Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2161. PoCs published by waraxe.
AI-analyzed exploit summary This is a detailed technical writeup describing multiple vulnerabilities in TorrentTrader Classic 1.09, including SQL injection, weak password generation, unauthorized database backup, and information leakage. The analysis includes code snippets, attack vectors, and exploitation techniques.
Description
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name.
Exploits (1)
This is a detailed technical writeup describing multiple vulnerabilities in TorrentTrader Classic 1.09, including SQL injection, weak password generation, unauthorized database backup, and information leakage. The analysis includes code snippets, attack vectors, and exploitation techniques.