![]() ![]() Have attached a screenshot where I create a file on the remote machine then retrieve that file unauthenticated from my laptop. \.\.\.\.\windows\win.ini"Īctual result: the win.ini file from the remote machine is displayed Enable the qBitTorrent web UI (in my case it runs on port 8080).If you were on my network, you'd do the following: ![]() Please let me know if there's anything you need from me. Note that this is my first open source bug report - so apologies if I've missed anything. Before using a specific plugin for a tracker, the user must indicate, into the script, his login to sign in. Have done some searches on your bug tracker for an existing bug report - and can't find one, some am raising this. 7-Zip A free file archiver for extremely high compression Caprine qBittorrent extra search engines Search engine plugins for qBittorrent, to use with trackers for which authentication is required. qBittorrent features a light footprint, whilst providing all the features you may need. I ran a Nessus vulnerability scan on a machine running qBitTorrent and found that the Web UI can be used to access arbitrary files on the host's filesystem - unauthenticated - via what appears to be a path traversal vulnerability. qBittorrent is a well established open-source BitTorrent client. Operating System: Windows 10, version 22H2. QBitTorrent version: 4.5.1 (latest stable as of today). ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |