Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
metaInfo.php in TorrentFlux 2.2, when $cfg["enable_file_priority"] is false, allows remote attackers to execute arbitrary commands via shell metacharacters (backticks) in the torrent parameter to (1) details.php and (2) startpop.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TorrentFlux 'metalnfo.php'任意命令执行漏洞
Vulnerability Description
TorrentFlux 2.2中的metalnfo.php存在任意命令执行漏洞,当$cfg["enable_file_priority"]是false时,远程攻击者可以通过传给(1)details.php和(2)startpop.php的torrent参数内的shell元字符(backticks)来执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A