49797vdb entry
http://osvdb.org/49797 CVE-2008-6960
X10media Mp3 Search Engine 1.6 - Remote File Disclosure
Record summary
CVE-2008-6960 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBX10media Mp3 Search Engine 1.6 - Remote File DisclosureExploitDB exploitby THUNDERNot analyzed1 file
References
732537Third-party advisory
http://secunia.com/advisories/32537 32227vdb entry
http://www.securityfocus.com/bid/32227 ADV-2008-3062vdb entry
http://www.vupen.com/english/advisories/2008/3062 x10automaticmp3-url-info-disclosure(46489)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/46489 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6960 7074exploit
https://www.exploit-db.com/exploits/7074