SB2014090502 - Multiple vulnerabilities in torrentflux.com TorrentFlux



SB2014090502 - Multiple vulnerabilities in torrentflux.com TorrentFlux

Published: September 5, 2014 Updated: August 10, 2020

Security Bulletin ID SB2014090502
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Input validation error (CVE-ID: CVE-2014-6028)

The vulnerability allows a remote #AU# to manipulate data.

TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.


2) Input validation error (CVE-ID: CVE-2014-6029)

The vulnerability allows a remote #AU# to manipulate or delete data.

TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.


Remediation

Install update from vendor's website.