CVE-2006-6330

TorrentFlux 2.2 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6330. PoCs published by r0ut3r.

AI-analyzed exploit summary This exploit demonstrates arbitrary file creation, overwrite, deletion, and command execution in TorrentFlux 2.2 via unsanitized parameters. It leverages the 'alias_file', 'delfile', and 'kill' parameters to manipulate files and execute commands.

Description

index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by r0ut3r · textwebappsphp
https://www.exploit-db.com/exploits/2786

This exploit demonstrates arbitrary file creation, overwrite, deletion, and command execution in TorrentFlux 2.2 via unsanitized parameters. It leverages the 'alias_file', 'delfile', and 'kill' parameters to manipulate files and execute commands.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: TorrentFlux 2.2
Auth required
Prerequisites: Registered member access to index.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2786
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22880

Scores

EPSS 0.0277
EPSS Percentile 84.4%

Details

Status published
Products (1)
torrentflux/torrentflux 2.2
Published Dec 06, 2006
Tracked Since Feb 18, 2026