Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Shoutbox | Knusperleicht | 2.6 (including) | 2.6 (including) |