CVE-2008-6960 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 7% (pctl 94)
Patch early
A public exploit exists.
Description
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 6.97% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-08-12 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| x10media | x10 automatic mp3 script |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | X10media Mp3 Search Engine 1.6 - Remote File Disclosure | 2008-11-09 |
References
- http://osvdb.org/49797
- http://secunia.com/advisories/32537
- http://www.securityfocus.com/bid/32227
- http://www.vupen.com/english/advisories/2008/3062
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46489
- https://www.exploit-db.com/exploits/7074
- http://osvdb.org/49797
- http://secunia.com/advisories/32537
- http://www.securityfocus.com/bid/32227
- http://www.vupen.com/english/advisories/2008/3062
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46489
- https://www.exploit-db.com/exploits/7074
→ the Explorer · watch your stack · NVD