Torrenttrader Project maintains a narrowly scoped torrent-tracker application with a small vulnerability footprint centered on cryptographic and randomness-handling weaknesses such as the use of insufficiently random values. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Torrenttrader Project over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2158HIGH account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a b | Jun 22, 2009 | 7.5 | 29 | NO | YES |
CVE-2007-5311HIGH Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote attackers to include and execute arbitrary local files via a .. | Oct 9, 2007 | 7.5 | 29 | NO | YES |
CVE-2008-6418HIGH SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the info_hash parameter. | Mar 6, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-4494HIGH SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id paramet | Oct 9, 2008 | 7.5 | 28 | NO | YES |
CVE-2009-2159MEDIUM backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a | Jun 22, 2009 | 6.4 | 26 | NO | YES |
CVE-2009-2157MEDIUM Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the origmsg parameter to account-inb | Jun 22, 2009 | 6.5 | 26 | NO | YES |
CVE-2009-2161MEDIUM Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and exe | Jun 22, 2009 | 5.1 | 23 | NO | YES |
CVE-2009-2160MEDIUM TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote | Jun 22, 2009 | 5.0 | 23 | NO | YES |
CVE-2007-4435HIGH Multiple SQL injection vulnerabilities in TorrentTrader before 1.07 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) account-inbox.php, (2 | Aug 20, 2007 | 7.5 | 22 | NO | NO |
CVE-2008-1173MEDIUM Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | Mar 6, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Torrenttrader Project.
Media articles that mention a CVE ID that affects a product developed by Torrenttrader Project — matched by CVE ID, not by vendor name.