Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
开源软件 BlogTorrent 信息泄露漏洞
Vulnerability Description
Blog Torrent是一套BT资源网站系统。 Blog Torrent 0.92及之前版本存在信息泄露漏洞。 由于将敏感文件存储在Web文档根目录下的data或torrents目录中,又缺乏充分的访问控制,使得远程攻击者可获取帐户名和密码Hash之类的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A