CVE-2006-5451
Torrentflux - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) file, and (3) users array variables in (a) admin.php, which are not properly handled when the administrator views the Activity Log; and the (4) torrent parameter, as used by the displayName variable, in (b) startpop.php, different vectors than CVE-2006-5227.
References (12)
Scores
EPSS
0.0168
EPSS Percentile
82.0%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
torrentflux/torrentflux
Timeline
Published
Oct 23, 2006
Tracked Since
Feb 18, 2026