Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2006-3534

Disclosure Date: July 12, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote attackers to read arbitrary files via encoded dot dot (%2E%2E) sequences in an HTTP GET request for a file path containing "/content".
0
Attacker Value
Unknown

CVE-2006-3007

Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, and (5) ICQ.
0
Attacker Value
Unknown

CVE-2002-1470

Disclosure Date: April 22, 2003 (last updated February 22, 2025)
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.
0
Attacker Value
Unknown

CVE-2002-0907

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-".
0