5
CVSSv2

CVE-2008-6960

Published: 12/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 up to and including 1.6 allows remote malicious users to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.

Vulnerable Product Search on Vulmon Subscribe to Product

x10media x10 automatic mp3 script 1.5.5

x10media x10 automatic mp3 script 1.6

Exploits

################# ~THUNDER ################################################################ ~X10media Mp3 Search Engine v155 - 16 Remote File Disclosure Vulnerability ~Founded by : THUNDER <t4h[at]hotmailfr> ~Dork: "This search engine is in no way intended for illegal downloads " ~File : Downloadphp ================= ...