Cross-Site Scripting Vulnerability in Nullsoft ShoutcastServer
CVE-2007-1229

Currently unrated

Key Information:

Vendor

Nullsoft

Vendor
CVE Published:
2 March 2007

What is CVE-2007-1229?

The Nullsoft ShoutcastServer version 1.9.7 contains a cross-site scripting vulnerability that permits remote attackers to execute arbitrary web scripts or HTML code. This vulnerability arises from improper handling of inputs in the administrator interface when viewing the log file, specifically through the top-level URI on the Incoming interface (port 8001/tcp). Attackers can exploit this weakness to inject malicious content, potentially compromising the security of the application and its users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.