PT-2008-5440 · X10 · X10 Automatic Mp3 Script

Thunder

·

Publicado

2008-09-19

·

Atualizado

2017-09-29

·

CVE-2008-4141

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions x10 Automatic MP3 Script version 1.5.5
Description The issue allows remote attackers to execute arbitrary PHP code. This can be achieved by providing a URL in the web root parameter to specific PHP files, such as includes/function core.php and templates/layout lyrics.php.
Recommendations For version 1.5.5, consider restricting access to the includes/function core.php and templates/layout lyrics.php files to minimize the risk of exploitation. Avoid using the web root parameter in these files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4141

Produtos afetados

X10 Automatic Mp3 Script