1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




x10 Automatic MP3 Script "url" File Disclosure Vulnerability

Report ID: SA32537
Source: Secunia
Date of Discovery: 10.11.2008
Criticality: Moderate
Affects:
x10 Automatic MP3 Script 1.x

Compromise From: From remote
Compromise Type: Exposure of sensitive information

Summary

A vulnerability in x10 Automatic MP3 Script, which can be exploited by malicious people to disclose potentially sensitive information.

Detailed Description

A vulnerability in x10 Automatic MP3 Script, which can be exploited by malicious people to disclose potentially sensitive information.

Input passed to the "url" parameter in download.php is not properly verified before being used. This can be exploited to e.g. download arbitrary local files.

The vulnerability is reported in version 1.6. Other versions may also be affected.

Solution

Edit the source code to ensure that input is properly verified.