FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-3007

This CVE name corresponds to:

Entered Topic
2006-07-11 shoutcast -- cross-site scripting, information exposure

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-3007
Phase Assigned(20060612)

Description

Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, and (5) ICQ.

References

Source Reference
BUGTRAQ 20060608 bug of script injection in shoutcast servers
GENTOO GLSA-200607-05
BID 18376
VUPEN ADV-2006-2254
SECUNIA 20524
SECUNIA 21005
XF shoutcast-djfields-xss(27129)