Security Advisory
CVE-2006-6972
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
SQL injection in torrents.php in BtitTracker 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) by and (2) order parameters. NOTE: it is not clear whether this issue is exploitable.