CVE-2009-2159

TorrentTrader Classic 1.09 - Info Disclosure

Title source: llm

Description

backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .gz file from backups/.

Exploits (1)

exploitdb WRITEUP VERIFIED
by waraxe · textwebappsphp
https://www.exploit-db.com/exploits/8958

Scores

EPSS 0.0674
EPSS Percentile 91.1%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

torrenttrader/torrenttrader_classic

Timeline

Published Jun 22, 2009
Tracked Since Feb 18, 2026