CVE-2008-6960
x10 Automatic Mp3 Search Engine Script 1.5.5-1.6 - Unauthenticated Arbitrary File Read via Encoded URL Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6960. PoCs published by THUNDER.
AI-analyzed exploit summary This exploit leverages a file disclosure vulnerability in X10media MP3 Search Engine by encoding a target file path in hexadecimal and passing it via the 'url' parameter in download.php, allowing unauthorized file downloads.
Description
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.
Exploits (1)
This exploit leverages a file disclosure vulnerability in X10media MP3 Search Engine by encoding a target file path in hexadecimal and passing it via the 'url' parameter in download.php, allowing unauthorized file downloads.