VendorsNullsoftshoutcast_server1.9.7
Vulnerabilities

Nullsoft Shoutcast Server 1.9.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-1999-1561
Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.
Published 2001-09-12 · Modified
7.2EPSS 0.003
CVE-2007-1229
Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the administrator interface when viewing the log file.
Published 2007-03-02 · Modified
4.31 PoCEPSS 0.018