Description
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-6919 | download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T11:49:02.466Z
Reserved: 2009-08-11T00:00:00.000Z
Link: CVE-2008-6960
No data.
Status : Deferred
Published: 2009-08-12T10:30:01.063
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-6960
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD