Torrenttrader
11 CVEs tracked since 2007. Since Aug 2007, none of them reached CISA KEV.
Torrenttrader CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2007-08 | 2 | 0 |
| 2007-09 | null or fewer | |
| 2007-10 | 2 | 0 |
| 2007-11 | null or fewer | |
| 2007-12 | null or fewer | |
| 2008-01 | null or fewer | |
| 2008-02 | null or fewer | |
| 2008-03 | 2 | 0 |
| 2008-04 | null or fewer | |
| 2008-05 | null or fewer | |
| 2008-06 | null or fewer | |
| 2008-07 | null or fewer | |
| 2008-08 | null or fewer | |
| 2008-09 | null or fewer | |
| 2008-10 | null or fewer | |
| 2008-11 | null or fewer | |
| 2008-12 | null or fewer | |
| 2009-01 | null or fewer | |
| 2009-02 | null or fewer | |
| 2009-03 | null or fewer | |
| 2009-04 | null or fewer | |
| 2009-05 | null or fewer | |
| 2009-06 | 5 | 0 |
Products
The products that kept showing up in Torrenttrader's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Torrenttrader.
- CVE-2009-2161Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary lo...5.1
- CVE-2009-2156Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Title field to requests.php, re...3.5
- CVE-2009-2159backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request a...6.4
- CVE-2009-2160TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote attackers to (2) ...5.0
- CVE-2009-2157Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the origmsg parameter to account-inbox.php; the categ...6.5
- CVE-2008-6418SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.7.5
- CVE-2008-4494SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.7.5
- CVE-2008-2428Multiple SQL injection vulnerabilities in TorrentTrader 1.08 Classic allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) wantusername parameter to account-signup.php, ...6.8
- CVE-2008-1172Cross-site request forgery (CSRF) vulnerabilities in account-inbox.php in TorrentTrader Classic 1.08 allow remote attackers to perform certain actions as other users, as demonstrated by sending mes...4.3
- CVE-2008-1173Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.4.3
- CVE-2007-5312Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) color parameter to pjirc/css.php and the (2) cat pa...4.3
- CVE-2007-5311Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the...7.5
- CVE-2007-4831Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title para...2.6
- CVE-2007-4536TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and...4.6
- CVE-2007-4435Multiple SQL injection vulnerabilities in TorrentTrader before 1.07 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) account-inbox.php, (2) account-setting...7.5
The record
- Peak rank
- #17 in Jun 2009
- Busiest month shown
- Jun 2009, 5 CVEs
- Months with a KEV entry
- 0 since Aug 2007
- Monthly snapshots
- 4 since 2007