4.3
CVE-2008-5905
- EPSS 2.46%
- Veröffentlicht 15.01.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:01:11
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.46% | 0.823 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504178
http://ktorrent.org/?q=node/23
http://openwall.com/lists/oss-security/2009/01/08/1
http://secunia.com/advisories/32442
http://secunia.com/advisories/32447
http://secunia.com/advisories/33675
http://secunia.com/advisories/34003
http://security.gentoo.org/glsa/glsa-200902-05.xml
http://www.securityfocus.com/bid/31927
http://www.ubuntu.com/usn/USN-711-1
http://www.vupen.com/english/advisories/2008/2911
https://bugs.gentoo.org/show_bug.cgi?id=244741
https://exchange.xforce.ibmcloud.com/vulnerabilities/46117