Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2010-1534
Disclosure Date: April 26, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2009-4767
Disclosure Date: April 20, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) input_name and (2) input_text parameters. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-3716
Disclosure Date: October 16, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/.
0
Attacker Value
Unknown
CVE-2009-3714
Disclosure Date: October 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.
0
Attacker Value
Unknown
CVE-2009-3715
Disclosure Date: October 16, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
0
Attacker Value
Unknown
CVE-2008-6301
Disclosure Date: February 26, 2009 (last updated October 04, 2023)
SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
0
Attacker Value
Unknown
CVE-2008-4512
Disclosure Date: October 09, 2008 (last updated October 04, 2023)
ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
0
Attacker Value
Unknown
CVE-2008-0775
Disclosure Date: February 14, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";".
0
Attacker Value
Unknown
CVE-2007-5948
Disclosure Date: November 14, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in main.php in SF-Shoutbox 1.2.1 through 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) nick (aka Name) and (2) shout (aka Shout) parameters.
0
Attacker Value
Unknown
CVE-2007-4330
Disclosure Date: August 14, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
0