CVE-2006-6331

Publication date 6 December 2006

Last updated 24 July 2024


Ubuntu priority

metaInfo.php in TorrentFlux 2.2, when $cfg[“enable_file_priority”] is false, allows remote attackers to execute arbitrary commands via shell metacharacters (backticks) in the torrent parameter to (1) details.php and (2) startpop.php.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
torrentflux 7.10 gutsy
Fixed 2.1-7
7.04 feisty
Fixed 2.1-7
6.10 edgy
Fixed 2.1-1ubuntu0.2
6.06 LTS dapper Not in release