metaInfo.php in TorrentFlux 2.2, when $cfg["enable_file_priority"] is false, allows remote attackers to execute arbitrary commands via shell metacharacters (backticks) in the torrent parameter to (1) details.php and (2) startpop.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 65.7%