Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BtiTracker details.ph 权限绕过漏洞
Vulnerability Description
当torrent预览在客户端被禁用时,BtiTracker 1.4.5之前的版本中的details.php存在权限绕过漏洞。远程攻击者通过一个直接请求绕过保护程序,比如(1)读取torrent任意细节(2)修改客户的torrent。
CVSS Information
N/A
Vulnerability Type
N/A