5
CVE-2008-6960
- EPSS 6.97%
- Veröffentlicht 12.08.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:03:19
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
X10media ≫ X10 Automatic Mp3 Script Version1.5.5
X10media ≫ X10 Automatic Mp3 Script Version1.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.97% | 0.933 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://osvdb.org/49797
http://secunia.com/advisories/32537
http://www.securityfocus.com/bid/32227
http://www.vupen.com/english/advisories/2008/3062
https://exchange.xforce.ibmcloud.com/vulnerabilities/46489
https://www.exploit-db.com/exploits/7074