返回列表 发布新帖

[官方消息] 【PTP】qB4.5.1安全问题

760 1
发表于 2023-2-27 17:30:37 | 查看全部 阅读模式


您需要 登录 才可以下载或查看,没有账号?注册

PassthePopcorn:qBittorrent 4.5.1 WebUI Vulnerability

A vulnerability has been reported in qBittorrent 4.5.1 running on Windows with the webui enabled.

A bug allows a remote attack to read files and traverse your filesystem using the webui uri.

Please disable the webui to secure your machine and follow the bug report awaiting a fix!

The bug report can be found here:


Confirmed by members to be vulnerable on:
qBit 4.5.1 - infinitycircuit
qBit 4.5.0 - flashgit

qBittorrent & operating system versions

qBitTorrent version: 4.5.1 (latest stable as of today).
Operating System: Windows 10, version 22H2. x64 architecture.

What is the problem?

I ran a Nessus vulnerability scan on a machine running qBitTorrent and found that the Web UI can be used to access arbitrary files on the host's filesystem - unauthenticated - via what appears to be a path traversal vulnerability.

Have done some searches on your bug tracker for an existing bug report - and can't find one, some am raising this. Note that this is my first open source bug report - so apologies if I've missed anything. Please let me know if there's anything you need from me.
Steps to reproduce

If you were on my network, you'd do the following:

Enable the qBitTorrent web UI (in my case it runs on port 8080)
From a command prompt, run curl -i "\..\..\..\..\windows\win.ini"

Expected result: a 403 or 404 response
Actual result: the win.ini file from the remote machine is displayed

Have attached a screenshot where I create a file on the remote machine then retrieve that file unauthenticated from my laptop.
Additional context


江南雨巷Lv.5 发表于 2023-2-28 09:20:41 | 查看全部
回复 点赞

使用道具 举报


您需要登录后才可以回帖 登录 | 注册




  • 关注公众号
  • 添加微信客服
Copyright © 2001-2025 隔壁网 版权所有 All Rights Reserved. 粤ICP备14056481号-1
关灯 在本版发帖
快速回复 返回顶部 返回列表