Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2024-13327
Disclosure Date: February 04, 2025 (last updated February 04, 2025)
The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2010-1499
Disclosure Date: April 23, 2010 (last updated October 04, 2023)
SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2008-2125
Disclosure Date: May 09, 2008 (last updated October 04, 2023)
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.
0
Attacker Value
Unknown
CVE-2006-3886
Disclosure Date: July 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI. NOTE: the start parameter/search action is already covered by CVE-2006-1807, and the show parameter/top action is already covered by CVE-2006-1360.
0
Attacker Value
Unknown
CVE-2006-3881
Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a request for the top-level URI. NOTE: the id parameter in index.php, and the type and show parameters in a top action, are already covered by CVE-2006-1349; and the term parameter in a search action is already covered by CVE-2006-1806.
0
Attacker Value
Unknown
CVE-2006-3882
Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
0
Attacker Value
Unknown
CVE-2006-1806
Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.
0
Attacker Value
Unknown
CVE-2006-1807
Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.
0
Attacker Value
Unknown
CVE-2006-1360
Disclosure Date: March 23, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) message1 or (5) message parameter to (b) cart.php.
0
Attacker Value
Unknown
CVE-2006-1349
Disclosure Date: March 22, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php.
0