Vulnerabilities > Musicbox

DATE CVE VULNERABILITY TITLE RISK
2008-05-09 CVE-2008-2125 SQL Injection vulnerability in Musicbox 2.3.6/2.3.7
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.
network
low complexity
musicbox CWE-89
7.5
2006-07-27 CVE-2006-3886 SQL Injection vulnerability in MusicBox Page Parameter
SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI.
network
low complexity
musicbox
7.5
2006-07-27 CVE-2006-3882 Remote Security vulnerability in Musicbox 2.3.4
Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
network
low complexity
musicbox
5.0
2006-07-27 CVE-2006-3881 Cross-Site Scripting vulnerability in Musicbox 2.3.4
Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a request for the top-level URI.
network
musicbox
4.3
2006-04-18 CVE-2006-1807 Input Validation vulnerability in MusicBox
Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.
network
low complexity
musicbox
7.5
2006-04-18 CVE-2006-1806 Input Validation vulnerability in MusicBox
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.
network
high complexity
musicbox
2.6
2006-03-23 CVE-2006-1360 SQL Injection vulnerability in Musicbox 2.3Beta2
Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) message1 or (5) message parameter to (b) cart.php.
network
low complexity
musicbox CWE-89
7.5
2006-03-22 CVE-2006-1349 Input Validation vulnerability in Musicbox 2.3Beta2
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php.
network
musicbox
4.3
2005-12-22 CVE-2005-4500 SQL Injection vulnerability in Musicbox 2.3
SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter.
network
low complexity
musicbox CWE-89
7.5