MEDIUM · 6.8

CVE-2007-5987

details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the de...

Vulnerability Description

details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Bti-TrackerBti-Tracker<= 1.3.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5987?

CVE-2007-5987 is a vulnerability with a CVSS score of 6.8 (MEDIUM). details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the de...

How severe is CVE-2007-5987?

CVE-2007-5987 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5987?

Check the references section above for vendor advisories and patch information. Affected products include: Bti-Tracker Bti-Tracker.