Lucene search

K
cveMitreCVE-2009-2156
HistoryJun 22, 2009 - 7:30 p.m.

CVE-2009-2156

2009-06-2219:30:00
CWE-79
mitre
web.nvd.nist.gov
29
cve
2009
2156
xss
vulnerabilities
torrenttrader classic 1.09
remote authenticated users
remote attackers

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

51.5%

Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Title field to requests.php, related to viewrequests.php; and (2) the Torrent Name field to torrents-upload.php, related to the logging of torrent uploads; and allow remote attackers to inject arbitrary web script or HTML via (3) the ttversion parameter to themes/default/footer.php, the (4) SITENAME and (5) CURUSER[username] parameters to themes/default/header.php, (6) the todayactive parameter to visitorstoday.php, (7) the activepeople parameter to visitorsnow.php, (8) the faq_categ[999][title] parameter to faq.php, and (9) the keepget parameter to torrents-details.php.

Affected configurations

Nvd
Node
torrenttradertorrenttrader_classicMatch1.09
VendorProductVersionCPE
torrenttradertorrenttrader_classic1.09cpe:2.3:a:torrenttrader:torrenttrader_classic:1.09:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

51.5%

Related for CVE-2009-2156