CVE-2009-2159

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
22/06/2009
Last modified:
09/04/2025

Description

backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .gz file from backups/.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:torrenttrader:torrenttrader_classic:1.09:*:*:*:*:*:*:*