vendor:
Mp3 Search Engine
by:
THUNDER
7.5
CVSS
HIGH
Remote File Disclosure
200
CWE
Product Name: Mp3 Search Engine
Affected Version From: 1.5.2005
Affected Version To: 1.6
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
X10media Mp3 Search Engine v1.5.5 – 1.6 Remote File Disclosure Vulnerability
X10media Mp3 Search Engine versions 1.5.5 to 1.6 are vulnerable to a remote file disclosure vulnerability. An attacker can exploit this vulnerability by encoding the URL of the file they wish to download and sending it to the download.php page. The file will be downloaded as an .mp3 extension, but can be opened with any text editor to view the contents.
Mitigation:
Upgrade to the latest version of X10media Mp3 Search Engine.