---
title: "CVE-2006-5451\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-5451?format=md
keywords: index, follow
---

# CVE-2006-5451

Publication date 23 October 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1
allow remote attackers to inject arbitrary web script or HTML via the (1)
action, (2) file, and (3) users array variables in (a) admin.php, which are
not properly handled when the administrator views the Activity Log; and the
(4) torrent parameter, as used by the displayName variable, in (b)
startpop.php, different vectors than CVE-2006-5227.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| torrentflux | 7.10 gutsy | Fixed 2.1-7 |
| 7.04 feisty | Fixed 2.1-7 |
| 6.10 edgy | Fixed 2.1-1ubuntu0.2 |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5451)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-5451)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-5451)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-5451)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-5451>
