entry |