SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Shoutcast_server | Nullsoft | 1.8.9 (including) | 1.8.9 (including) |