CVE-2006-6972 Information
Feb 14, 2021
cve
Description
SQL injection in torrents.php in BtitTracker 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) by and (2) order parameters. NOTE: it is not clear whether this issue is exploitable.
Reference
http://attrition.org/pipermail/vim/2006-June/000894.html http://pridels0.blogspot.com/2006/06/btittracker-sql-injection-vuln.html http://secunia.com/advisories/20753 http://www.attrition.org/pipermail/vim/2006-June/000890.html http://www.osvdb.org/26653 http://www.securityfocus.com/bid/18549 http://www.vupen.com/english/advisories/2006/2445 https://exchange.xforce.ibmcloud.com/vulnerabilities/27216
Share on: