Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2010-1499

Disclosure Date: April 23, 2010 (last updated October 04, 2023)
SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2008-2125

Disclosure Date: May 09, 2008 (last updated October 04, 2023)
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.
0
Attacker Value
Unknown

CVE-2006-3886

Disclosure Date: July 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI. NOTE: the start parameter/search action is already covered by CVE-2006-1807, and the show parameter/top action is already covered by CVE-2006-1360.
0
Attacker Value
Unknown

CVE-2006-3881

Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a request for the top-level URI. NOTE: the id parameter in index.php, and the type and show parameters in a top action, are already covered by CVE-2006-1349; and the term parameter in a search action is already covered by CVE-2006-1806.
0
Attacker Value
Unknown

CVE-2006-3882

Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
0
Attacker Value
Unknown

CVE-2006-1806

Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.
0
Attacker Value
Unknown

CVE-2006-1807

Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.
0
Attacker Value
Unknown

CVE-2006-1360

Disclosure Date: March 23, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) message1 or (5) message parameter to (b) cart.php.
0
Attacker Value
Unknown

CVE-2006-1349

Disclosure Date: March 22, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php.
0
Attacker Value
Unknown

CVE-2005-4500

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered.
0