VendorsTorrenttradertorrenttrader_classic1.08
Vulnerabilities

Torrenttrader Torrenttrader Classic 1.08

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2008-2428
Multiple SQL injection vulnerabilities in TorrentTrader 1.08 Classic allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) wantusername parameter to account-signup.php, or the (3) receiver parameter to account-inbox.php in a msg action.
Published 2008-06-18 · Modified
6.8EPSS 0.012
CVE-2008-1173
Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
Published 2008-03-06 · Modified
4.31 PoCEPSS 0.015
CVE-2008-1172
Cross-site request forgery (CSRF) vulnerabilities in account-inbox.php in TorrentTrader Classic 1.08 allow remote attackers to perform certain actions as other users, as demonstrated by sending messages.
Published 2008-03-06 · Modified
4.3EPSS 0.005