Musicbox is a narrowly scoped music-management or streaming application with a modestly represented vulnerability footprint that nonetheless appears among more prominent vendors in the landscape, suggesting concentrated use within particular deployment contexts. The recurring signal centers on SQL injection and related input-handling flaws, reflecting application-layer parsing challenges typical of data-driven music platforms; public exploit code has an established presence for vulnerabilities in this vendor's disclosures. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Musicbox over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2125HIGH SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter. | May 9, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-3886HIGH SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a requ | Jul 27, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-4500HIGH SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this informa | Dec 22, 2005 | 7.5 | 28 | NO | YES |
CVE-2006-1349MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show pa | Mar 22, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-1807HIGH Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search a | Apr 18, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-1360HIGH Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index. | Mar 23, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-3882MEDIUM Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. | Jul 27, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-3881MEDIUM Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a request for | Jul 27, 2006 | 4.3 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a searc | Apr 18, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Musicbox.
Media articles that mention a CVE ID that affects a product developed by Musicbox — matched by CVE ID, not by vendor name.