vendor:
MCshoutbox
by:
SirGod
7,5
CVSS
HIGH
SQL Injection Login Bypass, Cross-Site Scripting, Shell Upload
89, 79, 264
CWE
Product Name: MCshoutbox
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: NO
Related CWE: N/A
CPE: a:maniacomputer:mcshoutbox:1.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
MCshoutbox 1.1 (SQL/XSS/Shell) Multiple Remote Vulnerabilities
MCshoutbox 1.1 is vulnerable to SQL Injection Login Bypass, Cross-Site Scripting and Shell Upload. An attacker can exploit these vulnerabilities to bypass authentication, execute malicious scripts and upload malicious files.
Mitigation:
Ensure that user input is properly sanitized and validated. Use a web application firewall to detect and block malicious requests. Use strong passwords and two-factor authentication.