x10 Automatic MP3 Script 'url' Parameter File Disclosure Vulnerability
BID:32227
Info
x10 Automatic MP3 Script 'url' Parameter File Disclosure Vulnerability
| Bugtraq ID: | 32227 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6960 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2008 12:00AM |
| Updated: | May 07 2015 05:21PM |
| Credit: | THUNDER |
| Vulnerable: |
x10Media x10 Automatic MP3 Script 1.5.5 x10Media x10 Automatic MP3 Script 1.6 |
| Not Vulnerable: | |
Discussion
x10 Automatic MP3 Script 'url' Parameter File Disclosure Vulnerability
x10 Automatic MP3 Script is prone to a file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the webserver process. This may aid in further attacks.
Versions up to and including x10 Automatic MP3 Script 1.6 are vulnerable.
x10 Automatic MP3 Script is prone to a file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the webserver process. This may aid in further attacks.
Versions up to and including x10 Automatic MP3 Script 1.6 are vulnerable.
Exploit / POC
x10 Automatic MP3 Script 'url' Parameter File Disclosure Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/download.php?url=696e636c756465732f636f6e7374616e74732e706870
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/download.php?url=696e636c756465732f636f6e7374616e74732e706870
Solution / Fix
x10 Automatic MP3 Script 'url' Parameter File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
x10 Automatic MP3 Script 'url' Parameter File Disclosure Vulnerability
References:
References:
- x10 Automatic MP3 Script Homepage (x10Media)