details.php in BtiTracker before 1.4.5, when torrent viewing is disabled...
Vulnerability Description
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-5987
Credits & Attribution
No credits recorded in the NVD database.
References
- http://sourceforge.net/project/shownotes.php?release_id=552477
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38416
- http://sourceforge.net/tracker/index.php?func=detail&aid=1748243&group_id=146822&atid=766508
- http://osvdb.org/42217
- http://secunia.com/advisories/27550
- http://www.securityfocus.com/bid/26551
More from bti-tracker
View All →Affected Vendor
bti-tracker
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.