CVE-2006-5451

Publication date 23 October 2006

Last updated 17 July 2025


Ubuntu priority

Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) file, and (3) users array variables in (a) admin.php, which are not properly handled when the administrator views the Activity Log; and the (4) torrent parameter, as used by the displayName variable, in (b) startpop.php, different vectors than CVE-2006-5227.

Status

Package Ubuntu Release Status
torrentflux 7.10 gutsy
Fixed 2.1-7
7.04 feisty
Fixed 2.1-7
6.10 edgy
Fixed 2.1-1ubuntu0.2
6.06 LTS dapper Not in release