Unrated severityNVD Advisory· Published Feb 14, 2008· Updated Apr 23, 2026
CVE-2008-0775
CVE-2008-0775
Description
Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";".
Affected products
3cpe:2.3:a:simple_machines:smf_shoutbox:1.14:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:simple_machines:smf_shoutbox:1.14:*:*:*:*:*:*:*
- cpe:2.3:a:simple_machines:smf_shoutbox:1.15:*:*:*:*:*:*:*
- cpe:2.3:a:simple_machines:smf_shoutbox:1.16b:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.