CVE-2006-6598
TorrentFlux < 2.2 and torrentflux-b4rt < 2.1-b4rt-972 - Authenticated Directory Traversal via Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6598. PoCs published by r0ut3r.
AI-analyzed exploit summary This exploit leverages a local file inclusion vulnerability in TorrentFlux 2.2 via the 'alias' parameter in downloaddetails.php to expose database credentials stored in config.php. It requires authentication and uses a valid session cookie to access sensitive information.
Description
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-972 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the path parameter, a different vector than CVE-2006-6328.
Exploits (1)
This exploit leverages a local file inclusion vulnerability in TorrentFlux 2.2 via the 'alias' parameter in downloaddetails.php to expose database credentials stored in config.php. It requires authentication and uses a valid session cookie to access sensitive information.