PT-2008-5755 · Jmweb · Jmweb Mp3 Music Audio Search/Download Script

Sirgod

·

Published

2008-10-09

·

Updated

2017-09-29

·

CVE-2008-4522

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JMweb MP3 Music Audio Search and Download Script (affected versions not specified)
Description The issue concerns multiple directory traversal vulnerabilities. These vulnerabilities allow remote attackers to include and execute arbitrary local files. The attack can be performed by including a .. (dot dot) in the src parameter to API endpoints such as "listen.php" and "download.php".
Recommendations For JMweb MP3 Music Audio Search and Download Script, restrict access to the "listen.php" and "download.php" API endpoints to minimize the risk of exploitation. Avoid using the src parameter in these endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4522

Affected Products

Jmweb Mp3 Music Audio Search/Download Script