Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Shoutbox | Knusperleicht | 2.6 (including) | 2.6 (including) |