Description
|
|
Multiple vulnerabilities were identified in ShoutLIVE, which could be exploited by remote attackers to execute arbitrary commands and scripting code.
The first issue is due to an access validation error where the "savesettings.php" script allows unauthenticated users to edit the "settings.php" file, which could be exploited by remote attackers to inject and execute malicious PHP commands.
The second flaw is due to an input validation error in the "post.php" script that fails to properly validate certain parameters, which could be exploited by attackers to cause malicious scripting code to be executed by the user's browser.
|