Vulnerability Description
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Btitracker Project | Btitracker | <= 1.4.7 |
| Xbtitracker Project | Xbtitracker | <= 2.0.542 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/31556Third Party Advisory
- http://securityreason.com/securityalert/4186Third Party Advisory
- http://www.btiteam.org/Broken Link
- http://www.btiteam.org/smf/index.php?topic=12068Broken Link
- http://www.securityfocus.com/bid/30811ExploitThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44627Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/6296ExploitThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/31556Third Party Advisory
- http://securityreason.com/securityalert/4186Third Party Advisory
- http://www.btiteam.org/Broken Link
- http://www.btiteam.org/smf/index.php?topic=12068Broken Link
- http://www.securityfocus.com/bid/30811ExploitThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44627Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/6296ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2008-3784?
CVE-2008-3784 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.
How severe is CVE-2008-3784?
CVE-2008-3784 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3784?
Check the references section above for vendor advisories and patch information. Affected products include: Btitracker Project Btitracker, Xbtitracker Project Xbtitracker.