CVE-2007-4536
Last modified
CVE-2007-4536 is a vulnerability of currently unknown severity. TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Torrenttrader | Torrenttrader | <= 1.07 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4536?
How severe is CVE-2007-4536?
How do I fix CVE-2007-4536?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4530Multiple cross-site scripting (XSS) vulnerabilities in TeamS…
- CVE-2007-4531Soldat game server 1.4.2 and earlier, and dedicated server 2…
- CVE-2007-4532Soldat game server 1.4.2 and earlier, and dedicated server 2…
- CVE-2007-4533Format string vulnerability in the Say command in sv_main.cp…
- CVE-2007-4534Buffer overflow in the VThinker::BroadcastPrintf function in…
- CVE-2007-4535The VStr::Resize function in str.cpp in Vavoom 1.24 and earl…
- CVE-2007-4537Heap-based buffer overflow in the Huffman decompression algo…
- CVE-2007-4538email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote a…
- CVE-2007-4539The WebService (XML-RPC) interface in Bugzilla 2.23.3 throug…
- CVE-2007-4540Multiple SQL injection vulnerabilities in download.php in Ol…
- CVE-2007-4541Multiple cross-site scripting (XSS) vulnerabilities in Olate…
- CVE-2007-4542Multiple cross-site scripting (XSS) vulnerabilities in MapSe…
Are you affected by CVE-2007-4536?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
