CVE-2006-6331

Publication date 6 December 2006

Last updated 17 July 2025


Ubuntu priority

metaInfo.php in TorrentFlux 2.2, when $cfg["enable_file_priority"] is false, allows remote attackers to execute arbitrary commands via shell metacharacters (backticks) in the torrent parameter to (1) details.php and (2) startpop.php.

Status

Package Ubuntu Release Status
torrentflux 7.10 gutsy
Fixed 2.1-7
7.04 feisty
Fixed 2.1-7
6.10 edgy
Fixed 2.1-1ubuntu0.2
6.06 LTS dapper Not in release