← Vulnerability feed

Vulnerability record · CVE-2002-1470 · published 22 April 2003

CVE-2002-1470: Nullsoft shoutcast server vulnerability

Nullsoft · Shoutcast Server

SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.

2.1 CVSS 2.0 Low EPSS 0.48% · top 61.2%
2.1CVSS 2.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.

AV:L/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1470 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2006-3534Nullsoft shoutcast server vulnerabilityDirectory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote a…EPSS 2.5%7.5CVE-2004-1373SHOUTcast format string flaw allows code executionSHOUTcast 1.9.4 contains a format string vulnerability reachable through format specifiers placed in a content URL, demonstrated via the filename por…EPSS 70%analysed7.5CVE-2002-0907Nullsoft shoutcast server vulnerabilityBuffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a lo…EPSS 5.6%7.5CVE-2002-0199Nullsoft shoutcast server vulnerabilityBuffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary …EPSS 3.4%7.2CVE-1999-1561Nullsoft shoutcast server vulnerabilityNullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to g…EPSS 0.35%5.0CVE-2001-1304Nullsoft shoutcast server vulnerabilityBuffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user…EPSS 1.9%4.3CVE-2007-1229Nullsoft shoutcast server cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the…EPSS 1.8%4.3CVE-2006-3007Nullsoft shoutcast server vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ field…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2002-1470), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.