MCshoutbox SQL Injection and Arbitrary File Upload Vulnerabilities
Description
Multiple vulnerabilities have been identified in MCshoutbox, which could be exploited by attackers to gain knowledge of sensitive information, bypass security restrictions, or compromise a vulnerable web server.
The first issue is caused by an input validation error in the "scr_login.php" script when processing the "username" and "password" parameters supplied via "admin_login.php", which could be exploited by malicious people to conduct SQL injection attacks and gain unauthorized access to a vulnerable application where they can upload arbitrary PHP scripts and execute malicious code with the privileges of the web server.
The second vulnerability is caused by an input validation error in the "admin_login.php" script when processing the "loginerror" parameter, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected site.
Vulnerable Products
Vulnerable Software: MCshoutbox version 1.1 and prior