Unrated severityNVD Advisory· Published Jun 13, 2006· Updated Apr 16, 2026
CVE-2006-3007
CVE-2006-3007
Description
Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, and (5) ICQ.
Affected products
14cpe:2.3:a:nullsoft:shoutcast_server:1.7.1:*:linux:*:*:*:*:*+ 13 more
- cpe:2.3:a:nullsoft:shoutcast_server:1.7.1:*:linux:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.8.3:*:win32:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.8.9:*:freebsd:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.8.9:*:linux:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.8.9:*:mac_os_x:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.8.9:*:solaris:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.8.9:*:win32:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.2:*:win32:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:linux:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:mac_os_x:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:win32:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.5:*:linux:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.5:*:mac_os_x:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.5:*:win32:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7News mentions
0No linked articles in our index yet.