Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the mp3 title field.
References
Configurations
History
No history.
Information
Published : 2014-06-16 18:55
Updated : 2024-02-28 12:20
NVD link : CVE-2014-4166
Mitre link : CVE-2014-4166
CVE.ORG link : CVE-2014-4166
JSON object : View
Products Affected
shoutcast
- dnas
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')