RSS   Vulnerabilities for 'Utorrent webui'   RSS

2009-04-03
 
CVE-2008-6586

CWE-352
 

 
Cross-site request forgery (CSRF) vulnerability in gui/index.php in ?Torrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests that force the download of arbitrary torrent files via the add-url action and (2) hijack the authentication of administrators for requests that modify the administrator account via the setsetting action.

 

 >>> Vendor: Utorrent 3 Products
Utorrent
Utorrent webui
Utorrent remote


Copyright 2024, cxsecurity.com

 

Back to Top