Release date:
Updated on: 2012-10-05
Affected Systems:
Rivettracker <= 1.03
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52283
Cve id: CVE-2012-4996
RivetTracker is a revision of PHPBTTracker. It is written in PHP by "DeHackEd" and uses MySQL as the database backend. It provides the bit stream tracker function.
Multiple SQL injection vulnerabilities exist in RivetTracker 1.03 and other versions. Remote attackers can exploit this vulnerability by passing parameters to dltorrent. php and torrent_functions.php using hash parameters, resulting in arbitrary SQL command execution.
<* Source: Ali Raheem
Link: http://secunia.com/advisories/48245
Http://www.exploit-db.com/exploits/18553/
Http://xforce.iss.net/xforce/xfdb/73679
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Rivettracker
------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.rivetcode.com/software/rivettracker/