download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.
References
Link | Resource |
---|---|
http://osvdb.org/49797 | Exploit |
http://secunia.com/advisories/32537 | Vendor Advisory |
http://www.securityfocus.com/bid/32227 | Exploit |
http://www.vupen.com/english/advisories/2008/3062 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46489 | |
https://www.exploit-db.com/exploits/7074 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2009-08-12T10:00:00
Updated: 2017-09-28T12:57:01
Reserved: 2009-08-11T00:00:00
Link: CVE-2008-6960
JSON object: View
NVD Information
Status : Modified
Published: 2009-08-12T10:30:01.063
Modified: 2017-09-29T01:33:27.213
Link: CVE-2008-6960
JSON object: View
Redhat Information
No data.
CWE