SB2014090502 - Multiple vulnerabilities in torrentflux.com TorrentFlux
Published: September 5, 2014 Updated: August 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2014-6028)
The vulnerability allows a remote #AU# to manipulate data.
TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.
2) Input validation error (CVE-ID: CVE-2014-6029)
The vulnerability allows a remote #AU# to manipulate or delete data.
TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.
Remediation
Install update from vendor's website.