CVE-2012-4996 Information

Description

Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.

Reference

http://secunia.com/advisories/48245 http://www.exploit-db.com/exploits/18553 http://www.osvdb.org/79805 http://www.osvdb.org/79806 http://www.securityfocus.com/bid/52283 https://exchange.xforce.ibmcloud.com/vulnerabilities/73679

Share on: