Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6330. PoCs published by r0ut3r.
AI-analyzed exploit summary This exploit demonstrates arbitrary file creation, overwrite, deletion, and command execution in TorrentFlux 2.2 via unsanitized parameters. It leverages the 'alias_file', 'delfile', and 'kill' parameters to manipulate files and execute commands.
Description
index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter.
Exploits (1)
This exploit demonstrates arbitrary file creation, overwrite, deletion, and command execution in TorrentFlux 2.2 via unsanitized parameters. It leverages the 'alias_file', 'delfile', and 'kill' parameters to manipulate files and execute commands.