PT-2008-5440 · X10 · X10 Automatic Mp3 Script

Thunder

·

Published

2008-09-19

·

Updated

2017-09-29

·

CVE-2008-4141

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions x10 Automatic MP3 Script version 1.5.5
Description The issue allows remote attackers to execute arbitrary PHP code. This can be achieved by providing a URL in the web root parameter to specific PHP files, such as includes/function core.php and templates/layout lyrics.php.
Recommendations For version 1.5.5, consider restricting access to the includes/function core.php and templates/layout lyrics.php files to minimize the risk of exploitation. Avoid using the web root parameter in these files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4141

Affected Products

X10 Automatic Mp3 Script