📦

shoutbox

Vendor: endity.com

Actively Exploited 0 CISA KEV List
PoC / Exploits 5 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 2.32% Exploit Prob.
Latest CVE CVE-2009-4767 Apr 20

Security Vulnerability Index

Page 1 / 1
4.3 CVSS
CVE-2009-4767
Exploit Found

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) input_name and (2) input_text parameters. NOTE: some of these details are obtained from third party information.

EPSS: 1.47%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.

EPSS: 1.10%
6.8 CVSS
CVE-2007-4330
Exploit Found

PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

EPSS: 2.80%
7.8 CVSS

Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb.

EPSS: 1.41%
6.8 CVSS
CVE-2006-6721
Exploit Found

Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.

EPSS: 1.68%
5.1 CVSS
CVE-2006-3989
Exploit Found

PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter.

EPSS: 3.35%
7.5 CVSS

SQL injection vulnerability in Unknown Domain Shoutbox 2005.07.21 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

EPSS: 1.21%
4.3 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields.

EPSS: 1.30%
5.0 CVSS
CVE-2002-1429
Exploit Found

Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter.

EPSS: 6.61%