peter bassill · operator
$ cve CVE-2008-6960 JSON

CVE-2008-6960 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7% (pctl 94)

Patch early

A public exploit exists.

Description

download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS6.97% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-08-12
Last modified2026-06-16

Affected (1)

VendorProduct
x10mediax10 automatic mp3 script

Public exploits

SourceTitleDate
exploit-dbX10media Mp3 Search Engine 1.6 - Remote File Disclosure2008-11-09

References

→ the Explorer  ·  watch your stack  ·  NVD