Release date:
Updated on: 2012-10-05
Affected Systems:
Rivettracker <= 1.03
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-4993
RivetTracker is a revision of PHPBTTracker. It is written in PHP by "DeHackEd" and uses MySQL as the database backend. It provides the bit stream tracker function.
Tor__functions.php in RivetTracker 1.03 and other versions does not properly restrict access. Multiple SQL Injection Vulnerabilities exist, which allow remote attackers to perform security attacks with unknown impact.
<* Source: Ali Raheem
Link: http://www.exploit-db.com/exploits/18553/
Http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-4993
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Rivettracker
------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.rivetcode.com/software/rivettracker/