CVE-2012-4993

RivetTracker <1.03 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4993. PoCs published by Ali Raheem.

AI-analyzed exploit summary The writeup describes SQL injection vulnerabilities in RivetTracker <=1.03, specifically in files like dltorrent.php and torrent_functions.php, which allow arbitrary SQL queries and potential file disclosure or code execution depending on database privileges.

Description

torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact.

Exploits (1)

exploitdb WRITEUP
by Ali Raheem · textwebappsmultiple
https://www.exploit-db.com/exploits/18553

The writeup describes SQL injection vulnerabilities in RivetTracker <=1.03, specifically in files like dltorrent.php and torrent_functions.php, which allow arbitrary SQL queries and potential file disclosure or code execution depending on database privileges.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: RivetTracker <=1.03
No auth needed
Prerequisites: Access to the vulnerable RivetTracker instance · SQL injection payloads
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18553

Scores

EPSS 0.0230
EPSS Percentile 81.0%

Details

CWE
CWE-264
Status published
Products (1)
rivetcode/rivettracker < 1.03
Published Sep 19, 2012
Tracked Since Feb 18, 2026