7.5
CVSSv2

CVE-2007-2141

Published: 19/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote malicious users to inject arbitrary PHP code into shouts.php via the shout parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

shoutpro shoutpro

Exploits

<?/* File: shoutboxphp Affects: ShoutPro 152 (may affect earlier versions) Date: 17th April 2007 Issue Description: =========================================================================== ShoutPro 152 fails to fully sanitize user input ($shout) that it writes to the shoutsphp file when adding a new message, this can result in the inje ...