| Name |
Description |
| CVE-2018-5316 |
The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for
WordPress has XSS via the includes/pages/redirect.php page parameter.
|
| CVE-2018-5312 |
The tabs-responsive plugin 1.8.0 for WordPress has XSS via the
post_title parameter to wp-admin/post.php.
|
| CVE-2018-5311 |
The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the
tonjoo_ecae_options[custom_css] parameter to the
wp-admin/admin.php?page=tonjoo_excerpt URI.
|
| CVE-2018-5293 |
The GD Rating System plugin 2.3 for WordPress has XSS via the
wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
|
| CVE-2018-5292 |
The GD Rating System plugin 2.3 for WordPress has XSS via the
wp-admin/admin.php panel parameter for the gd-rating-system-information
page.
|
| CVE-2018-5288 |
The GD Rating System plugin 2.3 for WordPress has XSS via the
wp-admin/admin.php panel parameter for the gd-rating-system-transfer
page.
|
| CVE-2018-5286 |
The GD Rating System plugin 2.3 for WordPress has XSS via the
wp-admin/admin.php panel parameter for the gd-rating-system-about page.
|
| CVE-2018-5284 |
The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid
parameter to wp-admin/options-general.php.
|
| CVE-2018-5281 |
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices
has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings
screens.
|
| CVE-2018-5280 |
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices
has XSS via the Configure SSO screens.
|
| CVE-2018-5263 |
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before
4.0.21 for Joomla! allows XSS.
|
| CVE-2018-5249 |
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and
0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via
the login form's username field (aka the login parameter to the
ban_canLogin function in index.php).
|
| CVE-2018-5216 |
Radiant CMS 1.1.4 has XSS via crafted Markdown input in the
part_body_content parameter to an admin/pages/*/edit resource.
|
| CVE-2018-5215 |
Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title
parameter.
|
| CVE-2018-5214 |
The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via
the al2fb_facebook_id parameter to wp-admin/profile.php.
|
| CVE-2018-5213 |
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS
via the sdm_upload (aka Downloadable File) parameter in an edit action
to wp-admin/post.php.
|
| CVE-2018-5212 |
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS
via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit
action to wp-admin/post.php.
|
| CVE-2018-5078 |
Online Ticket Booking has XSS via the admin/eventlist.php cast
parameter.
|
| CVE-2018-5077 |
Online Ticket Booking has XSS via the admin/movieedit.php moviename
parameter.
|
| CVE-2018-5076 |
Online Ticket Booking has XSS via the admin/newsedit.php newstitle
parameter.
|
| CVE-2018-5075 |
Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name
parameter.
|
| CVE-2018-5074 |
Online Ticket Booking has XSS via the admin/manageownerlist.php contact
parameter.
|
| CVE-2018-5072 |
Online Ticket Booking has XSS via the admin/sitesettings.php keyword
parameter.
|
| CVE-2018-5071 |
Persistent XSS exists in the web server on Cobham Sea Tel 116 build
222429 satellite communication system devices: remote attackers can
inject malicious JavaScript code using the device's TELNET shell
built-in commands, as demonstrated by the "set ship name" command. This
is similar to a Cross Protocol Injection with SNMP.
|
| CVE-2018-1190 |
An issue was discovered in these Pivotal Cloud Foundry products: all
versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA
bosh v30.x versions prior to v30.8 and all other versions prior to
v45.0. A cross-site scripting (XSS) attack is possible in the clientId
parameter of a request to the UAA OpenID Connect check session iframe
endpoint used for single logout session management.
|
| CVE-2017-9979 |
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the
REST call invoked does not exist, an error will be triggered
containing the invalid method previously invoked. The response sent to
the user isn't sanitized in this case. An attacker can leverage this
issue by including arbitrary HTML or JavaScript code as a parameter,
aka XSS.
|
| CVE-2017-9934 |
Missing CSRF token checks and improper input validation in Joomla! CMS
1.7.3 through 3.7.2 lead to an XSS vulnerability.
|
| CVE-2017-9931 |
Cross-Site Scripting (XSS) exists in Green Packet DX-350 Firmware
version v2.8.9.5-g1.4.8-atheeb, as demonstrated by the action parameter
to ajax.cgi.
|
| CVE-2017-9836 |
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote
authenticated administrators to inject arbitrary web script or HTML via
the virtual_name parameter to /admin.php (i.e., creating a virtual
album).
|
| CVE-2017-9816 |
Cross-site scripting (XSS) vulnerability in Paessler PRTG Network
Monitor before 17.2.32.2279 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2017-9813 |
In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack
2 Critical Fix 4 (version 8.0.4.312), the scriptName parameter of the
licenseKeyInfo action method is vulnerable to cross-site scripting
(XSS).
|
| CVE-2017-9802 |
The Javascript method Sling.evalString() in Apache Sling Servlets Post
before 2.3.22 uses the javascript 'eval' function to parse input
strings, which allows for XSS attacks by passing specially crafted
input strings.
|
| CVE-2017-9781 |
A cross site scripting (XSS) vulnerability exists in Check_MK versions
1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to
inject arbitrary HTML or JavaScript via the _username parameter when
attempting authentication to webapi.py, which is returned unencoded
with content type text/html.
|
| CVE-2017-9767 |
Multiple cross-site scripting (XSS) vulnerabilities in Quali
CloudShell before 8 allow remote authenticated users to inject
arbitrary web script or HTML via the (1) Name or (2) Description
parameter to RM/Reservation/ReserveNew; the (3) Description parameter
to RM/Topology/Update; the (4) Name, (5) Description, (6)
ExecutionBatches[0].Name, (7) ExecutionBatches[0].Description, or (8)
Labels parameter to SnQ/JobTemplate/Edit; or (9) Alias or (10)
Description parameter to
RM/AbstractTemplate/AddOrUpdateAbstractTemplate.
|
| CVE-2017-9764 |
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows
remote attackers to inject arbitrary web script or HTML via the
Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a
para action.
|
| CVE-2017-9674 |
In SimpleCE 2.3.0, an authenticated XSS vulnerability was found on
index.php/content/text/1?return_url=[XSS] exploitable as a regular or
admin user.
|
| CVE-2017-9668 |
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user
group, there is no XSS filtering, resulting in storage-type XSS
generation, via the description parameter in an addgroup action.
|
| CVE-2017-9624 |
Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI
1.8.2 and earlier allow remote attackers to inject arbitrary web script
or HTML via crafted currency decimal-sign data.
|
| CVE-2017-9623 |
Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI
1.8.2 and earlier allow remote attackers to inject arbitrary web script
or HTML via crafted country data.
|
| CVE-2017-9622 |
Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI
1.8.2 and earlier allow remote attackers to inject arbitrary web script
or HTML via crafted common data.
|
| CVE-2017-9621 |
Cross-site scripting (XSS) vulnerability in
modules/Base/Lang/Administrator/update_translation.php in EPESI in
Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the (1) original or (2) new parameter.
|
| CVE-2017-9613 |
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors
before b1705.1234962 allows remote authenticated users to inject
arbitrary web script or HTML via the file upload functionality.
|
| CVE-2017-9609 |
Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows
remote authenticated users to inject arbitrary web script or HTML via
the map_language parameter to backend/pages/lang_settings.php.
|
| CVE-2017-9556 |
Cross-site scripting (XSS) vulnerability in Video Metadata Editor in
Synology Video Station before 2.3.0-1435 allows remote authenticated
attackers to inject arbitrary web script or HTML via the title
parameter.
|
| CVE-2017-9555 |
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in
Synology Photo Station before 6.7.0-3414 allows remote attackers to
inject arbitrary web script or HTML via the image parameter.
|
| CVE-2017-9551 |
Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before
16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting
potential dangerous payload, e.g. XSS code, to be saved as their name
in the usr_registration table. The values are then emailed to the the
user and administrator and if accepted become part of the new user's
account.
|
| CVE-2017-9548 |
admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS)
vulnerability, which allows remote authenticated users to inject
arbitrary web script or HTML by launching a Home Template Edit Page
action and entering the Navigation Title of a page that is scheduled
for future publication (aka a pending page change).
|
| CVE-2017-9547 |
admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS)
vulnerability, which allows remote authenticated users to inject
arbitrary web script or HTML by launching an Edit Page action and
entering the Navigation Title or Page Title of a page that is scheduled
for future publication (aka a pending page change).
|
| CVE-2017-9546 |
admin.php in BigTree through 4.2.18 allows remote authenticated users
to cause a denial of service (inability to save revisions) via XSS
sequences in a revision name.
|
| CVE-2017-9537 |
Persistent cross-site scripting (XSS) in the Add Node function of
SolarWinds Network Performance Monitor version 12.0.15300.90 allows
remote attackers to introduce arbitrary JavaScript into various
vulnerable parameters.
|
| CVE-2017-9523 |
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page,
aka NSWA-1342.
|
| CVE-2017-9516 |
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by
uploading a malicious SVG file.
|
| CVE-2017-9510 |
The repository changelog resource in Atlassian FishEye before version
4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript
via a cross site scripting (XSS) vulnerability through the start date
and end date parameters.
|
| CVE-2017-9509 |
The review file upload resource in Atlassian Crucible before version
4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript
via a cross site scripting (XSS) vulnerability through the charset of
a previously uploaded file.
|
| CVE-2017-9508 |
Various resources in Atlassian FishEye and Crucible before version
4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript
via a cross site scripting (XSS) vulnerability through the name of a
repository or review file.
|
| CVE-2017-9507 |
The review dashboard resource in Atlassian Crucible from version 4.1.0
before version 4.4.1 allows remote attackers to inject arbitrary HTML
or JavaScript via a cross site scripting (XSS) vulnerability in the
review filter title parameter.
|
| CVE-2017-9506 |
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0
before version 1.9.12 and from version 2.0.0 before version 2.0.4
allows remote attackers to access the content of internal network
resources and/or perform an XSS attack via Server Side Request Forgery
(SSRF).
|
| CVE-2017-9467 |
Cross-site scripting (XSS) vulnerability in the GlobalProtect external
interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before
7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2017-9459 |
Cross-site scripting (XSS) vulnerability in the management web
interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before
7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2017-9452 |
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0
and earlier allows remote attackers to inject arbitrary web script or
HTML via the page parameter.
|
| CVE-2017-9451 |
Cross site scripting (XSS) vulnerability in pages.edit_form.php in
flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript
via the PATH_INFO in an acp.php URL, due to use of unsanitized
$_SERVER['PHP_SELF'] to generate URLs.
|
| CVE-2017-9448 |
Cross-site scripting (XSS) vulnerabilities in BigTree CMS through
4.2.18 allow remote authenticated users to inject arbitrary web script
or HTML via the description parameter. This issue exists in
core\admin\ajax\pages\save-revision.php and
core\admin\modules\pages\revisions.php. Low-privileged (administrator)
users can attack high-privileged (Developer) users.
|
| CVE-2017-9441 |
** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in
BigTree CMS through 4.2.18 allow remote authenticated users to inject
arbitrary web script or HTML by uploading a crafted package, triggering
mishandling of the (1) title or (2) version or (3) author_name
parameter in manifest.json. This issue exists in
core\admin\modules\developer\extensions\install\unpack.php and
core\admin\modules\developer\packages\install\unpack.php. NOTE: the
vendor states "You must implicitly trust any package or extension you
install as they all have the ability to write PHP files."
|
| CVE-2017-9420 |
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin
before 3.3.0 for WordPress allows remote attackers to inject arbitrary
JavaScript via the yr parameter.
|
| CVE-2017-9419 |
Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom
Fields Search plugin 0.3.28 for WordPress allows remote attackers to
inject arbitrary JavaScript via the cs-all-0 parameter.
|
| CVE-2017-9366 |
Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS)
vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows
remote attackers to inject arbitrary web script or HTML via a crafted
tab_name parameter.
|
| CVE-2017-9361 |
WebsiteBaker v2.10.0 has a stored XSS vulnerability in
/account/details.php.
|
| CVE-2017-9338 |
Inadequate escaping lead to XSS vulnerability in the search module in
ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before
9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write
or paste malicious content into the search dialogue.
|
| CVE-2017-9337 |
The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS
vulnerability in the content of a post.
|
| CVE-2017-9336 |
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS
vulnerability in the content of a post.
|
| CVE-2017-9332 |
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11
mishandles the URI, allowing XSS via vectors involving quotes in the
self Smarty tag.
|
| CVE-2017-9331 |
The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored
Cross-site Scripting (XSS) vulnerability in
modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows
remote attackers to inject arbitrary web script or HTML via a crafted
meeting description parameter.
|
| CVE-2017-9313 |
Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before
1.850 allow remote attackers to inject arbitrary web script or HTML via
the sec parameter to view_man.cgi, the referers parameter to
change_referers.cgi, or the name parameter to save_user.cgi. NOTE:
these issues were not fixed in 1.840.
|
| CVE-2017-9306 |
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to
bypass the XSS filter, as demonstrated by use of an "<svg/onload="
substring instead of an "<svg onload=" substring.
|
| CVE-2017-9305 |
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2
allows remote attackers to bypass the XSS filter via padded zero
characters, as demonstrated by an attack on
tiki-batch_send_newsletter.php.
|
| CVE-2017-9299 |
Open Ticket Request System (OTRS) 3.3.9 has XSS in
index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS]
and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance
because it represents a 2017 discovery of an issue in software from
2014. The 3.3.20 release, for example, is not affected.
|
| CVE-2017-9292 |
Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug
542782.
|
| CVE-2017-9289 |
Bram Korsten Note through 1.2.0 is vulnerable to a reflected XSS in
note-source\ui\editor.php (edit parameter).
|
| CVE-2017-9288 |
The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected
XSS in sendtesterror.php (backurl parameter).
|
| CVE-2017-9252 |
andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in
the search page via the text-search parameter to index.php in
a route=search action.
|
| CVE-2017-9251 |
andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in
the sitename parameter to admin.php.
|
| CVE-2017-9249 |
Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows
remote authenticated users to inject arbitrary web script or HTML
persistently by uploading a crafted HTML file. The attack vector is the
content of this file, and the filename must be specified in the
PATH_INFO to readfile.php.
|
| CVE-2017-9248 |
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2
2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect
Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which
makes it easier for remote attackers to defeat cryptographic protection
mechanisms, leading to a MachineKey leak, arbitrary file uploads or
downloads, XSS, or ASP.NET ViewState compromise.
|
| CVE-2017-9244 |
Cross-site scripting (XSS) vulnerability in the Trello app before
4.0.8 for iOS might allow remote attackers to inject arbitrary web
script or HTML by uploading and attaching a crafted photo to a Card.
|
| CVE-2017-9243 |
Aries QWR-1104 Wireless-N Router with Firmware Version WRC.253.2.0913
has XSS on the Wireless Site Survey page, exploitable with the name of
an access point.
|
| CVE-2017-9145 |
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not
properly validate the imgsize or lang parameter to prevent XSS.
|
| CVE-2017-9140 |
Cross-site scripting (XSS) vulnerability in
Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET
WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows
remote attackers to inject arbitrary web script or HTML via the bgColor
parameter to Telerik.ReportViewer.axd.
|
| CVE-2017-9085 |
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 6.5
to 8.0 allow remote attackers to inject arbitrary web script via the
(1) "paramFile" parameter to
/Site/Troubleshooting/DiagnosticReport.asp, or (2) "paramFile"
parameter to /Site/Troubleshooting/SpeedTest.asp.
|
| CVE-2017-9072 |
Two CalendarXP products have XSS in common parts of HTML files.
CalendarXP FlatCalendarXP through 9.9.290 has XSS in iflateng.htm and
nflateng.htm. CalendarXP PopCalendarXP through 9.8.308 has XSS in
ipopeng.htm and npopeng.htm.
|
| CVE-2017-9071 |
In MODX Revolution before 2.5.7, an attacker might be able to trigger
XSS by injecting a payload into the HTTP Host header of a request. This
is exploitable only in conjunction with other issues such as Cache
Poisoning.
|
| CVE-2017-9070 |
In MODX Revolution before 2.5.7, a user with resource edit permissions
can inject an XSS payload into the title of any post via the pagetitle
parameter to connectors/index.php.
|
| CVE-2017-9068 |
In MODX Revolution before 2.5.7, an attacker is able to trigger
Reflected XSS by injecting payloads into several fields on the setup
page, as demonstrated by the database_type parameter.
|
| CVE-2017-9063 |
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability
related to the Customizer exists, involving an invalid customization
session.
|
| CVE-2017-9061 |
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability
exists when attempting to upload very large files, because the error
message does not properly restrict presentation of the filename.
|
| CVE-2017-9037 |
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro
ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to
inject arbitrary web script or HTML via the (1) S44, (2) S5, (3)
S_action_fail, (4) S_ptn_update, (5) T113, (6) T114, (7) T115, (8)
T117117, (9) T118, (10) T_action_fail, (11) T_ptn_update, (12)
textarea, (13) textfield5, or (14) tmLastConfigFileModifiedDate
parameter to notification.cgi.
|
| CVE-2017-9032 |
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro
ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to
inject arbitrary web script or HTML via the (1) T1 or (2)
tmLastConfigFileModifiedDate parameter to log_management.cgi.
|
| CVE-2017-8920 |
irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the
R parameter without proper output encoding, aka XSS.
|
| CVE-2017-8899 |
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has
a composite of Stored XSS and Information Disclosure issues in the
attachments feature found in User CP. This can be triggered by any
Invision Power Board user and can be used to gain access to
moderator/admin accounts. The primary cause is the ability to upload an
SVG document with a crafted attribute such an onload; however, full
path disclosure is required for exploitation.
|
| CVE-2017-8898 |
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has
stored XSS in the Announcements, allowing privilege escalation from an
Invision Power Board moderator to an admin. An attack uses the
announce_content parameter in an
index.php?/modcp/announcements/&action=create request. This is related
to the "<> Source" option.
|
| CVE-2017-8897 |
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has
pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18:
admin/convertutf8/index.php?controller= is the attack vector. This UTF8
Converter vulnerability can easily be used to make a malicious
announcement affecting any Invision Power Board user who views the
announcement.
|
| CVE-2017-8896 |
ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before
9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages
by injecting code in url parameters.
|
| CVE-2017-8892 |
Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3
allows remote attackers to inject arbitrary web script or HTML
persistently via the name of an uploaded image.
|
| CVE-2017-8876 |
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to
content/content.blueprintssections.php.
|
| CVE-2017-8839 |
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350,
and 2500 devices with firmware before
fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The
affected script is guest/preview.cgi.
|
| CVE-2017-8838 |
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and
2500 devices with firmware before
fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The
affected script is cgi-bin/HASync/hasync.cgi.
|
| CVE-2017-8833 |
Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE:
1.6.0 is not an official release but the vendor's README.md file offers
a link to v160.zip with a description of "Download latest
in-development version from github."
|
| CVE-2017-8832 |
Allen Disk 1.6 has XSS in the id parameter to downfile.php.
|
| CVE-2017-8808 |
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2
has XSS when the $wgShowExceptionDetails setting is false and the
browser sends non-standard URL escaping.
|
| CVE-2017-8801 |
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build
before 6152) and XG before CP 1352 has XSS via a crafted URI using a
blocked website.
|
| CVE-2017-8795 |
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
There is XSS in home/seos/courier/smtpg_add.html with the param
parameter.
|
| CVE-2017-8792 |
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
There is XSS in home/seos/courier/user_add.html with the param
parameter.
|
| CVE-2017-8780 |
GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during
a publish operation by an administrator, as demonstrated by a malformed
P element.
|
| CVE-2017-8778 |
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5
has XSS via a SCRIPT element in an issue attachment or avatar that is
an SVG document.
|
| CVE-2017-8763 |
Cross-site scripting (XSS) vulnerability in
modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI
1.8.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via a crafted URI that lacks the cid parameter.
|
| CVE-2017-8762 |
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a
page, as demonstrated by a crafted oncut attribute in a B element.
|
| CVE-2017-8760 |
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
There is XSS in courier/1000@/index.html with the auth_params
parameter. The device tries to use internal WAF filters to stop
specific XSS Vulnerabilities. However, these can be bypassed by using
some modifications to the payloads, e.g., URL encoding.
|
| CVE-2017-8654 |
Microsoft SharePoint Server 2010 Service Pack 2 allows a cross-site
scripting (XSS) vulnerability when it does not properly sanitize a
specially crafted web request to an affected SharePoint server, aka
"Microsoft Office SharePoint XSS Vulnerability".
|
| CVE-2017-8629 |
Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of
privilege vulnerability when it fails to properly sanitize a specially
crafted web request to an affected SharePoint server, aka "Microsoft
SharePoint XSS Vulnerability".
|
| CVE-2017-8569 |
Microsoft SharePoint Server allows an elevation of privilege
vulnerability due to the way that it sanitizes a specially crafted web
request to an affected SharePoint server, aka "SharePoint Server XSS
Vulnerability".
|
| CVE-2017-8551 |
An elevation of privilege vulnerability exists when Microsoft
SharePoint software fails to properly sanitize a specially crafted
requests, aka "Microsoft SharePoint XSS vulnerability".
|
| CVE-2017-8514 |
An information disclosure vulnerability exists when Microsoft
SharePoint software fails to properly sanitize a specially crafted
requests, aka "Microsoft SharePoint Reflective XSS Vulnerability".
|
| CVE-2017-8440 |
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS)
vulnerability in the Discover page that could allow an attacker to
obtain sensitive information from or perform destructive actions on
behalf of other Kibana users.
|
| CVE-2017-8439 |
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug
in the Time Series Visual Builder. This bug could allow an attacker to
obtain sensitive information from Kibana users.
|
| CVE-2017-8384 |
Craft CMS before 2.6.2976 allows XSS attacks because an array returned
by HttpRequestService::getSegments() and getActionSegments() need not
be zero-based. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2017-8052.
|
| CVE-2017-8376 |
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is
mishandled during a mouse operation by an administrator.
|
| CVE-2017-8304 |
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
courier/1000@/oauth/playground/callback.html allows XSS with a crafted
URI.
|
| CVE-2017-8302 |
Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, related to
admin/core/views/carch/list.cfm,
admin/core/views/carch/loadsiteflat.cfm,
admin/core/views/cusers/inc/dsp_nextn.cfm,
admin/core/views/cusers/inc/dsp_search_form.cfm,
admin/core/views/cusers/inc/dsp_users_list.cfm,
admin/core/views/cusers/list.cfm, and
admin/core/views/cusers/listusers.cfm.
|
| CVE-2017-8298 |
cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a
"Posts > Add New" action, and during creation of new tags and users.
|
| CVE-2017-8139 |
HedEx Earlier than V200R006C00 versions have the stored cross-site
scripting (XSS) vulnerability. Attackers can exploit the vulnerability
to plant malicious scripts into the configuration file to interrupt
the services of legitimate users.
|
| CVE-2017-8127 |
The UMA product with software V200R001 has a cross-site scripting
(XSS) vulnerability due to insufficient input validation. An attacker
could craft malicious links or scripts to launch XSS attacks.
|
| CVE-2017-8125 |
The UMA product with software V200R001 and V300R001 has a cross-site
scripting (XSS) vulnerability due to insufficient input validation. An
attacker could craft malicious links or scripts to launch XSS attacks.
|
| CVE-2017-8103 |
In MyBB before 1.8.11, the Email MyCode component allows XSS, as
demonstrated by an onmouseover event.
|
| CVE-2017-8102 |
Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an
admin's cookie and other information by composing a new entry as an
editor user. This is related to lack of the serendipity_event_xsstrust
plugin and a set_config error in that plugin.
|
| CVE-2017-8085 |
In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in
framework/modules/file/connector/elfinder.php.
|
| CVE-2017-8052 |
Craft CMS before 2.6.2974 allows XSS attacks.
|
| CVE-2017-8044 |
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and
1.4.x versions prior to 1.4.3), certain pages allow code to be injected
into the DOM environment through query parameters, leading to XSS
attacks.
|
| CVE-2017-8041 |
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior
to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS
attack on certain Single Sign-On service UI pages by inputting code in
the text field for an organization name.
|
| CVE-2017-8000 |
In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA
Security Console Administrator could craft a token profile and store
the profile name in the RSA Authentication Manager database. The
profile name could include a crafted script (with an XSS payload) that
could be executed when viewing or editing the assigned token profile in
the token by another administrator's browser session.
|
| CVE-2017-7998 |
Multiple cross-site scripting (XSS) vulnerabilities in Gespage before
7.4.9 allow remote attackers to inject arbitrary web script or HTML
via the (1) printer name when adding a printer in the admin panel or
(2) username parameter to webapp/users/user_reg.jsp.
|
| CVE-2017-7992 |
Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php
v2.8.17 is vulnerable to a reflected XSS in
examples/consumer-authentication/cruise.php via the URI, as
demonstrated by the cavv parameter.
|
| CVE-2017-7990 |
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with
resultant XSS, in which administrative authentication is hijacked to
insert JavaScript into a name field in
webapp/reports/manageReports.jsp.
|
| CVE-2017-7987 |
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of
file and folder names leads to XSS vulnerabilities in the template
manager component.
|
| CVE-2017-7986 |
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering
of specific HTML attributes leads to XSS vulnerabilities in various
components.
|
| CVE-2017-7985 |
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering
of multibyte characters leads to XSS vulnerabilities in various
components.
|
| CVE-2017-7984 |
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering
leads to XSS in the template manager component.
|
| CVE-2017-7953 |
INFOR EAM V11.0 Build 201410 has XSS via comment fields.
|
| CVE-2017-7944 |
XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install
DB failure error message in page_dbsettings.php.
|
| CVE-2017-7897 |
A cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x
before 2.3.2) Timeline include page, used in My View (my_view_page.php)
and User Information (view_user_page.php) pages, allows remote
attackers to inject arbitrary code (if CSP settings permit it) through
crafted PATH_INFO in a URL, due to use of unsanitized
$_SERVER['PHP_SELF'] to generate URLs.
|
| CVE-2017-7896 |
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1
before CP 1644 has XSS.
|
| CVE-2017-7891 |
sourcebans-pp (SourceBans++) 1.5.4.7 has XSS in admin.comms.php via the
rebanid parameter.
|
| CVE-2017-7887 |
Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall
parameter.
|
| CVE-2017-7871 |
trollepierre/tdm before 2017-04-13 is vulnerable to a reflected XSS in
tdm-master/webhook.php (challenge parameter).
|
| CVE-2017-7855 |
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS
vulnerability discovered in the "language" parameter.
|
| CVE-2017-7739 |
A reflected Cross-site Scripting (XSS) vulnerability in web proxy
disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to
5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject
arbitrary web script or HTML in the context of the victim's browser
via sending a maliciously crafted URL to the victim.
|
| CVE-2017-7736 |
A stored Cross-site Scripting (XSS) vulnerability in Fortinet FortiWeb
webUI Certificate View page in 5.8.0, 5.7.1 and earlier, allows
attackers to inject arbitrary web script or HTML via special crafted
malicious certificate import.
|
| CVE-2017-7733 |
A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0
to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute
arbitrary javascript code via webUI "Login Disclaimer" redir
parameter.
|
| CVE-2017-7732 |
A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet
FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through
5.3.9 customized pre-authentication webmail login page allows attacker
to inject arbitrary web script or HTML via crafted HTTP requests.
|
| CVE-2017-7725 |
concrete5 8.1.0 places incorrect trust in the HTTP Host header during
caching, if the administrator did not define a "canonical" URL on
installation of concrete5 using the "Advanced Options" settings. Remote
attackers can make a GET request with any domain name in the Host
header; this is stored and allows for arbitrary domains to be set for
certain links displayed to subsequent visitors, potentially an XSS
vector.
|
| CVE-2017-7723 |
XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the
e-mail subject or body.
|
| CVE-2017-7678 |
In Apache Spark before 2.2.0, it is possible for an attacker to take
advantage of a user's trust in the server to trick them into visiting
a link that points to a shared Spark cluster and submits data
including MHTML to the Spark master, or history server. This data,
which could contain a script, would then be reflected back to the user
and could be evaluated and executed by MS Windows-based clients. It is
not an attack on Spark itself, but on the user, who may then execute
the script inadvertently when viewing elements of the Spark web UIs.
|
| CVE-2017-7666 |
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery
(CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.
|
| CVE-2017-7665 |
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain
user input components in the UI which had been guarding for some forms
of XSS issues but were insufficient.
|
| CVE-2017-7663 |
Both global and Room chat are vulnerable to XSS attack in Apache
OpenMeetings 3.2.0.
|
| CVE-2017-7626 |
The "Smart related articles" extension 1.1 for Joomla! has XSS in
dialog.php (n_art,type in GET Method).
|
| CVE-2017-7591 |
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site
scripting (XSS) attacks within the Admin UI, as demonstrated by the
_sortKeys parameter to the authzRoles script under managed/user/.
|
| CVE-2017-7590 |
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site
scripting (XSS) attacks within the Admin UI, as demonstrated by a
crafted Managed Object Name.
|
| CVE-2017-7583 |
ILIAS before 5.2.3 has XSS via SVG documents.
|
| CVE-2017-7579 |
inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.
|
| CVE-2017-7554 |
It was found that the App Studio component of RHMAP 4.4 executes
javascript provided by a user. An attacker could use this flaw to
execute a stored XSS attack on an application administrator using App
Studio.
|
| CVE-2017-7430 |
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager
3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
|
| CVE-2017-7425 |
Multiple potential reflected XSS issues exist in NetIQ iManager
versions before 2.7.7 Patch 10 HF2 and 3.0.3.2.
|
| CVE-2017-7422 |
Reflected and stored Cross-Site Scripting (XSS, CWE-79)
vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and
Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2
before Hotfix 9 allow remote authenticated attackers to bypass
protection mechanisms (CWE-693) and other security features, if this
component is configured. Note esfadmingui is not enabled by default.
|
| CVE-2017-7421 |
Reflected and stored Cross-Site Scripting (XSS, CWE-79)
vulnerabilities in Directory Server (aka Enterprise Server
Administration web UI) and ESMAC (aka Enterprise Server Monitor and
Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3
and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before
Hotfix 9 allow remote authenticated attackers to bypass protection
mechanisms (CWE-693) and other security features.
|
| CVE-2017-7416 |
ntopng before 3.0 allows XSS because GET and POST parameters are
improperly validated.
|
| CVE-2017-7409 |
Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect
external interface via crafted request parameters, aka PAN-SA-2017-0011
and PAN-70674.
|
| CVE-2017-7400 |
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0
allows remote authenticated administrators to conduct XSS attacks via a
crafted federation mapping.
|
| CVE-2017-7391 |
A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The
vulnerability exists due to insufficient filtration of user-supplied
data (prefix) passed to the
'magmi-git-master/magmi/web/ajax_gettime.php' URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-7390 |
A Cross-Site Scripting (XSS) was discovered in 'SocialNetwork v1.2.1'.
The vulnerability exists due to insufficient filtration of
user-supplied data (mail) passed to the
'SocialNetwork-andrea/app/template/pw_forgot.php' URL. An attacker
could execute arbitrary HTML and script code in a browser in the
context of the vulnerable website.
|
| CVE-2017-7389 |
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass
Release_3.5.4'. The vulnerabilities exist due to insufficient
filtration of user-supplied data (meeting_id, user) passed to the
'openeclass-master/modules/tc/webconf/webconf.php' URL. An attacker
could execute arbitrary HTML and script code in a browser in the
context of the vulnerable website.
|
| CVE-2017-7388 |
A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The
vulnerability exists due to insufficient filtration of user-supplied
data (token) passed to the
'wallacepos-master/myaccount/resetpassword.php' URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-7387 |
TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a
reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID
parameter).
|
| CVE-2017-7386 |
citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in
symetrie-master/app/commands/page.php (model parameter).
|
| CVE-2017-7384 |
Cross-site scripting (XSS) vulnerability in FlipBuilder Flip PDF
allows remote attackers to inject arbitrary web script or HTML via the
currentHTMLURL parameter.
|
| CVE-2017-7363 |
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS
attack.
|
| CVE-2017-7362 |
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS
attack.
|
| CVE-2017-7361 |
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS
attack.
|
| CVE-2017-7360 |
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
|
| CVE-2017-7359 |
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
|
| CVE-2017-7352 |
Stored Cross-site scripting (XSS) vulnerability in Pure Storage Purity
4.7.5 allows remote authenticated users to inject arbitrary web script
or HTML via the "host" parameter on the 'System > Configuration > SNMP
> Add SNMP Trap Manager' screen.
|
| CVE-2017-7335 |
A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x
(6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x
(8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows an authenticated user to inject
arbitrary web script or HTML via non-sanitized parameters "refresh"
and "branchtotable" present in HTTP POST requests.
|
| CVE-2017-7320 |
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier
does not properly constrain the language parameter, which allows
remote attackers to conduct Cookie-Bombing attacks and cause a denial
of service (cookie quota exhaustion), or conduct HTTP Response
Splitting attacks with resultant XSS, via an invalid parameter value.
|
| CVE-2017-7316 |
An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is
XSS on the 404 page.
|
| CVE-2017-7309 |
A cross-site scripting (XSS) vulnerability in the MantisBT
Configuration Report page (adm_config_report.php) allows remote
attackers to inject arbitrary code (if CSP settings permit it) through
a crafted 'config_option' parameter. This is fixed in 1.3.9, 2.1.3, and
2.2.3.
|
| CVE-2017-7298 |
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add
a new course" page, as demonstrated by a crafted attribute of an SVG
element.
|
| CVE-2017-7296 |
An issue was discovered in Contiki Operating System 3.0. A Persistent
XSS vulnerability is present in the MQTT/IBM Cloud Config page (aka
mqtt.html) of cc26xx-web-demo. The cc26xx-web-demo features a webserver
that runs on a constrained device. That particular page allows a user
to remotely configure that device's operation by sending HTTP POST
requests. The vulnerability consists of improper input sanitisation of
the text fields on the MQTT/IBM Cloud config page, allowing for
JavaScript code injection.
|
| CVE-2017-7288 |
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite
(ZCS) before 8.7.1 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2017-7276 |
There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before
7.03.019.
|
| CVE-2017-7271 |
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework
before 2.0.11, when development mode is used, allows remote attackers
to inject arbitrary web script or HTML via crafted request data that is
mishandled on the debug-mode exception screen.
|
| CVE-2017-7257 |
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add
Article" feature via the m1_content parameter. Someone must login to
conduct the attack.
|
| CVE-2017-7256 |
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add
Article" feature via the m1_summary parameter. Someone must login to
conduct the attack.
|
| CVE-2017-7255 |
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add
Article" feature via the m1_title parameter. Someone must login to
conduct the attack.
|
| CVE-2017-7251 |
A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The
vulnerability exists due to insufficient filtration of user-supplied
data (preview) passed to the
"pi-develop/www/script/editor/markitup/preview/markdown.php" URL. An
attacker could execute arbitrary HTML and script code in a browser in
the context of the vulnerable website.
|
| CVE-2017-7250 |
A Cross-Site Scripting (XSS) was discovered in Gazelle before
2017-03-19. The vulnerability exists due to insufficient filtration of
user-supplied data (action) passed to the
'Gazelle-master/sections/tools/finances/bitcoin_balance.php' URL. An
attacker could execute arbitrary HTML and script code in a browser in
the context of the vulnerable website.
|
| CVE-2017-7249 |
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before
2017-03-19. The vulnerabilities exist due to insufficient filtration of
user-supplied data (action, userid) passed to the
'Gazelle-master/sections/tools/data/ocelot_info.php' URL. An attacker
could execute arbitrary HTML and script code in a browser in the
context of the vulnerable website.
|
| CVE-2017-7248 |
A Cross-Site Scripting (XSS) was discovered in Gazelle before
2017-03-19. The vulnerability exists due to insufficient filtration of
user-supplied data (type) passed to the
'Gazelle-master/sections/better/transcode.php' URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-7247 |
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before
2017-03-19. The vulnerabilities exist due to insufficient filtration of
user-supplied data (torrents, size) passed to the
'Gazelle-master/sections/tools/managers/multiple_freeleech.php' URL. An
attacker could execute arbitrary HTML and script code in a browser in
the context of the vulnerable website.
|
| CVE-2017-7242 |
Multiple Cross-Site Scripting (XSS) were discovered in admin/modules
components in SLiMS 7 Cendana through 2017-03-23: the keywords
parameter to bibliography/checkout_item.php, bibliography/dl_print.php,
bibliography/item.php, bibliography/item_barcode_generator.php,
bibliography/printed_card.php, circulation/loan_rules.php,
master_file/author.php, master_file/coll_type.php, and
master_file/doc_language.php and the quickReturnID field to
circulation/ajax_action.php.
|
| CVE-2017-7241 |
A cross-site scripting (XSS) vulnerability in the MantisBT Move
Attachments page (move_attachments_page.php, part of admin tools)
allows remote attackers to inject arbitrary code through a crafted
'type' parameter, if Content Security Protection (CSP) settings allows
it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this
vulnerability is not exploitable if the admin tools directory is
removed, as recommended in the "Post-installation and upgrade tasks" of
the MantisBT Admin Guide. A reminder to do so is also displayed on the
login page.
|
| CVE-2017-7233 |
Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18
relies on user input in some cases to redirect the user to an "on
success" URL. The security check for these redirects (namely
``django.utils.http.is_safe_url()``) considered some numeric URLs
"safe" when they shouldn't be, aka an open redirect vulnerability.
Also, if a developer relies on ``is_safe_url()`` to provide safe
redirect targets and puts such a URL into a link, they could suffer
from an XSS attack.
|
| CVE-2017-7222 |
A cross-site scripting (XSS) vulnerability in MantisBT before 2.1.1
allows remote attackers to inject arbitrary HTML or JavaScript (if
MantisBT's CSP settings permit it) by modifying 'window_title' in the
application configuration. This requires privileged access to MantisBT
configuration management pages (i.e., administrator access rights) or
altering the system configuration file (config_inc.php).
|
| CVE-2017-7205 |
A Cross-Site Scripting (XSS) was discovered in GamePanelX-V3 3.0.12.
The vulnerability exists due to insufficient filtration of
user-supplied data (a) passed to the
"GamePanelX-V3-master/ajax/ajax.php" URL. An attacker could execute
arbitrary HTML and script code in a browser in the context of the
vulnerable website.
|
| CVE-2017-7204 |
A Cross-Site Scripting (XSS) was discovered in imdbphp 5.1.1. The
vulnerability exists due to insufficient filtration of user-supplied
data (name) passed to the "imdbphp-master/demo/search.php" URL. An
attacker could execute arbitrary HTML and script code in a browser in
the context of the vulnerable website.
|
| CVE-2017-7203 |
A Cross-Site Scripting (XSS) was discovered in ZoneMinder before
1.30.2. The vulnerability exists due to insufficient filtration of
user-supplied data (postLoginQuery) passed to the
"ZoneMinder-master/web/skins/classic/views/js/postlogin.js.php" URL.
An attacker could execute arbitrary HTML and script code in a browser
in the context of the vulnerable website.
|
| CVE-2017-7202 |
Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana
before 2017-03-16. The vulnerabilities exist due to insufficient
filtration of user-supplied data (id) passed to the
'slims7_cendana-master/template/default/detail_template.php' and
'slims7_cendana-master/template/default-rtl/detail_template.php' URLs.
An attacker could execute arbitrary HTML and script code in a browser
in the context of the vulnerable website.
|
| CVE-2017-7188 |
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a
base64-encoded SCRIPT element within a data: URL in the returnUrl
parameter to default/toggleCollapse.
|
| CVE-2017-7109 |
An issue was discovered in certain Apple products. iOS before 11 is
affected. Safari before 11 is affected. iCloud before 7.0 on Windows
is affected. iTunes before 12.7 on Windows is affected. tvOS before 11
is affected. The issue involves the "WebKit" component. A cross-site
scripting (XSS) vulnerability allows remote attackers to inject
arbitrary web script or HTML via crafted web content that incorrectly
interacts with the Application Cache policy.
|
| CVE-2017-7089 |
An issue was discovered in certain Apple products. iOS before 11 is
affected. Safari before 11 is affected. iCloud before 7.0 on Windows
is affected. The issue involves the "WebKit" component. It allows
remote attackers to conduct Universal XSS (UXSS) attacks via a crafted
web site that is mishandled during parent-tab processing.
|
| CVE-2017-7059 |
A DOMParser XSS issue was discovered in certain Apple products. iOS
before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS
before 10.2.2 is affected. The issue involves the "WebKit" component.
|
| CVE-2017-7038 |
A DOMParser XSS issue was discovered in certain Apple products. iOS
before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS
before 10.2.2 is affected. The issue involves the "WebKit" component.
|
| CVE-2017-6973 |
A cross-site scripting (XSS) vulnerability in the MantisBT
Configuration Report page (adm_config_report.php) allows remote
attackers to inject arbitrary code through a crafted 'action'
parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.
|
| CVE-2017-6958 |
An XSS vulnerability in the MantisBT Source Integration Plugin (before
2.0.2) search result page allows an attacker to inject arbitrary HTML
or JavaScript (if MantisBT's CSP settings permit it) by crafting any
valid parameter.
|
| CVE-2017-6878 |
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows
remote authenticated users to inject arbitrary web script or HTML via
the name_2 parameter to admin/column/delete.php.
|
| CVE-2017-6877 |
Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim
0.7.1 and earlier allows remote attackers to inject arbitrary web
script.
|
| CVE-2017-6818 |
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is
cross-site scripting (XSS) via taxonomy term names.
|
| CVE-2017-6817 |
In WordPress before 4.7.3 (wp-includes/embed.php), there is
authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
|
| CVE-2017-6814 |
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting
(XSS) via Media File Metadata. This is demonstrated by both (1)
mishandling of the playlist shortcode in the wp_playlist_shortcode
function in wp-includes/media.php and (2) mishandling of meta
information in the renderTracks function in
wp-includes/js/mediaelement/wp-playlist.js.
|
| CVE-2017-6812 |
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in
inc/admin/template_files/admin.vote.php (id parameter).
|
| CVE-2017-6811 |
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in
inc/admin/template_files/admin.shop.php (id parameter).
|
| CVE-2017-6810 |
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in
inc/admin/template_files/admin.fplinks.php (linkid parameter).
|
| CVE-2017-6809 |
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in
inc/admin/template_files/admin.donate.php (id parameter).
|
| CVE-2017-6808 |
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in
inc/admin/template_files/admin.faq.php (id parameter).
|
| CVE-2017-6799 |
A cross-site scripting (XSS) vulnerability in view_filters_page.php in
MantisBT before 2.2.1 allows remote attackers to inject arbitrary
JavaScript via the 'view_type' parameter.
|
| CVE-2017-6797 |
A cross-site scripting (XSS) vulnerability in
bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before
2.2.1 allows remote attackers to inject arbitrary JavaScript via the
'action_type' parameter.
|
| CVE-2017-6789 |
A vulnerability in the Cisco Unified Intelligence Center web interface
could allow an unauthenticated, remote attacker to impact the integrity
of the system by executing a Document Object Model (DOM)-based,
environment or client-side cross-site scripting (XSS) attack. The
vulnerability occurs because user-supplied data in the DOM input is not
validated. An attacker could exploit this vulnerability by sending
crafted URLs that contain malicious DOM statements to the affected
system. A successful exploit could allow the attacker to affect the
integrity of the system by manipulating the database. Known Affected
Releases 11.0(1)ES10. Cisco Bug IDs: CSCvf18325.
|
| CVE-2017-6788 |
The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client
Software contains a vulnerability that could allow an unauthenticated,
remote attacker to conduct a cross-site scripting (XSS) attack against
a user of the affected software. The vulnerability is due to
insufficient input validation of some parameters that are passed to
the WebLaunch function of the affected software. An attacker could
exploit this vulnerability by convincing a user to access a malicious
link or by intercepting a user request and injecting malicious code
into the request. Cisco Bug IDs: CSCvf12055. Known Affected Releases:
98.89(40).
|
| CVE-2017-6776 |
A vulnerability in the web framework of Cisco Elastic Services
Controller (ESC) could allow an unauthenticated, remote attacker to
conduct a cross-site scripting (XSS) attack against a user of the web
interface. The vulnerability is due to insufficient validation of
user-supplied input by the affected software. An attacker could
exploit this vulnerability by convincing a user to access a malicious
link or by intercepting a user request and injecting malicious code
into the request. An exploit could allow the attacker to execute
arbitrary script code in the context of the affected site or allow the
attacker to access sensitive browser-based information. Cisco Bug IDs:
CSCvd76324. Known Affected Releases: 2.2(9.76) and 2.3(1).
|
| CVE-2017-6769 |
A vulnerability in the web-based management interface of the Cisco
Secure Access Control System (ACS) could allow an authenticated, remote
attacker to conduct a stored cross-site scripting (XSS) attack against
a user of the web interface of the affected system. More Information:
CSCve70587. Known Affected Releases: 5.8(0.8) 5.8(1.5).
|
| CVE-2017-6765 |
A vulnerability in the web-based management interface of Cisco Adaptive
Security Appliance (ASA) 9.1(6.11) and 9.4(1.2) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack against a user of the web-based management interface of an
affected device, aka WebVPN XSS. The vulnerability is due to
insufficient validation of user-supplied input by the web-based
management interface of an affected device. An attacker could exploit
this vulnerability by persuading a user of the interface to click a
crafted link. A successful exploit could allow the attacker to execute
arbitrary script code in the context of the interface or allow the
attacker to access sensitive browser-based information. Cisco Bug IDs:
CSCve19179.
|
| CVE-2017-6764 |
A vulnerability in the web-based management interface of Cisco Adaptive
Security Appliance (ASA) 9.5(1) could allow an authenticated, remote
attacker to conduct a cross-site scripting (XSS) attack against a user
of the web-based management interface of an affected device. The
vulnerability is due to insufficient validation of user-supplied input
by the web-based management interface of an affected device. An
attacker could exploit this vulnerability by persuading a user of the
interface to click a crafted link. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the
interface or allow the attacker to access sensitive browser-based
information. Cisco Bug IDs: CSCvd82064.
|
| CVE-2017-6762 |
A vulnerability in the web-based management interface of Cisco Jabber
Guest Server 10.6(9), 11.0(0), and 11.0(1) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack against a user of the web-based management interface of
the affected software. The vulnerability is due to insufficient
validation of user-supplied input by the web-based management interface
of the affected software. An attacker could exploit this vulnerability
by persuading a user of the interface to click a crafted link. A
successful exploit could allow the attacker to execute arbitrary script
code in the context of the interface or allow the attacker to access
sensitive browser-based information. Cisco Bug IDs: CSCve09718.
|
| CVE-2017-6761 |
A vulnerability in the web-based management interface of Cisco Finesse
10.6(1) and 11.5(1) could allow an unauthenticated, remote attacker to
conduct a cross-site scripting (XSS) attack against a user of the
web-based management interface of an affected device. The vulnerability
is due to insufficient validation of user-supplied input by the
web-based management interface of an affected device. An attacker could
exploit this vulnerability by persuading a user of the interface to
click a crafted link. A successful exploit could allow the attacker to
execute arbitrary script code in the context of the interface or allow
the attacker to access sensitive browser-based information. Cisco Bug
IDs: CSCvd96744.
|
| CVE-2017-6755 |
A vulnerability in the web portal of the Cisco Prime Collaboration
Provisioning (PCP) Tool could allow an unauthenticated, remote attacker
to conduct a cross-site scripting (XSS) attack against a user of the
web interface of an affected system. More Information: CSCvc90312.
Known Affected Releases: 12.1.
|
| CVE-2017-6749 |
A vulnerability in the web-based management interface of Cisco Web
Security Appliance (WSA) could allow an authenticated, remote attacker
to conduct a stored cross-site scripting (XSS) attack against a user of
the web-based management interface of an affected device. Affected
Products: virtual and hardware versions of Cisco Web Security Appliance
(WSA). More Information: CSCvd88865. Known Affected Releases:
10.1.0-204.
|
| CVE-2017-6734 |
A vulnerability in the web-based management interface of Cisco Identity
Services Engine (ISE) Software could allow an authenticated, remote
attacker to conduct a cross-site scripting (XSS) attack against a user
of the web interface of an affected device, related to the Guest
Portal. More Information: CSCvd74794. Known Affected Releases:
1.3(0.909) 2.1(0.800).
|
| CVE-2017-6733 |
A vulnerability in the web-based application interface of the Cisco
Identity Services Engine (ISE) portal could allow an unauthenticated,
remote attacker to conduct a stored cross-site scripting (XSS) attack
against a user of the web interface of an affected system. More
Information: CSCvd87482. Known Affected Releases: 2.1(102.101)
2.2(0.283) 2.3(0.151).
|
| CVE-2017-6725 |
A vulnerability in the web framework code of Cisco Prime Infrastructure
could allow an unauthenticated, remote attacker to conduct a cross-site
scripting (XSS) attack against a user of the web interface of an
affected system. More Information: CSCuw65833 CSCuw65837. Known
Affected Releases: 2.2(2).
|
| CVE-2017-6724 |
A vulnerability in the web framework code of Cisco Prime Infrastructure
could allow an unauthenticated, remote attacker to conduct a cross-site
scripting (XSS) attack against a user of the web interface of an
affected system. More Information: CSCuw65843. Known Affected Releases:
3.1(0.0).
|
| CVE-2017-6717 |
A vulnerability in the web framework of Cisco Firepower Management
Center could allow an authenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against a user of the web interface.
More Information: CSCvc38801. Known Affected Releases: 6.0.1.3 6.2.1.
Known Fixed Releases: 6.2.1.
|
| CVE-2017-6716 |
A vulnerability in the web framework code of Cisco Firepower Management
Center could allow an authenticated, remote attacker to conduct a
stored cross-site scripting (XSS) attack against a user of the web
interface of an affected system. Affected Products: Cisco Firepower
Management Center Software Releases prior to 6.0.0.0. More Information:
CSCuy88785. Known Affected Releases: 5.4.1.6.
|
| CVE-2017-6715 |
A vulnerability in the web framework of Cisco Firepower Management
Center could allow an authenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against a user of the web interface.
Affected Products: Cisco Firepower Management Center Releases 5.4.1.x
and prior. More Information: CSCuy88951. Known Affected Releases:
5.4.1.6.
|
| CVE-2017-6702 |
A vulnerability in the web framework of Cisco SocialMiner could allow
an unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack against a user of the web interface of an affected system.
More Information: CSCve15285. Known Affected Releases: 11.5(1).
|
| CVE-2017-6701 |
A vulnerability in the web application interface of the Cisco Identity
Services Engine (ISE) portal could allow an unauthenticated, remote
attacker to conduct a stored cross-site scripting (XSS) attack against
a user of the web interface of an affected system. More Information:
CSCvd49141. Known Affected Releases: 2.1(102.101).
|
| CVE-2017-6700 |
A vulnerability in the web-based management interface of Cisco Prime
Infrastructure (PI) and Evolved Programmable Network Manager (EPNM)
could allow an unauthenticated, remote attacker to conduct a Document
Object Model (DOM) based (environment or client-side) cross-site
scripting (XSS) attack against a user of the web-based management
interface of an affected device. More Information: CSCvc24620
CSCvc49586. Known Affected Releases: 3.1(1) 2.0(4.0.45B).
|
| CVE-2017-6699 |
A vulnerability in the web-based management interface of Cisco Prime
Infrastructure (PI) and Evolved Programmable Network Manager (EPNM)
could allow an unauthenticated, remote attacker to conduct a reflected
cross-site scripting (XSS) attack against a user of the web-based
management interface of an affected device. More Information:
CSCvc24616 CSCvc35363 CSCvc49574. Known Affected Releases: 3.1(1)
2.0(4.0.45B).
|
| CVE-2017-6675 |
A vulnerability in the web interface of Cisco Industrial Network
Director could allow an unauthenticated, remote attacker to conduct a
reflected cross-site scripting (XSS) attack against an affected system.
More Information: CSCvd25405. Known Affected Releases: 1.1(0.176).
|
| CVE-2017-6661 |
A vulnerability in the web-based management interface of Cisco Email
Security Appliance (ESA) and Cisco Content Security Management
Appliance (SMA) could allow an unauthenticated, remote attacker to
conduct a cross-site scripting (XSS) attack against a user of the
web-based management interface of an affected device, aka Message
Tracking XSS. More Information: CSCvd30805 CSCvd34861. Known Affected
Releases: 10.0.0-203 10.1.0-049.
|
| CVE-2017-6654 |
A vulnerability in the web-based management interface of Cisco Unified
Communications Manager 10.5 through 11.5 could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack against a user of the web-based management interface of an
affected device. The vulnerability is due to insufficient validation of
user-supplied input by the web-based management interface of an
affected device. An attacker could exploit this vulnerability by
persuading a user of the interface to click a crafted link. A
successful exploit could allow the attacker to execute arbitrary script
code in the context of the interface or allow the attacker to access
sensitive browser-based information. Cisco Bug IDs: CSCvc06608.
|
| CVE-2017-6618 |
A vulnerability in the web-based GUI of Cisco Integrated Management
Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker
to perform a cross-site scripting (XSS) attack. The vulnerability is
due to insufficient validation of user-supplied input by the affected
software. An attacker could exploit this vulnerability by persuading an
authenticated user of the web-based GUI on an affected system to follow
a malicious link. A successful exploit could allow the attacker to
execute arbitrary code in the context of the web-based GUI on the
affected system. Cisco Bug IDs: CSCvd14587.
|
| CVE-2017-6611 |
A vulnerability in the web framework code of Cisco Prime Infrastructure
2.2(2) could allow an unauthenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against the user of the web interface
of the affected system. The vulnerability is due to insufficient input
validation of some parameters passed to the web server. An attacker
could exploit this vulnerability by convincing the user to access a
malicious link or by intercepting the user request and injecting the
malicious code. An exploit could allow the attacker to execute
arbitrary script code in the context of the affected site or allow the
attacker to access sensitive browser-based information. Cisco Bug IDs:
CSCuw65830.
|
| CVE-2017-6605 |
A vulnerability in the web-based management interface of Cisco Identity
Services Engine (ISE) could allow an authenticated, remote attacker to
conduct a reflective cross-site scripting (XSS) attack against a user
of the web-based management interface of an affected device. More
Information: CSCvc85415. Known Affected Releases: 2.1(0.800).
|
| CVE-2017-6562 |
XSS in Agora-Project 3.2.2 exists with an
index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS]
attack.
|
| CVE-2017-6561 |
XSS in Agora-Project 3.2.2 exists with an
index.php?ctrl=object&action=[XSS] attack.
|
| CVE-2017-6560 |
XSS in Agora-Project 3.2.2 exists with an
index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.
|
| CVE-2017-6559 |
XSS in Agora-Project 3.2.2 exists with an
index.php?disconnect=1&msgNotif[]=[XSS] attack.
|
| CVE-2017-6556 |
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS)
2.1.6 allows remote authenticated users to inject arbitrary web script
or HTML via the "adminpage > sitesetting > General Settings >
globalmetadata" field.
|
| CVE-2017-6555 |
Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php
in CMS Made Simple 2.1.6 allows remote authenticated users to inject
arbitrary web script or HTML via the m1_description parameter (aka
"Design Manager > Categories > Category Description").
|
| CVE-2017-6547 |
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U,
RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W,
RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+,
RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and
RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W
routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+
B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro
routers with firmware before 3.0.0.4.380.9488 allows remote attackers
to inject arbitrary JavaScript by requesting filenames longer than 50
characters.
|
| CVE-2017-6544 |
Gargaj/wuhu through 2017-03-08 is vulnerable to a reflected XSS in
wuhu-master/www_admin/users.php (id parameter).
|
| CVE-2017-6541 |
Multiple Cross-Site Scripting (XSS) issues were discovered in
webpagetest 3.0. The vulnerabilities exist due to insufficient
filtration of user-supplied data (benchmark, time) passed to the
webpagetest-master/www/benchmarks/viewtest.php URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-6540 |
Multiple Cross-Site Scripting (XSS) issues were discovered in
webpagetest 3.0. The vulnerabilities exist due to insufficient
filtration of user-supplied data (configs) passed to the
webpagetest-master/www/benchmarks/compare.php URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-6539 |
Multiple Cross-Site Scripting (XSS) issues were discovered in
webpagetest 3.0. The vulnerabilities exist due to insufficient
filtration of user-supplied data (benchmark, time) passed to the
webpagetest-master/www/benchmarks/delta.php URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-6538 |
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0.
The vulnerability exists due to insufficient filtration of
user-supplied data (video) passed to the
webpagetest-master/www/speedindex/index.php URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-6537 |
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0.
The vulnerability exists due to insufficient filtration of
user-supplied data (bgcolor) passed to the
webpagetest-master/www/video/view.php URL. An attacker could execute
arbitrary HTML and script code in a browser in the context of the
vulnerable website.
|
| CVE-2017-6536 |
Multiple Cross-Site Scripting (XSS) issues were discovered in
webpagetest 3.0. The vulnerabilities exist due to insufficient
filtration of user-supplied data (url, pssid) passed to the
webpagetest-master/www/weblite.php URL. An attacker could execute
arbitrary HTML and script code in a browser in the context of the
vulnerable website.
|
| CVE-2017-6535 |
Multiple Cross-Site Scripting (XSS) issues were discovered in
webpagetest 3.0. The vulnerabilities exist due to insufficient
filtration of user-supplied data (benchmark, url) passed to the
webpagetest-master/www/benchmarks/trendurl.php URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-6534 |
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0.
The vulnerability exists due to insufficient filtration of
user-supplied data (pssid) passed to the webpagetest-master/www/pss.php
URL. An attacker could execute arbitrary HTML and script code in a
browser in the context of the vulnerable website.
|
| CVE-2017-6533 |
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0.
The vulnerability exists due to insufficient filtration of
user-supplied data (benchmark) passed to the
webpagetest-master/www/benchmarks/view.php URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-6518 |
Cross-site scripting (XSS) vulnerability in /sanadata/seo/index.asp in
SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web
script or HTML via the txtFrom parameter.
|
| CVE-2017-6511 |
andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in
index.php because of missing validation of the action parameter in
application/classes/application.php.
|
| CVE-2017-6509 |
Smith0r/burgundy-cms before 2017-03-06 is vulnerable to a reflected XSS
in admin/components/menu/views/menuitems.php (id parameter).
|
| CVE-2017-6503 |
WebUI in qBittorrent before 3.3.11 did not escape many values, which
could potentially lead to XSS.
|
| CVE-2017-6491 |
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI
1.8.1.1. The vulnerabilities exist due to insufficient filtration of
user-supplied data (tooltip_id, callback, args, cid) passed to the
EPESI-master/modules/Utils/Tooltip/req.php URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-6490 |
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI
1.8.1.1. The vulnerabilities exist due to insufficient filtration of
user-supplied data (cid, value, element, mode, tab, form_name, id)
passed to the EPESI-master/modules/Utils/RecordBrowser/grid.php URL. An
attacker could execute arbitrary HTML and script code in a browser in
the context of the vulnerable website.
|
| CVE-2017-6489 |
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI
1.8.1.1. The vulnerabilities exist due to insufficient filtration of
user-supplied data (element, state, cat, id, cid) passed to the
EPESI-master/modules/Utils/Watchdog/subscribe.php URL. An attacker
could execute arbitrary HTML and script code in a browser in the
context of the vulnerable website.
|
| CVE-2017-6488 |
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI
1.8.1.1. The vulnerabilities exist due to insufficient filtration of
user-supplied data (visible, tab, cid) passed to the
EPESI-master/modules/Utils/RecordBrowser/Filters/save_filters.php URL.
An attacker could execute arbitrary HTML and script code in a browser
in the context of the vulnerable website.
|
| CVE-2017-6487 |
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI
1.8.1.1. The vulnerabilities exist due to insufficient filtration of
user-supplied data (state, element, id, tab, cid) passed to the
"EPESI-master/modules/Utils/RecordBrowser/favorites.php" URL. An
attacker could execute arbitrary HTML and script code in a browser in
the context of the vulnerable website.
|
| CVE-2017-6486 |
A Cross-Site Scripting (XSS) issue was discovered in reasoncms before
4.7.1. The vulnerability exists due to insufficient filtration of
user-supplied data (nyroModalSel) passed to the
"reasoncms-master/www/nyroModal/demoSent.php" URL. An attacker could
execute arbitrary HTML and script code in a browser in the context of
the vulnerable website.
|
| CVE-2017-6485 |
A Cross-Site Scripting (XSS) issue was discovered in php-calendar
before 2017-03-03. The vulnerability exists due to insufficient
filtration of user-supplied data (errorMsg) passed to the
"php-calendar-master/error.php" URL. An attacker could execute
arbitrary HTML and script code in a browser in the context of the
vulnerable website.
|
| CVE-2017-6484 |
Multiple Cross-Site Scripting (XSS) issues were discovered in
INTER-Mediator 5.5. The vulnerabilities exist due to insufficient
filtration of user-supplied data (c and cred) passed to the
"INTER-Mediator-master/Auth_Support/PasswordReset/resetpassword.php"
URL. An attacker could execute arbitrary HTML and script code in a
browser in the context of the vulnerable website.
|
| CVE-2017-6483 |
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor
2.2.2. The vulnerabilities exist due to insufficient filtration of
user-supplied data passed to several pages (lang_code in
themes/*/admin/system_preferences/language_edit.tmpl.php). An attacker
could execute arbitrary HTML and script code in a browser in the
context of the vulnerable website.
|
| CVE-2017-6481 |
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam
1.2. The vulnerabilities exist due to insufficient filtration of
user-supplied data passed to several pages (instructions in
app/admin/instructions/preview.php; subnetId in
app/admin/powerDNS/refresh-ptr-records.php). An attacker could execute
arbitrary HTML and script code in a browser in the context of the
vulnerable website.
|
| CVE-2017-6480 |
groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS
in commons/browser.php (path parameter).
|
| CVE-2017-6479 |
FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a
reflected XSS in forums/search.php (search-by-topic parameter).
|
| CVE-2017-6478 |
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected
XSS in install/index.php (step parameter).
|
| CVE-2017-6446 |
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and
admin/users.php with the sortby and order parameters.
|
| CVE-2017-6443 |
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00
allows remote attackers to inject arbitrary web script or HTML via the
W_AD1 parameter to Forms/oadmin_1.
|
| CVE-2017-6394 |
Multiple Cross-Site Scripting (XSS) issues were discovered in OpenEMR
5.0.0 and 5.0.1-dev. The vulnerabilities exist due to insufficient
filtration of user-supplied data passed to the
"openemr-master/gacl/admin/object_search.php" URL (section_value;
src_form). An attacker could execute arbitrary HTML and script code in
a browser in the context of the vulnerable website.
|
| CVE-2017-6340 |
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before
CP 1746 does not sanitize a rest/commonlog/report/template name field,
which allows a 'Reports Only' user to inject malicious JavaScript while
creating a new report. Additionally, IWSVA implements incorrect access
control that allows any authenticated, remote user (even with low
privileges like 'Auditor') to create or modify reports, and
consequently take advantage of this XSS vulnerability. The JavaScript
is executed when victims visit reports or auditlog pages.
|
| CVE-2017-6103 |
Persistent XSS Vulnerability in Wordpress plugin AnyVar v0.1.1.
|
| CVE-2017-6102 |
Persistent XSS in wordpress plugin rockhoist-badges v1.2.2.
|
| CVE-2017-6099 |
Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in
PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote
attackers to inject arbitrary web script or HTML via the token
parameter.
|
| CVE-2017-6069 |
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any
tag, and can optionally insert XSS via the tags parameter.
|
| CVE-2017-6068 |
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can
create any block, and can optionally insert XSS via the content
parameter.
|
| CVE-2017-6067 |
Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom
form field.
|
| CVE-2017-6066 |
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can
perform any Edit Language action, and can optionally insert XSS via the
title parameter.
|
| CVE-2017-6061 |
Cross-site scripting (XSS) vulnerability in the help component of SAP
BusinessObjects Financial Consolidation 10.0.0.1933 allows remote
attackers to inject arbitrary web script or HTML via a GET request.
/finance/help/en/frameset.htm is the URI for this component. The vendor
response is SAP Security Note 2368106.
|
| CVE-2017-6003 |
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language
in portal/layout via the bottom two form fields.
|
| CVE-2017-6002 |
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add
any blog entry, and can optionally insert XSS into that entry via the
body parameter.
|
| CVE-2017-5998 |
Cross-site scripting (XSS) vulnerability in InterSect Alliance SNARE
Epilog for UNIX version 1.5 allows remote authenticated users to inject
arbitrary web script or HTML via the str_log_name parameter in a "Web
Admin Portal > Log Configuration > Add" action.
|
| CVE-2017-5942 |
An issue was discovered in the WP Mail plugin before 1.2 for WordPress.
The replyto parameter when composing a mail allows for a reflected XSS.
This would allow you to execute JavaScript in the context of the user
receiving the mail.
|
| CVE-2017-5938 |
Cross-site scripting (XSS) vulnerability in the nav_path function in
lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows
remote attackers to inject arbitrary web script or HTML via the
nav_data name.
|
| CVE-2017-5900 |
Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02
router with firmware NB16WV_R0.09 allows remote authenticated users to
inject arbitrary web script or HTML via the S801F0334 parameter to
hdd.htm.
|
| CVE-2017-5882 |
Cross-site scripting (XSS) vulnerability in index.asp in SANADATA
SanaCMS 7.3 allows remote attackers to inject arbitrary web script or
HTML via the search parameter.
|
| CVE-2017-5877 |
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack
against the /about-us/locations/index direction parameter.
|
| CVE-2017-5876 |
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack
against the /news-events/events date parameter.
|
| CVE-2017-5875 |
XSS was discovered in dotCMS 3.7.0, with an authenticated attack
against the /myAccount addressID parameter.
|
| CVE-2017-5874 |
CSRF exists on D-Link DIR-600M Rev. Cx devices before
v3.05ENB01_beta_20170306. This can be used to bypass authentication and
insert XSS sequences or possibly have unspecified other impact.
|
| CVE-2017-5870 |
Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin
3.0.15 allow remote attackers to inject arbitrary web script or HTML
via the (1) domain or (2) transport parameter to domain/add; the (3)
name parameter to mailbox/add/did/<domain id>; the (4) goto parameter
to alias/add/did/<domain id>; or the (5) captchatext parameter to
auth/lost-password.
|
| CVE-2017-5833 |
Cross-site scripting (XSS) vulnerability in the invocation code
generation for interstitial zones in Revive Adserver before 4.0.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified parameters.
|
| CVE-2017-5832 |
Cross-site scripting (XSS) vulnerability in Revive Adserver before
4.0.1 allows remote authenticated users to inject arbitrary web script
or HTML via the user's email address.
|
| CVE-2017-5673 |
In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum
message subject (aka topic subject) accepts JavaScript, leading to XSS.
Six files are affected: crypsis/layouts/message/item/default.php,
crypsis/layouts/message/item/top/default.php,
crypsis/layouts/message/item/bottom/default.php,
crypsisb3/layouts/message/item/default.php,
crypsisb3/layouts/message/item/top/default.php, and
crypsisb3/layouts/message/item/bottom/default.php. This is fixed in
5.0.5.
|
| CVE-2017-5621 |
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and
1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat
message or the content of a ticket article, when using either the REST
API or the WebSocket API.
|
| CVE-2017-5620 |
An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3,
and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of
getting downloaded. This creates an attack vector of executing code in
the domain of the application.
|
| CVE-2017-5616 |
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho
allows remote attackers to inject arbitrary web script or HTML via the
addendum parameter.
|
| CVE-2017-5612 |
Cross-site scripting (XSS) vulnerability in
wp-admin/includes/class-wp-posts-list-table.php in the posts list
table in WordPress before 4.7.2 allows remote attackers to inject
arbitrary web script or HTML via a crafted excerpt.
|
| CVE-2017-5608 |
Cross-site scripting (XSS) vulnerability in the image upload function
in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web
script or HTML via a crafted image filename.
|
| CVE-2017-5584 |
Cross-site scripting (XSS) vulnerability in the Management Web
Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x
before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2017-5553 |
Cross-site scripting (XSS) vulnerability in
plugins/markdown_plugin/_markdown.plugin.php in b2evolution before
6.8.5 allows remote authenticated users to inject arbitrary web script
or HTML via a javascript: URL.
|
| CVE-2017-5542 |
Cross-site scripting (XSS) vulnerability in
template/usererror.missing_extension.php in Symphony CMS before 2.6.10
allows remote attackers to inject arbitrary web script or HTML via the
existing-folder parameter.
|
| CVE-2017-5532 |
A vulnerability in the report renderer component of TIBCO
JasperReports Server, TIBCO JasperReports Server Community Edition,
TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports
Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO
Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and
Analytics for AWS, TIBCO Jaspersoft Studio, and TIBCO Jaspersoft
Studio for ActiveMatrix BPM may allow a subset of authorized users to
perform persistent cross-site scripting (XSS) attacks. Affected
releases are TIBCO JasperReports Server 6.2.3 and below; 6.3.0; 6.3.1;
6.3.2; 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0 and
below, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0 and
below, TIBCO JasperReports Library 6.2.3 and below; 6.3.0; 6.3.1;
6.3.2; 6.4.0; 6.4.1, TIBCO JasperReports Library for ActiveMatrix BPM
6.4.1 and below, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0 and
below, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0 and
below, TIBCO Jaspersoft Studio 6.2.3 and below; 6.3.0; 6.3.1; 6.3.2;
6.4.0, and TIBCO Jaspersoft Studio for ActiveMatrix BPM 6.4.0 and
below.
|
| CVE-2017-5528 |
Multiple JasperReports Server components contain vulnerabilities
which may allow authorized users to perform cross-site scripting
(XSS) and cross-site request forgery (CSRF) attacks. The impact of
this vulnerability includes the theoretical disclosure of sensitive
information. Affects TIBCO JasperReports Server (versions 6.1.1 and
below, 6.2.0, 6.2.1, and 6.3.0), TIBCO JasperReports Server Community
Edition (versions 6.3.0 and below), TIBCO JasperReports Server for
ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS
with Multi-Tenancy (versions 6.2.0 and below), and TIBCO Jaspersoft
Reporting and Analytics for AWS (versions 6.2.0 and below).
|
| CVE-2017-5516 |
Multiple cross-site scripting (XSS) vulnerabilities in the user forms
in GeniXCMS through 0.0.8 allow remote attackers to inject arbitrary
web script or HTML via crafted parameters.
|
| CVE-2017-5515 |
Cross-site scripting (XSS) vulnerability in the user prompt function in
GeniXCMS through 0.0.8 allows remote authenticated users to inject
arbitrary web script or HTML via tag names.
|
| CVE-2017-5494 |
Multiple cross-site scripting (XSS) vulnerabilities in the file types
table in b2evolution through 6.8.3 allow remote authenticated users to
inject arbitrary web script or HTML via a .swf file in a (1) comment
frame or (2) avatar frame.
|
| CVE-2017-5490 |
Cross-site scripting (XSS) vulnerability in the theme-name fallback
functionality in wp-includes/class-wp-theme.php in WordPress before
4.7.1 allows remote attackers to inject arbitrary web script or HTML
via a crafted directory name of a theme, related to
wp-admin/includes/class-theme-installer-skin.php.
|
| CVE-2017-5488 |
Multiple cross-site scripting (XSS) vulnerabilities in
wp-admin/update-core.php in WordPress before 4.7.1 allow remote
attackers to inject arbitrary web script or HTML via the (1) name or
(2) version header of a plugin.
|
| CVE-2017-5367 |
Multiple reflected XSS vulnerabilities exist within form and link input
parameters of ZoneMinder v1.30 and v1.29, an open-source CCTV server
web application, which allows a remote attacker to execute malicious
scripts within an authenticated client's browser. The URL is
/zm/index.php and sample parameters could include
action=login&view=postlogin[XSS] view=console[XSS] view=groups[XSS]
view=events&filter[terms][1][cnj]=and[XSS]
view=events&filter%5Bterms%5D%5B1%5D%5Bcnj%5D=and[XSS]
view=events&filter%5Bterms%5D%5B1%5D%5Bcnj%5D=[XSS]and
view=events&limit=1%22%3E%3C/a%3E[XSS] (among others).
|
| CVE-2017-5258 |
In version 3.5 and prior of Cambium Networks ePMP firmware, an
attacker who knows or can guess the RW community string can provide a
URL for a configuration file over SNMP with XSS strings in certain
SNMP OIDs, serve it via HTTP, and the affected device will perform a
configuration restore using the attacker's supplied config file,
including the inserted XSS strings.
|
| CVE-2017-5257 |
In version 3.5 and prior of Cambium Networks ePMP firmware, an
attacker who knows (or guesses) the SNMP read/write (RW) community
string can insert XSS strings in certain SNMP OIDs which will execute
in the context of the currently-logged on user.
|
| CVE-2017-5256 |
In version 3.5 and prior of Cambium Networks ePMP firmware, all
authenticated users have the ability to update the Device Name and
System Description fields in the web administration console, and those
fields are vulnerable to persistent cross-site scripting (XSS)
injection.
|
| CVE-2017-5241 |
Biscom Secure File Transfer version 5.1.1015 (and possibly prior) is
vulnerable to post-authentication persistent cross-site scripting
(XSS) in the "Name" and "Description" fields of a Workspace, as well
as the "Description" field of a File Details pane of a file stored in
a Workspace. This issue has been resolved in version 5.1.1025.
|
| CVE-2017-5197 |
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2.
The attack vector is a page name. An example payload is a crafted
JavaScript event handler within a malformed SVG element.
|
| CVE-2017-5191 |
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2
and 4.3 exists because Access Gateway Error pages do not validate the
HTTP Referer header.
|
| CVE-2017-5183 |
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as
an Identity Server, has XSS in the AssertionConsumerServiceURL field of
a signed AuthnRequest in a samlp:AuthnRequest document.
|
| CVE-2017-5179 |
Cross-site scripting (XSS) vulnerability in Tenable Nessus before
6.9.3 allows remote authenticated users to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2017-5045 |
XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows,
and Linux and 57.0.2987.108 for Android allowed detection of a blocked
iframe load, which allowed a remote attacker to brute force JavaScript
variables via a crafted HTML page.
|
| CVE-2017-4967 |
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x
versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and
these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions
prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in
the RabbitMQ management UI are vulnerable to XSS attacks.
|
| CVE-2017-4965 |
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x
versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and
these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions
prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in
the RabbitMQ management UI are vulnerable to XSS attacks.
|
| CVE-2017-4940 |
The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG,
5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG)
contains a vulnerability that may allow for stored cross-site
scripting (XSS). An attacker can exploit this vulnerability by
injecting Javascript, which might get executed when other users access
the Host Client.
|
| CVE-2017-4929 |
VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a
moderate Cross-Site Scripting (XSS) issue which may lead to
information disclosure.
|
| CVE-2017-4926 |
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability
that may allow for stored cross-site scripting (XSS). An attacker with
VC user privileges can inject malicious java-scripts which will get
executed when other VC users access the page.
|
| CVE-2017-4011 |
Embedding Script (XSS) in HTTP Headers vulnerability in the server in
McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote
attackers to get session/cookie information via modification of the
HTTP request.
|
| CVE-2017-3948 |
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee
Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows
authenticated users to inject arbitrary web script or HTML via
injecting malicious JavaScript into a user's browsing session.
|
| CVE-2017-3933 |
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network
Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to
view confidential information via a cross site request forgery attack.
|
| CVE-2017-3902 |
Cross-site scripting (XSS) vulnerability in the Web user interface
(UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows
authenticated users to inject malicious Java scripts via bypassing
input validation.
|
| CVE-2017-3888 |
A vulnerability in the web-based management interface of Cisco Unified
Communications Manager could allow an authenticated, remote attacker to
conduct a reflected cross-site scripting (XSS) attack against a user of
the web-based management interface of an affected device. This
vulnerability affects Cisco Unified Communications Manager with a
default configuration running an affected software release with the
attacker authenticated as the administrative user. More Information:
CSCvc83712. Known Affected Releases: 12.0(0.98000.452). Known Fixed
Releases: 12.0(0.98000.750) 12.0(0.98000.708) 12.0(0.98000.707)
12.0(0.98000.704) 12.0(0.98000.554) 12.0(0.98000.546) 12.0(0.98000.543)
12.0(0.98000.248) 12.0(0.98000.244) 12.0(0.98000.242).
|
| CVE-2017-3874 |
A vulnerability in the web framework of Cisco Unified Communications
Manager (CallManager) could allow an authenticated, remote attacker to
perform a cross-site scripting (XSS) attack. More Information:
CSCvb70033. Known Affected Releases: 11.5(1.11007.2). Known Fixed
Releases: 12.0(0.98000.507) 11.0(1.23900.5) 11.0(1.23900.3)
10.5(2.15900.2).
|
| CVE-2017-3872 |
A cross-site scripting (XSS) filter bypass vulnerability in the
web-based management interface of Cisco Unified Communications Manager
could allow an unauthenticated, remote attacker to conduct XSS attacks
against a user of an affected device. More Information: CSCvc21620.
Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases:
12.0(0.98000.641) 12.0(0.98000.500) 12.0(0.98000.219).
|
| CVE-2017-3868 |
A vulnerability in the web-based management interface of Cisco UCS
Director could allow an unauthenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against a user of the web-based
management interface of an affected device. More Information:
CSCvc44344. Known Affected Releases: 6.0(0.0).
|
| CVE-2017-3866 |
A vulnerability in the web framework code of Cisco Prime Service
Catalog could allow an unauthenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against the user of the web
interface of the affected system. More Information: CSCvc79842
CSCvc79846 CSCvc79855 CSCvc79873 CSCvc79882 CSCvc79891. Known Affected
Releases: 11.1.2.
|
| CVE-2017-3848 |
A vulnerability in the HTTP web-based management interface of Cisco
Prime Infrastructure could allow an unauthenticated, remote attacker to
conduct a cross-site scripting (XSS) attack against a user of the web
interface of the affected system. More Information: CSCuw63001
CSCuw63003. Known Affected Releases: 2.2(2). Known Fixed Releases:
3.1(0.0).
|
| CVE-2017-3847 |
A vulnerability in the web framework of Cisco Firepower Management
Center could allow an authenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against a user of the web interface.
More Information: CSCvc72741. Known Affected Releases: 6.2.1.
|
| CVE-2017-3845 |
A vulnerability in the web-based management interface of Cisco Prime
Collaboration Assurance could allow an unauthenticated, remote attacker
to conduct a cross-site scripting (XSS) attack against a user of the
web-based management interface of an affected device. Affected
Products: Cisco Prime Collaboration Assurance software versions 11.0,
11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance
software versions prior to 11.0 are not vulnerable. More Information:
CSCvc77783. Known Affected Releases: 11.5(0).
|
| CVE-2017-3838 |
A vulnerability in Cisco Secure Access Control System (ACS) could allow
an unauthenticated, remote attacker to conduct a DOM-based cross-site
scripting (XSS) attack against the user of the web interface of the
affected system. More Information: CSCvc04838. Known Affected Releases:
5.8(2.5).
|
| CVE-2017-3833 |
A vulnerability in the web framework of Cisco Unified Communications
Manager could allow an unauthenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against a user of the web interface
of the affected software. More Information: CSCvb95951. Known Affected
Releases: 12.0(0.99999.2). Known Fixed Releases: 11.0(1.23064.1)
11.5(1.12031.1) 11.5(1.12900.21) 11.5(1.12900.7) 11.5(1.12900.8)
11.6(1.10000.4) 12.0(0.98000.155) 12.0(0.98000.178) 12.0(0.98000.366)
12.0(0.98000.367) 12.0(0.98000.468) 12.0(0.98000.469) 12.0(0.98000.536)
12.0(0.98000.6) 12.0(0.98500.6).
|
| CVE-2017-3829 |
A vulnerability in the web-based management interface of Cisco Unified
Communications Manager Switches could allow an unauthenticated, remote
attacker to conduct a cross-site scripting (XSS) attack against a user
of the web-based management interface of an affected device. More
Information: CSCvc30999. Known Affected Releases: 12.0(0.98000.280).
Known Fixed Releases: 11.0(1.23900.3) 12.0(0.98000.180)
12.0(0.98000.422) 12.0(0.98000.541) 12.0(0.98000.6).
|
| CVE-2017-3828 |
A vulnerability in the web-based management interface of Cisco Unified
Communications Manager Switches could allow an unauthenticated, remote
attacker to conduct a cross-site scripting (XSS) attack against a user
of the web-based management interface of an affected device. More
Information: CSCvb98777. Known Affected Releases: 11.0(1.10000.10)
11.5(1.10000.6). Known Fixed Releases: 11.0(1.23063.1) 11.5(1.12029.1)
11.5(1.12900.11) 11.5(1.12900.21) 11.6(1.10000.4) 12.0(0.98000.156)
12.0(0.98000.178) 12.0(0.98000.369) 12.0(0.98000.470) 12.0(0.98000.536)
12.0(0.98000.6) 12.0(0.98500.6).
|
| CVE-2017-3821 |
A vulnerability in the serviceability page of Cisco Unified
Communications Manager could allow an unauthenticated, remote attacker
to conduct reflected cross-site scripting (XSS) attacks. More
Information: CSCvc49348. Known Affected Releases: 10.5(2.14076.1).
Known Fixed Releases: 12.0(0.98000.209) 12.0(0.98000.478)
12.0(0.98000.609).
|
| CVE-2017-3802 |
A vulnerability in Cisco Unified Communications Manager could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack against a user of the web interface of an affected system.
More Information: CSCvc20679. Known Affected Releases: 12.0(0.99000.9).
Known Fixed Releases: 12.0(0.98000.176) 12.0(0.98000.414)
12.0(0.98000.531) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.8).
|
| CVE-2017-3798 |
A cross-site scripting (XSS) filter bypass vulnerability in the
web-based management interface of Cisco Unified Communications Manager
could allow an unauthenticated, remote attacker to mount XSS attacks
against a user of an affected device. More Information: CSCvb97237.
Known Affected Releases: 11.0(1.10000.10) 11.5(1.10000.6). Known Fixed
Releases: 11.5(1.12029.1) 11.5(1.12900.11) 12.0(0.98000.369)
12.0(0.98000.370) 12.0(0.98000.398) 12.0(0.98000.457).
|
| CVE-2017-3161 |
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a
cross-site scripting (XSS) attack through an unescaped query
parameter.
|
| CVE-2017-3153 |
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found
vulnerable to Reflected XSS in the search functionality.
|
| CVE-2017-3152 |
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found
vulnerable to DOM XSS in the edit-tag functionality.
|
| CVE-2017-3128 |
A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS
allows attackers to execute unauthorized code or commands via the
policy global-label parameter.
|
| CVE-2017-3125 |
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and
5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in
the security context of the browser of a victim logged in FortiMail,
assuming the victim is social engineered into clicking an URL crafted
by the attacker.
|
| CVE-2017-3104 |
Adobe RoboHelp has a cross-site scripting (XSS) vulnerability. This
affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.
|
| CVE-2017-2969 |
Adobe Campaign versions 16.4 Build 8724 and earlier have a cross-site
scripting (XSS) vulnerability.
|
| CVE-2017-2683 |
A non-privileged user of the Siemens web application RUGGEDCOM NMS <
V1.2 on port 8080/TCP and 8081/TCP could perform a persistent
Cross-Site Scripting (XSS) attack, potentially resulting in obtaining
administrative permissions.
|
| CVE-2017-2645 |
In Moodle 3.x, XSS can occur via attachments to evidence of prior
learning.
|
| CVE-2017-2644 |
In Moodle 3.x, XSS can occur via evidence of prior learning.
|
| CVE-2017-2578 |
In Moodle 3.x, there is XSS in the assignment submission page.
|
| CVE-2017-2549 |
An issue was discovered in certain Apple products. iOS before 10.3.2
is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is
affected. The issue involves the "WebKit" component. It allows remote
attackers to conduct Universal XSS (UXSS) attacks via a crafted web
site that improperly interacts with frame loading.
|
| CVE-2017-2528 |
An issue was discovered in certain Apple products. iOS before 10.3.2
is affected. Safari before 10.1.1 is affected. The issue involves the
"WebKit" component. It allows remote attackers to conduct Universal
XSS (UXSS) attacks via a crafted web site that improperly interacts
with cached frames.
|
| CVE-2017-2510 |
An issue was discovered in certain Apple products. iOS before 10.3.2
is affected. Safari before 10.1.1 is affected. The issue involves the
"WebKit" component. It allows remote attackers to conduct Universal
XSS (UXSS) attacks via a crafted web site that improperly interacts
with pageshow events.
|
| CVE-2017-2508 |
An issue was discovered in certain Apple products. iOS before 10.3.2
is affected. Safari before 10.1.1 is affected. The issue involves the
"WebKit" component. It allows remote attackers to conduct Universal
XSS (UXSS) attacks via a crafted web site that improperly interacts
with container nodes.
|
| CVE-2017-2504 |
An issue was discovered in certain Apple products. iOS before 10.3.2
is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is
affected. The issue involves the "WebKit" component. It allows remote
attackers to conduct Universal XSS (UXSS) attacks via a crafted web
site that improperly interacts with WebKit Editor commands.
|
| CVE-2017-2475 |
An issue was discovered in certain Apple products. iOS before 10.3 is
affected. Safari before 10.1 is affected. tvOS before 10.2 is
affected. The issue involves the "WebKit" component. It allows remote
attackers to conduct Universal XSS (UXSS) attacks via crafted use of
frames on a web site.
|
| CVE-2017-2445 |
An issue was discovered in certain Apple products. iOS before 10.3 is
affected. Safari before 10.1 is affected. tvOS before 10.2 is
affected. The issue involves the "WebKit" component. It allows remote
attackers to conduct Universal XSS (UXSS) attacks via crafted frame
objects.
|
| CVE-2017-2393 |
An issue was discovered in certain Apple products. iOS before 10.3 is
affected. The issue involves the "Safari Reader" component. It allows
remote attackers to conduct Universal XSS (UXSS) attacks via a crafted
web site.
|
| CVE-2017-2361 |
An issue was discovered in certain Apple products. macOS before
10.12.3 is affected. The issue involves the "Help Viewer" component,
which allows XSS attacks via a crafted web site.
|
| CVE-2017-18015 |
The ILLID Share This Image plugin before 1.04 for WordPress has XSS via
the sharer.php url parameter.
|
| CVE-2017-18012 |
The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the
class.zlinkpreview.php url parameter.
|
| CVE-2017-18011 |
The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6
for WordPress has XSS via the text_ads_ajax.php border_color parameter.
|
| CVE-2017-18010 |
The E-goi Smart Marketing SMS and Newsletters Forms plugin before
2.0.0 for WordPress has XSS via the
admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
|
| CVE-2017-18006 |
netpub/server.np in Extensis Portfolio NetPublish has XSS in the
quickfind parameter, aka Open Bug Bounty ID OBB-290447.
|
| CVE-2017-18004 |
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to
maps/default/mapAndPoint.
|
| CVE-2017-17995 |
Biometric Shift Employee Management System has XSS via the Last_Name
parameter in an index.php?user=ajax request.
|
| CVE-2017-17994 |
Biometric Shift Employee Management System has XSS via the criteria
parameter in an index.php?user=competency_criteria request.
|
| CVE-2017-17993 |
Biometric Shift Employee Management System has XSS via the amount
parameter in an index.php?user=addition_deduction request.
|
| CVE-2017-17991 |
Biometric Shift Employee Management System has XSS via the expense_name
parameter in an index.php?user=expenses request.
|
| CVE-2017-17989 |
Biometric Shift Employee Management System has XSS via the index.php
holiday_name parameter in an edit_holiday action.
|
| CVE-2017-17988 |
PHP Scripts Mall Muslim Matrimonial Script has XSS via the
admin/event_add.php event_title parameter.
|
| CVE-2017-17986 |
PHP Scripts Mall Muslim Matrimonial Script has XSS via the
admin/caste_view.php comm_id parameter.
|
| CVE-2017-17985 |
PHP Scripts Mall Muslim Matrimonial Script has XSS via the
admin/state_view.php cou_id parameter.
|
| CVE-2017-17984 |
PHP Scripts Mall Muslim Matrimonial Script has XSS via the
admin/event_edit.php edit_id parameter.
|
| CVE-2017-17981 |
PHP Scripts Mall Muslim Matrimonial Script has XSS via the
admin/slider_edit.php edit_id parameter.
|
| CVE-2017-17971 |
The test_sql_and_script_inject function in htdocs/main.inc.php in
Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick
nor onscroll, which allows XSS.
|
| CVE-2017-17958 |
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the
my_wishlist.php fid parameter.
|
| CVE-2017-17956 |
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the
admin/sellerupd.php companyname parameter.
|
| CVE-2017-17955 |
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the
shopping-cart.php cusid parameter.
|
| CVE-2017-17954 |
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the
seller-view.php usid parameter.
|
| CVE-2017-17953 |
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php
chid1 parameter.
|
| CVE-2017-17949 |
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.
|
| CVE-2017-17948 |
Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic
request.
|
| CVE-2017-17940 |
PHP Scripts Mall Single Theater Booking has XSS via the title parameter
to admin/sitesettings.php.
|
| CVE-2017-17938 |
PHP Scripts Mall Single Theater Booking has XSS via the
admin/viewtheatre.php theatreid parameter.
|
| CVE-2017-17937 |
Vanguard Marketplace Digital Products PHP has XSS via the phps_query
parameter to /search.
|
| CVE-2017-17933 |
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or
9021) in NetWin SurgeFTP version 23f2 has XSS via the classid,
domainid, or username parameter.
|
| CVE-2017-17929 |
PHP Scripts Mall Professional Service Script has XSS via the
admin/bannerview.php view parameter.
|
| CVE-2017-17925 |
PHP Scripts Mall Professional Service Script has XSS via the
admin/general_settingupd.php website_title parameter.
|
| CVE-2017-17911 |
packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer
parameter in an index.php?p=core/contact request, aka Open Bug Bounty
ID OBB-278503.
|
| CVE-2017-17909 |
PHP Scripts Mall Responsive Realestate Script has XSS via the
admin/general.php gplus parameter.
|
| CVE-2017-17907 |
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php
carid parameter or the admin/sitesettings.php websitename parameter.
|
| CVE-2017-17904 |
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the
edit_profile_first_name parameter to user/edit_profile.
|
| CVE-2017-17896 |
Readymade Job Site Script has XSS via the keyword parameter to the /job
URI.
|
| CVE-2017-17893 |
Readymade Video Sharing Script has XSS via the search_video.php search
parameter, the viewsubs.php chnlid parameter, or the
user-profile-edit.php fname parameter.
|
| CVE-2017-17869 |
The mgl-instagram-gallery plugin for WordPress has XSS via the
single-gallery.php media parameter.
|
| CVE-2017-17868 |
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render
Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
|
| CVE-2017-17837 |
The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the
windowId handling. The default size of the windowId get's cut off
after 10 characters (by default), so the impact might be limited. A
fix got applied and released in Apache deltaspike-1.8.1.
|
| CVE-2017-17828 |
Bus Booking Script has XSS via the results.php datepicker parameter or
the admin/new_master.php spemail parameter.
|
| CVE-2017-17792 |
Cross site scripting (XSS) vulnerability in the markup_clean_href
function in inc/conv.php in BlogoText through 3.7.6 allows remote
attackers to inject arbitrary JavaScript via a comment.
|
| CVE-2017-17780 |
The Clockwork SMS clockwork-test-message.php component has XSS via a
crafted "to" parameter in a clockwork-test-message request to
wp-admin/admin.php. This component code is found in the following
WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3,
Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar -
Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure
Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2,
Gravity Forms - Clockwork SMS 2.2, and WP e-Commerce - Clockwork SMS
2.0.5.
|
| CVE-2017-17778 |
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter
or the admin/userview.php uid parameter.
|
| CVE-2017-17775 |
Piwigo 2.9.2 has XSS via the name parameter in an
admin.php?page=album-3-properties request.
|
| CVE-2017-17753 |
Multiple cross-site scripting (XSS) vulnerabilities in the
esb-csv-import-export plugin through 1.1 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) cie_type,
(2) cie_import, (3) cie_update, or (4) cie_ignore parameter to
includes/admin/views/esb-cie-import-export-page.php.
|
| CVE-2017-17752 |
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body
of an e-mail message, with JavaScript code executed on the Read Mail
screen (aka the /_readmail URI). This is fixed in version 4.2.4.
|
| CVE-2017-17745 |
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in
TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to
submit arbitrary java script via the 'sysName' parameter.
|
| CVE-2017-17744 |
A cross-site scripting (XSS) vulnerability in the custom-map plugin
through 1.1 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the map_id parameter to
view/advancedsettings.php.
|
| CVE-2017-17737 |
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and
below) has XSS via the REF parameter to /network_diagnostics.html or
/storage_info.html.
|
| CVE-2017-17719 |
A cross-site scripting (XSS) vulnerability in the wp-concours plugin
through 1.1 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the result_message parameter to
includes/concours_page.php.
|
| CVE-2017-17714 |
Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId
parameter, the /register User-Agent HTTP header, the /register country
parameter, the /register countryCode parameter, the /register cpu
parameter, the /register isp parameter, the /register lat parameter,
the /register lon parameter, the /register org parameter, the /register
query parameter, the /register region parameter, the /register
regionName parameter, the /register timezone parameter, the /register
vId parameter, the /register zip parameter, or the /tping id parameter.
|
| CVE-2017-17698 |
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has
reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
|
| CVE-2017-17694 |
Techno - Portfolio Management Panel through 2017-11-16 allows XSS via
the panel/search.php s parameter.
|
| CVE-2017-17569 |
Scubez Posty Readymade Classifieds has XSS via the
admin/user_activate_submit.php ID parameter.
|
| CVE-2017-17451 |
The WP Mailster plugin before 1.5.5 for WordPress has XSS in the
unsubscribe handler via the mes parameter to
view/subscription/unsubscribe2.php.
|
| CVE-2017-17431 |
GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status,
term, to, or token parameter. NOTE: this might overlap CVE-2017-14761,
CVE-2017-14762, or CVE-2017-14765.
|
| CVE-2017-17383 |
Jenkins through 2.93 allows remote authenticated administrators to
conduct XSS attacks via a crafted tool name in a job configuration
form, as demonstrated by the JDK tool in Jenkins core and the Ant tool
in the Ant plugin, aka SECURITY-624.
|
| CVE-2017-17096 |
Cross-site scripting (XSS) vulnerability in the Content Cards plugin
before 0.9.7 for WordPress allows remote attackers to inject arbitrary
JavaScript via crafted OpenGraph data.
|
| CVE-2017-17094 |
wp-includes/feed.php in WordPress before 4.9.1 does not properly
restrict enclosures in RSS and Atom fields, which might allow attackers
to conduct XSS attacks via a crafted URL.
|
| CVE-2017-17093 |
wp-includes/general-template.php in WordPress before 4.9.1 does not
properly restrict the lang attribute of an HTML element, which might
allow attackers to conduct XSS attacks via the language setting of a
site.
|
| CVE-2017-17092 |
wp-includes/functions.php in WordPress before 4.9.1 does not require
the unfiltered_html capability for upload of .js files, which might
allow remote attackers to conduct XSS attacks via a crafted file.
|
| CVE-2017-17089 |
custom/run.cgi in Webmin before 1.870 allows remote authenticated
administrators to conduct XSS attacks via the description field in the
custom command functionality.
|
| CVE-2017-17059 |
XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts
or wp-thumb-post) plugin 8.1.3 for WordPress via the query string to
amtyThumbPostsAdminPg.php.
|
| CVE-2017-17057 |
There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The
vulnerability exists due to insufficient filtration of user-supplied
data in the 'Range' field of the 'Department' module in a Personnel
Advanced Query. A remote attacker can execute arbitrary HTML and
script code in the browser in the context of the vulnerable
application.
|
| CVE-2017-17055 |
Artica Web Proxy before 3.06.112911 allows remote attackers to execute
arbitrary code as root by conducting a cross-site scripting (XSS)
attack involving the username-form-id parameter to
freeradius.users.php.
|
| CVE-2017-17043 |
The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected
XSS because the parameter "post" to
/wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php
is not filtered correctly.
|
| CVE-2017-16962 |
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate
Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location
or details field of a Google Calendar invitation, (2) a crafted
Outlook.com calendar (aka Hotmail Calendar) invitation, (3) e-mail
granting access to a directory that has JavaScript in its name, (4)
JavaScript in a note name, (5) JavaScript in a task name, or (6) HTML
e-mail that is mishandled in the Inbox component.
|
| CVE-2017-16956 |
b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a
private letter with a certain /article URI, and a second private letter
with a modified title.
|
| CVE-2017-16950 |
Cross - site scripting (XSS) vulnerability in UrBackup Server before
2.1.20 allows remote attackers to inject arbitrary web script or HTML
via the action parameter.
|
| CVE-2017-16919 |
MapOS 3.1.11 and earlier has a Stored Cross-site Scripting (XSS)
vulnerability in /clientes/visualizar, which allows remote attackers to
inject arbitrary web script or HTML via a crafted description
parameter.
|
| CVE-2017-16908 |
In Horde Groupware 5.2.19, there is XSS via the Name field during
creation of a new Resource. This can be leveraged for remote code
execution after compromising an administrator account, because the
CVE-2015-7984 CSRF protection mechanism can then be bypassed.
|
| CVE-2017-16907 |
In Horde Groupware 5.2.19, there is XSS via the Color field in a Create
Task List action.
|
| CVE-2017-16906 |
In Horde Groupware 5.2.19, there is XSS via the URL field in a
"Calendar -> New Event" action.
|
| CVE-2017-16904 |
The Public tologin feature in admin.php in LvyeCMS through 3.1 allows
XSS via a crafted username that is mishandled during later log viewing
by an administrator.
|
| CVE-2017-16884 |
Cross-site scripting (XSS) vulnerability in MistServer before 2.13
allows remote attackers to inject arbitrary web script or HTML via
vectors related to failed authentication requests alerts.
|
| CVE-2017-16881 |
b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON
objects, as demonstrated by a crafted userAvatarURL value to
/settings/avatar, related to processor/AdminProcessor.java,
processor/ArticleProcessor.java, processor/UserProcessor.java,
service/ArticleQueryService.java, service/AvatarQueryService.java, and
service/CommentQueryService.java.
|
| CVE-2017-16880 |
The dump function in Util/TemplateHelper.php in filp whoops before
2.1.13 has XSS.
|
| CVE-2017-16876 |
Cross-site scripting (XSS) vulnerability in the _keyify function in
mistune.py in Mistune before 0.8.1 allows remote attackers to inject
arbitrary web script or HTML by leveraging failure to escape the "key"
argument.
|
| CVE-2017-16866 |
dayrui FineCms 5.2.0 before 2017.11.16 has Cross Site Scripting (XSS)
in core/M_Controller.php via the DR_URI field.
|
| CVE-2017-16856 |
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows
remote attackers to inject arbitrary HTML or JavaScript via cross site
scripting (XSS) vulnerabilities in various rss properties which were
used as links without restriction on their scheme.
|
| CVE-2017-16843 |
Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the
NewKeyword or NewDomain field to /goform/RgParentalBasic.
|
| CVE-2017-16842 |
Cross-site scripting (XSS) vulnerability in
admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin
before 5.8.0 for WordPress allows remote attackers to inject arbitrary
web script or HTML.
|
| CVE-2017-16841 |
LanSweeper 6.0.100.75 has XSS via the description parameter to
/Calendar/CalendarActions.aspx.
|
| CVE-2017-16836 |
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse
10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the
actionHandler/ajax_managed_services.php service parameter.
|
| CVE-2017-16833 |
Stored cross-site scripting (XSS) vulnerability in Gemirro before
0.16.0 allows attackers to inject arbitrary web script via a crafted
javascript: URL in the "homepage" value of a ".gemspec" file.
|
| CVE-2017-16821 |
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java
in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP
header that is mishandled during display of a client IP address in
/admin/user/userid.
|
| CVE-2017-16815 |
installer.php in the Snap Creek Duplicator (WordPress Site Migration &
Backup) plugin before 1.2.30 for WordPress has XSS because the values
"url_new"
(/wp-content/plugins/duplicator/installer/build/view.step4.php) and
"logging"
(wp-content/plugins/duplicator/installer/build/view.step2.php) are not
filtered correctly.
|
| CVE-2017-16810 |
Cross-site scripting (XSS) vulnerability in the All Variables tab in
Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers
to inject arbitrary web script or HTML via the Variable Set Name
parameter.
|
| CVE-2017-16807 |
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3,
2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a
specially prepared SVG document that has been uploaded as a content
file.
|
| CVE-2017-16802 |
In the sharingGroupPopulateOrganisations function in
app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted
organisation name that is manually added.
|
| CVE-2017-16801 |
Cross-site scripting (XSS) vulnerability in Octopus Deploy
3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to
inject arbitrary web script or HTML via the Step Template Name
parameter.
|
| CVE-2017-16799 |
In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php,
stored XSS is possible via the m1_name parameter to
admin/moduleinterface.php during addition of a category, a related
issue to CVE-2010-3882.
|
| CVE-2017-16798 |
In CMS Made Simple 2.2.3.1, the is_file_acceptable function in
modules/FileManager/action.upload.php only blocks file extensions that
begin or end with a "php" substring, which allows remote attackers to
bypass intended access restrictions or trigger XSS via other
extensions, as demonstrated by .phtml, .pht, .html, or .svg.
|
| CVE-2017-16792 |
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in
a Box) before 0.13.10 allows attackers to inject arbitrary web script
via the "homepage" value of a ".gemspec" file, related to views/gem.erb
and views/index.erb.
|
| CVE-2017-16789 |
Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS
3, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and
other products, allows remote authenticated administrators to inject
arbitrary web script or HTML via the users management panel of the web
interface.
|
| CVE-2017-16785 |
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
|
| CVE-2017-16784 |
In CMS Made Simple 2.2.2, there is Reflected XSS via the
cntnt01detailtemplate parameter.
|
| CVE-2017-16782 |
In Home Assistant before 0.57, it is possible to inject JavaScript code
into a persistent notification via crafted Markdown text, aka XSS.
|
| CVE-2017-16781 |
The installer in MyBB before 1.8.13 has XSS.
|
| CVE-2017-16768 |
Cross-site scripting (XSS) vulnerability in User Policy editor in
Synology MailPlus Server before 1.4.0-0415 allows remote authenticated
users to inject arbitrary HTML via the name parameter.
|
| CVE-2017-16765 |
XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
|
| CVE-2017-16760 |
Inedo BuildMaster before 5.8.2 has XSS.
|
| CVE-2017-16758 |
Cross-site scripting (XSS) vulnerability in
admin/partials/uif-access-token-display.php in the Ultimate Instagram
Feed plugin before 1.3 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the "access_token" parameter.
|
| CVE-2017-16685 |
Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data
Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to
insufficient encoding of user controlled inputs.
|
| CVE-2017-16681 |
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence
Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user
controlled inputs are not sufficiently encoded.
|
| CVE-2017-16665 |
RemObjects Remoting SDK 9 1.0.0.0 for Delphi is vulnerable to a
reflected Cross Site Scripting (XSS) attack via the service parameter
to the /soap URI, triggering an invalid attempt to generate WSDL.
|
| CVE-2017-16636 |
In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new
page, new category, and edit post function body message context. Remote
attackers are able to bypass the basic editor validation to trigger
cross site scripting. The XSS is persistent and the request method to
inject via editor is GET. To save the editor context, the followup POST
method request must be processed to perform the attack via the
application side. The basic validation of the editor does not allow
injecting script codes and blocks the context. Attackers can inject the
code by using an editor tag that is not recognized by the basic
validation. Thus allows a restricted user account to inject malicious
script code to perform a persistent attack against higher privilege
web-application user accounts.
|
| CVE-2017-16635 |
In TinyWebGallery v2.4, an XSS vulnerability is located in the
`mkname`, `mkitem`, and `item` parameters of the `Add/Create` module.
Remote attackers with low-privilege user accounts for backend access
are able to inject malicious script codes into the `TWG Explorer` item
listing. The request method to inject is POST and the attack vector is
located on the application-side of the service. The injection point is
the add/create input field and the execution point occurs in the item
listing after the add or create.
|
| CVE-2017-16568 |
Cross-site scripting (XSS) vulnerability in Logitech Media Server
7.9.0 allows remote attackers to inject arbitrary web script or HTML
via a radio URL.
|
| CVE-2017-16567 |
Cross-site scripting (XSS) vulnerability in Logitech Media Server
7.9.0 allows remote attackers to inject arbitrary web script or HTML
via a "favorite."
|
| CVE-2017-16564 |
Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on
Vonage (Grandstream) HT802 devices allows remote authenticated users to
inject arbitrary web script or HTML via the DHCP vendor class ID field
(P148).
|
| CVE-2017-16230 |
In admin/write-post.php in Typecho through 1.1, one can log in to the
background page, write a new article, and add payload in the article
content, resulting in XSS via index.php/action/contents-post-edit.
|
| CVE-2017-15948 |
Perch Content Management System 3.0.3 allows unrestricted file upload
(with resultant XSS) via the Asset Title field in conjunction with the
Select File field. This is exploitable with a Limited Admin account.
|
| CVE-2017-15947 |
Simple ASC Content Management System v1.2 has XSS in the location field
in the sign function, related to guestbook.asp, formgb.asp, and
msggb.asp.
|
| CVE-2017-15936 |
In Artica Pandora FMS version 7.0, an Attacker with write Permission
can create an agent with an XSS Payload; when a user enters the agent
definitions page, the script will get executed.
|
| CVE-2017-15911 |
The Admin Console in Ignite Realtime Openfire Server before 4.1.7
allows arbitrary client-side JavaScript code execution on victims who
click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS.
Session ID and data theft may follow as well as the possibility of
bypassing CSRF protections, injection of iframes to establish
communication channels, etc. The vulnerability is present after login
into the application.
|
| CVE-2017-15892 |
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command
Creator in Synology Chat before 2.0.0-1124 allow remote authenticated
users to inject arbitrary web script or HTML via (1) COMMAND, (2)
COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter.
|
| CVE-2017-15890 |
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology
MailPlus Server before 1.4.0-0415 allows remote authenticated users to
inject arbitrary web script or HTML via the NAME parameter.
|
| CVE-2017-15888 |
Cross-site scripting (XSS) vulnerability in Custom Internet Radio List
in Synology Audio Station before 6.3.0-3260 allows remote
authenticated attackers to inject arbitrary web script or HTML via the
NAME parameter.
|
| CVE-2017-15885 |
Reflected XSS in the web administration portal on the Axis 2100 Network
Camera 2.03 allows an attacker to execute arbitrary JavaScript via the
conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might
overlap CVE-2007-5214.
|
| CVE-2017-15878 |
A cross-site scripting (XSS) vulnerability exists in
fields/types/markdown/MarkdownType.js in KeystoneJS before
4.0.0-beta.7 via the Contact Us feature.
|
| CVE-2017-15872 |
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and
include/inc_tmpl/admin.newuser.tmpl.php via the username (aka
new_login) field.
|
| CVE-2017-15867 |
Multiple cross-site scripting (XSS) vulnerabilities in the
user-login-history plugin through 1.5.2 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) date_from,
(2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser,
(7) operating_system, or (8) ip_address parameter to
admin/partials/listing/listing.php.
|
| CVE-2017-15863 |
Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin
before 3.5.19 for WordPress via the date1 or date2 parameter to
wp-admin/options-general.php.
|
| CVE-2017-15812 |
The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a
Settings values in the admin panel.
|
| CVE-2017-15811 |
The Pootle Button plugin before 1.2.0 for WordPress has XSS via the
assets_url parameter in assets/dialog.php, exploitable via
wp-admin/admin-ajax.php.
|
| CVE-2017-15810 |
The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress
has XSS via the tab parameter to wp-admin/admin.php.
|
| CVE-2017-15809 |
In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a
crafted tag.
|
| CVE-2017-15736 |
Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7
allows remote attackers to inject arbitrary web script or HTML via a
crafted string, as demonstrated by a PGP field, related to
prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.
|
| CVE-2017-15728 |
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS)
via metaDescription or metaKeywords.
|
| CVE-2017-15727 |
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS)
via an HTML attachment.
|
| CVE-2017-15687 |
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server
7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.
|
| CVE-2017-15648 |
In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the
page_title parameter.
|
| CVE-2017-15646 |
Webmin before 1.860 has XSS with resultant remote code execution. Under
the 'Others/File Manager' menu, there is a 'Download from remote URL'
option to download a file from a remote server. After setting up a
malicious server, one can wait for a file download request and then
send an XSS payload that will lead to Remote Code Execution, as
demonstrated by an OS command in the value attribute of a name='cmd'
input element.
|
| CVE-2017-15612 |
mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such
as in java\nscript:) or a crafted email address, related to the escape
and autolink functions.
|
| CVE-2017-15574 |
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible
by using an SVG document as an attachment.
|
| CVE-2017-15573 |
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because
markup is mishandled in wiki content.
|
| CVE-2017-15571 |
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3,
XSS exists in app/views/issues/_list.html.erb via crafted column data.
|
| CVE-2017-15570 |
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3,
XSS exists in app/views/timelog/_list.html.erb via crafted column data.
|
| CVE-2017-15569 |
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3,
XSS exists in app/helpers/queries_helper.rb via a multi-value field
with a crafted value that is mishandled during rendering of an issue
list.
|
| CVE-2017-15568 |
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3,
XSS exists in app/helpers/application_helper.rb via a multi-value field
with a crafted value that is mishandled during rendering of issue
history.
|
| CVE-2017-15538 |
Stored XSS vulnerability in the Media Objects component of ILIAS before
5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject
JavaScript to gain administrator privileges, related to the
setParameter function in
Services/MediaObjects/classes/class.ilMediaItem.php.
|
| CVE-2017-15384 |
rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.
|
| CVE-2017-15380 |
XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the
requester's registration area) via the nome parameter.
|
| CVE-2017-15362 |
osTicket 1.10.1 allows arbitrary client-side JavaScript code execution
on victims who click a crafted support/scp/tickets.php?status= link,
aka XSS. Session ID and data theft may follow as well as the
possibility of bypassing CSRF protections, injection of iframes to
establish communication channels, etc. The vulnerability is present
after login into the application. This affects a different tickets.php
file than CVE-2015-1176.
|
| CVE-2017-15312 |
Huawei SmartCare V200R003C10 has a stored XSS (cross-site scripting)
vulnerability in the dashboard module. A remote authenticated attacker
could exploit this vulnerability to inject malicious scripts in the
affected device.
|
| CVE-2017-15305 |
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
|
| CVE-2017-15294 |
The Java administration console in SAP CRM has XSS. This is SAP
Security Note 2478964.
|
| CVE-2017-15291 |
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering
page in TP-LINK TL-MR3220 wireless routers allows remote attackers to
inject arbitrary web script or HTML via the Description field.
|
| CVE-2017-15287 |
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia
Dreambox devices, as demonstrated by the "Name des Bouquets" field, or
the file parameter to the /file URI.
|
| CVE-2017-15279 |
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3
allows remote attackers to inject arbitrary web script or HTML via the
"page name" (aka nodename) parameter during the creation of a new page,
related to Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs and
Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs.
|
| CVE-2017-15278 |
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9.
The vulnerability exists due to insufficient filtration of data (in
/sources/folders.queries.php). An attacker could execute arbitrary HTML
and script code in a browser in the context of the vulnerable website.
|
| CVE-2017-15273 |
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before
16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting
a potential dangerous payload, e.g., XSS code, to be saved as titles
in internal artefacts.
|
| CVE-2017-15219 |
The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site
Scripting (XSS) affecting a vanity-urls Title field, a containers
Description field, and a templates Description field.
|
| CVE-2017-15216 |
MISP before 2.4.81 has a potential reflected XSS in a quickDelete
action that is used to delete a sighting, related to
app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and
app/webroot/js/misp.js.
|
| CVE-2017-15215 |
Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated
attacker to inject JavaScript via the searchtags parameter to
index.php. If the victim is an administrator, an attacker can (for
example) take over the admin session or change global settings or
add/delete links. It is also possible to execute JavaScript against
unauthenticated users.
|
| CVE-2017-15214 |
Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an
authenticated user to inject JavaScript to gain administrator
privileges and also to execute JavaScript against other users
(including unauthenticated users), via the name, title, or id parameter
to plugins/dokuwiki/lib/plugins/changelinks/syntax.php.
|
| CVE-2017-15213 |
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an
authenticated user to inject JavaScript to gain administrator
privileges, via the real_name or email_address field to
themes/CleanFS/templates/common.editallusers.tpl.
|
| CVE-2017-15194 |
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the
URI or (2) the refresh page.
|
| CVE-2017-15188 |
A persistent (stored) XSS vulnerability in the EyesOfNetwork web
interface (aka eonweb) 5.1-0 allows remote authenticated administrators
to inject arbitrary web script or HTML via the hosts array parameter to
module/admin_device/index.php.
|
| CVE-2017-15100 |
An attacker submitting facts to the Foreman server containing HTML can
cause a stored XSS on certain pages: (1) Facts page, when clicking on
the "chart" button and hovering over the chart; (2) Trends page, when
checking the graph for a trend based on a such fact; (3) Statistics
page, for facts that are aggregated on this page.
|
| CVE-2017-15051 |
Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass
before 2.1.27.9 allow authenticated remote attackers to inject
arbitrary web script or HTML via the (1) URL value of an item or (2)
user log history. To exploit the vulnerability, the attacker must be
first authenticated to the application. For the first one, the attacker
has to simply inject XSS code within the URL field of a shared item.
For the second one however, the attacker must prepare a payload within
its profile, and then ask an administrator to modify its profile. From
there, whenever the administrator accesses the log, it can be XSS'ed.
|
| CVE-2017-15039 |
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a
data: URL in the redirectUrl parameter to
app/index.php/meetings/default/createMeeting.
|
| CVE-2017-1500 |
A Reflected Cross Site Scripting (XSS) vulnerability exists in the
authorization function exposed by RESTful Web Api of IBM Worklight
Framework 6.1, 6.2, 6.3, 7.0, 7.1, and 8.0. The vulnerable parameter
is "scope"; if you set as its value a "realm" not defined in
authenticationConfig.xml, you get an HTTP 403 Forbidden response and
the value will be reflected in the body of the HTTP response. By
setting it to arbitrary JavaScript code it is possible to modify the
flow of the authorization function, potentially leading to credential
disclosure within a trusted session.
|
| CVE-2017-14995 |
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business
Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex
Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics
Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner
1.2.0 is affected by stored XSS.
|
| CVE-2017-14985 |
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web
interface (aka eonweb) 5.1-0 allows remote authenticated users to
inject arbitrary web script or HTML via the url parameter to
module/module_frame/index.php.
|
| CVE-2017-14984 |
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web
interface (aka eonweb) 5.1-0 allows remote authenticated users to
inject arbitrary web script or HTML via the bp_name parameter to
/module/admin_bp/add_services.php.
|
| CVE-2017-14983 |
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web
interface (aka eonweb) 5.1-0 allows remote authenticated administrators
to inject arbitrary web script or HTML via the object parameter to
module/admin_conf/index.php.
|
| CVE-2017-14981 |
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The
vulnerability exists due to insufficient filtration of data (url in
/mods/_standard/rss_feeds/edit_feed.php). An attacker could inject
arbitrary HTML and script code into a browser in the context of the
vulnerable website.
|
| CVE-2017-14973 |
IDenticard Two-Reader Controller Configuration Manager 1.18.8 (396) is
vulnerable to Stored Cross-Site Scripting (XSS) via the notes field in
/~user_handler?file=logged_in.shtm (aka the edit user page).
|
| CVE-2017-14957 |
Stored XSS vulnerability via a comment in inc/conv.php in BlogoText
before 3.7.6 allows an unauthenticated attacker to inject JavaScript.
If the victim is an administrator, an attacker can (for example) change
global settings or create/delete posts. It is also possible to execute
JavaScript against unauthenticated users of the blog.
|
| CVE-2017-14923 |
Stored XSS vulnerability via IMG element at "Leadname" of CRM in Tine
2.0 Community Edition before 2017.08.4 allows an authenticated user to
inject JavaScript, which is mishandled during rendering by the
application administrator and other users.
|
| CVE-2017-14922 |
Stored XSS vulnerability via IMG element at "History" of Profile,
Calendar, Tasks, and CRM in Tine 2.0 Community Edition before 2017.08.4
allows an authenticated user to inject JavaScript, which is mishandled
during rendering by the application administrator and other users.
|
| CVE-2017-14921 |
Stored XSS vulnerability via IMG element at "Filename" of Filemanager
in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated
user to inject JavaScript, which is mishandled during rendering by the
application administrator and other users.
|
| CVE-2017-14920 |
Stored XSS vulnerability in eGroupware Community Edition before
16.1.20170922 allows an unauthenticated remote attacker to inject
JavaScript via the User-Agent HTTP header, which is mishandled during
rendering by the application administrator.
|
| CVE-2017-14765 |
In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a
page=menus request.
|
| CVE-2017-14762 |
In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS
via the id parameter.
|
| CVE-2017-14761 |
In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the
id parameter.
|
| CVE-2017-14753 |
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web
interface (aka eonweb) 5.1-0 allows remote authenticated users to
inject arbitrary web script or HTML via the filter parameter to
module/module_filters/index.php.
|
| CVE-2017-14752 |
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before
16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting
a potential dangerous payload, e.g., XSS code, to be saved as their
first name, last name, or display name in the profile fields that can
cause issues such as escalation of privileges or unknown execution of
malicious code when replying to messages in Mahara.
|
| CVE-2017-14751 |
The Intense WP "WP Jobs" plugin 1.5 for WordPress has XSS, related to
the Job Qualification field.
|
| CVE-2017-14744 |
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
|
| CVE-2017-14735 |
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as
demonstrated by use of : to construct a javascript: URL.
|
| CVE-2017-14717 |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks
Description parameter.
|
| CVE-2017-14716 |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title
parameter.
|
| CVE-2017-14715 |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts
Title parameter.
|
| CVE-2017-14714 |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls
Subject parameter.
|
| CVE-2017-14713 |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls
Description parameter.
|
| CVE-2017-14712 |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall
Notes Title parameter.
|
| CVE-2017-14651 |
WSO2 Data Analytics Server 3.1.0 has XSS in
carbon/resources/add_collection_ajaxprocessor.jsp via the
collectionName or parentPath parameter.
|
| CVE-2017-14622 |
Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon
Affiliates Store plugin before 2.1.1 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) page
parameter or (2) kbAction parameter in the kbAmz page to
wp-admin/admin.php.
|
| CVE-2017-14621 |
Portus 2.2.0 has XSS via the Team field, related to typeahead.
|
| CVE-2017-14619 |
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8
allows remote attackers to inject arbitrary web script or HTML via the
"Title of your FAQ" field in the Configuration Module.
|
| CVE-2017-14618 |
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ
through 2.9.8 allows remote attackers to inject arbitrary web script or
HTML via the Questions field in an "Add New FAQ" action.
|
| CVE-2017-14597 |
AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the
txtDomainName field to adminpanel/modules/pro/inc/ajax.php during
addition of a domain.
|
| CVE-2017-14588 |
Various resources in Atlassian FishEye and Crucible before version
4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript
via a cross site scripting (XSS) vulnerability in the dialog
parameter.
|
| CVE-2017-14587 |
The administration user deletion resource in Atlassian FishEye and
Crucible before version 4.4.2 allows remote attackers to inject
arbitrary HTML or JavaScript via a cross site scripting (XSS)
vulnerability in the uname parameter.
|
| CVE-2017-14534 |
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via
the PATH_INFO to location.php, related to PHP_SELF.
|
| CVE-2017-14530 |
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for
WordPress has CSRF via the name parameter in an action=manage&do=create
operation, as demonstrated by inserting XSS sequences.
|
| CVE-2017-14516 |
Cross-Site Scripting (XSS) exists in SAP Business Objects Financial
Consolidation before 2017-06-13, aka SAP Security Note 2422292.
|
| CVE-2017-14510 |
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before
7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).
The WebToLeadCapture functionality is found vulnerable to
unauthenticated cross-site scripting (XSS) attacks. This attack vector
is mitigated by proper validating the redirect URL values being passed
along.
|
| CVE-2017-14506 |
geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by
uploading a gem file that has a crafted gem.homepage value in its
.gemspec file.
|
| CVE-2017-14498 |
SilverStripe CMS before 3.6.1 has XSS via an SVG document that is
mishandled by (1) the Insert Media option in the content editor or (2)
an admin/assets/add pathname, as demonstrated by the
admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload
URI, aka issue SS-2017-017.
|
| CVE-2017-14416 |
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1)
devices have XSS in the action parameter to htdocs/web/wandetect.php.
|
| CVE-2017-14415 |
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1)
devices have XSS in the action parameter to htdocs/web/sitesurvey.php.
|
| CVE-2017-14414 |
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1)
devices have XSS in the action parameter to htdocs/web/shareport.php.
|
| CVE-2017-14413 |
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1)
devices have XSS in the action parameter to htdocs/web/wpsacts.php.
|
| CVE-2017-14363 |
Cross-Site Scripting (XSS) vulnerability has been identified in Micro
Focus Operations Manager i, versions 10.60, 10.61, 10.62. The
vulnerability could be remotely exploited to allow Cross-Site
Scripting (XSS).
|
| CVE-2017-14357 |
A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP
ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to
6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be
exploited remotely to allow Reflected and Stored Cross-Site Scripting
(XSS)
|
| CVE-2017-14347 |
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to
fun.php in a delete action.
|
| CVE-2017-14321 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow
remote attackers to inject arbitrary web script or HTML via the (1)
customer name or (2) subject in a ticket.
|
| CVE-2017-14313 |
The shibboleth_login_form function in shibboleth.php in the Shibboleth
plugin before 1.8 for WordPress is prone to an XSS vulnerability due to
improper use of add_query_arg().
|
| CVE-2017-14268 |
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have XSS in the
sms_content parameter in a getSMSlist request.
|
| CVE-2017-14241 |
Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0
allows remote authenticated users to inject arbitrary web script or
HTML via the Title parameter to htdocs/admin/menus/edit.php.
|
| CVE-2017-14239 |
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM
6.0.0 allow remote authenticated users to inject arbitrary web script
or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip,
(4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors,
(9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14)
ProfId4, (15) ProfId5, or (16) ProfId6 parameter to
htdocs/admin/company.php.
|
| CVE-2017-14219 |
XSS (persistent) on the Intelbras Wireless N 150Mbps router with
firmware WRN 240 allows attackers to steal wireless credentials without
being connected to the network, related to
userRpm/popupSiteSurveyRpm.htm and userRpm/WlanSecurityRpm.htm. The
attack vector is a crafted ESSID, as demonstrated by an "airbase-ng -e"
command.
|
| CVE-2017-14197 |
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before
5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues
in Matrix WYSIWYG plugins.
|
| CVE-2017-14195 |
The call_msg function in controllers/Form.php in dayrui FineCms 5.0.11
might have XSS related to the Referer HTTP header with Internet
Explorer.
|
| CVE-2017-14194 |
The out function in controllers/member/Login.php in dayrui FineCms
5.0.11 has XSS related to the Referer HTTP header with Internet
Explorer.
|
| CVE-2017-14193 |
The oauth function in controllers/member/api.php in dayrui FineCms
5.0.11 has XSS related to the Referer HTTP header with Internet
Explorer.
|
| CVE-2017-14192 |
The checktitle function in controllers/member/api.php in dayrui FineCms
5.0.11 has XSS related to the module field.
|
| CVE-2017-14186 |
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 5.6.0
to 5.6.2, 5.4.0 to 5.4.6, 5.2.0 to 5.2.12, 5.0 and below versions
under SSL VPN web portal allows an authenticated user to inject
arbitrary web script or HTML in the context of the victim's browser
via the login redir parameter. An URL Redirection attack may also be
feasible by injecting an external URL via the affected parameter.
|
| CVE-2017-14142 |
Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before
13.2.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) partnerId or (2) playerVersion parameter to
server/admin_console/web/tools/bigRedButton.php; the (3) partnerId,
(4) playerVersion, (5) secret, (6) entryId, (7) adminUiConfId, or (8)
uiConfId parameter to
server/admin_console/web/tools/bigRedButtonPtsPoc.php; the (9)
streamUsername, (10) streamPassword, (11) streamRemoteId, (12)
streamRemoteBackupId, or (13) entryId parameter to
server/admin_console/web/tools/AkamaiBroadcaster.php; the (14) entryId
parameter to server/admin_console/web/tools/XmlJWPlayer.php; or the
(15) partnerId or (16) playerVersion parameter to
server/alpha/web/lib/bigRedButtonPtsPocHlsjs.php.
|
| CVE-2017-14134 |
A Reflected XSS Vulnerability affects the forgotten password page of
Maplesoft Maple T.A. 2016.0.6 (Customer Hosted) via the emailAddress
parameter to passwordreset/PasswordReset.do, aka Open Bug Bounty ID
OBB-286688.
|
| CVE-2017-14126 |
The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
|
| CVE-2017-14093 |
The Log Query and Quarantine Query pages in Trend Micro ScanMail for
Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.
|
| CVE-2017-14070 |
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via
the PATH_INFO to ipsearch.php, related to PHP_SELF.
|
| CVE-2017-14049 |
In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows
remote authenticated users to conduct XSS attacks via the Website
header or Website footer field.
|
| CVE-2017-14036 |
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
|
| CVE-2017-13994 |
A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions
prior to 6.2.0. The web interface lacks proper web request validation,
which could allow XSS attacks to occur if an authenticated user of the
web interface is tricked into clicking a malicious link.
|
| CVE-2017-13986 |
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM
and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or
6.11.0 Patch 1, allows for unintended information when a specific URL
is sent to the system.
|
| CVE-2017-13819 |
An issue was discovered in certain Apple products. macOS before
10.13.1 is affected. The issue involves the "HelpViewer" component. A
cross-site scripting (XSS) vulnerability allows remote attackers to
inject arbitrary web script or HTML by bypassing the Same Origin
Policy for quarantined HTML documents.
|
| CVE-2017-13778 |
Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the
site_name parameter.
|
| CVE-2017-13762 |
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
|
| CVE-2017-13754 |
Cross-site scripting (XSS) vulnerability in the "advanced settings -
time server" module in Wibu-Systems CodeMeter before 6.50b allows
remote attackers to inject arbitrary web script or HTML via the
"server name" field in actions/ChangeConfiguration.html.
|
| CVE-2017-13700 |
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices.
There is XSS in the administration interface.
|
| CVE-2017-13697 |
controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to
the dirname variable.
|
| CVE-2017-13671 |
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent
XSS via comments. It only impacts the users of the same instance
because the comment field is not part of the MISP synchronisation.
|
| CVE-2017-13138 |
DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme
before 11.2 for WordPress allows remote attackers to inject arbitrary
JavaScript.
|
| CVE-2017-12984 |
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php,
admin/message.php, and admin/message_update.php.
|
| CVE-2017-12980 |
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious
RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or
edit a wiki that uses RSS or Atom data from an attacker-controlled
server to trigger JavaScript execution. The JavaScript can be in an
author field, as demonstrated by the dc:creator element.
|
| CVE-2017-12979 |
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious
language name in a code element, in /inc/parser/xhtml.php. An attacker
can create or edit a wiki with this element to trigger JavaScript
execution.
|
| CVE-2017-12978 |
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an
external link added by an authenticated user.
|
| CVE-2017-12971 |
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows
remote attackers to inject arbitrary web script or HTML via the
account parameter to phpsftpd/users.php.
|
| CVE-2017-12948 |
Core\Admin\PFTemplater.php in the PressForward plugin 4.3.0 and earlier
for WordPress has XSS in the PATH_INFO to wp-admin/admin.php, related
to PHP_SELF.
|
| CVE-2017-12907 |
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url
path to usersearch.php.
|
| CVE-2017-12906 |
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow
remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to (1) cheaters.php or (2) confirm_resend.php.
|
| CVE-2017-12882 |
Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin
before 1.3.0 allows remote authenticated users to inject arbitrary
JavaScript or HTML via the file upload functionality.
|
| CVE-2017-12881 |
Cross-site request forgery (CSRF) vulnerability in the Spring Batch
Admin before 1.3.0 allows remote attackers to hijack the
authentication of unspecified victims and submit arbitrary requests,
such as exploiting the file upload vulnerability.
|
| CVE-2017-12856 |
Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote
attackers to inject arbitrary web script or HTML via the keyword
parameter to index.php.
|
| CVE-2017-12844 |
Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp
Mail Server 10.4.4 allows remote authenticated domain administrators
to inject arbitrary web script or HTML via a crafted user name.
|
| CVE-2017-12813 |
PHPJabbers File Sharing Script 1.0 has stored XSS in the comments
section.
|
| CVE-2017-12812 |
PHPJabbers Night Club Booking Software has stored XSS in the name
parameter in the reservations tab.
|
| CVE-2017-12811 |
PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item.
|
| CVE-2017-12810 |
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the
admin panel.
|
| CVE-2017-12798 |
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q
parameter to searchsuggest.php.
|
| CVE-2017-12792 |
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP
1.5 allow remote attackers to hijack the authentication of
administrators for requests that conduct cross-site scripting (XSS)
attacks via the (1) linkname, (2) url, or (3) title parameter in an
add action to linksmanage.php.
|
| CVE-2017-12777 |
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some
parameter to usersearch.php.
|
| CVE-2017-12738 |
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with
the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00.
The integrated web server (port 80/tcp) of the affected devices could
allow Cross-Site Scripting (XSS) attacks if unsuspecting users are
tricked into clicking on a malicious link.
|
| CVE-2017-12680 |
Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type
parameter to shoutbox.php.
|
| CVE-2017-12677 |
IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an
Angular expression on the authorize response page, which might allow
remote attackers to obtain sensitive information about the
IdentityServer authorization response.
|
| CVE-2017-12655 |
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the
query parameter to log.php in a dailylog action.
|
| CVE-2017-12649 |
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or
summary that is mishandled in the Web Content Display.
|
| CVE-2017-12648 |
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
|
| CVE-2017-12647 |
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base
article title.
|
| CVE-2017-12646 |
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name,
password, or e-mail address.
|
| CVE-2017-12645 |
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid
portletId.
|
| CVE-2017-12630 |
In Apache Drill 1.11.0 and earlier when submitting form from Query
page users are able to pass arbitrary script or HTML which will take
effect on Profile page afterwards. Example: after submitting special
script that returns cookie information from Query page, malicious user
may obtain this information from Profile page afterwards.
|
| CVE-2017-12583 |
DokuWiki through 2017-02-19b has XSS in the at parameter (aka the
DATE_AT variable) to doku.php.
|
| CVE-2017-12572 |
Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x
before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk
Light before 6.5.2, with exploitation requiring administrative access,
aka SPL-134104.
|
| CVE-2017-12416 |
Cross-site scripting (XSS) vulnerability in the GlobalProtect internal
and external gateway interface in Palo Alto Networks PAN-OS before
6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before
8.0.3 allows remote attackers to inject arbitrary web script or HTML
via vectors related to improper request parameter validation.
|
| CVE-2017-12413 |
AXIS 2100 devices 2.43 have XSS via the URI, possibly related to
admin/admin.shtml.
|
| CVE-2017-12366 |
A vulnerability in Cisco WebEx Meeting Center could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack against a user of an affected system. The vulnerability is
due to insufficient input validation of some parameters that are passed
to the web server of the affected system. An attacker could exploit
this vulnerability by convincing a user to follow a malicious link or
by intercepting a user request and injecting malicious code into the
request. A successful exploit could allow the attacker to execute
arbitrary script code in the context of the affected web interface or
allow the attacker to access sensitive browser-based information. Cisco
Bug IDs: CSCvf78635,, CSCvg52440.
|
| CVE-2017-12358 |
A vulnerability in the web-based management interface of Cisco Jabber
for Windows, Mac, Android, and iOS could allow an authenticated, remote
attacker to conduct a cross-site scripting (XSS) attack against a user
of the web-based management interface. The vulnerability is due to
insufficient validation of user-supplied input by the web-based
management interface of an affected device. An attacker could exploit
this vulnerability by persuading a user of the interface to click a
malicious link. A successful exploit could allow the attacker to
execute arbitrary script code in the context of the interface or allow
the attacker to access sensitive browser-based information. Cisco Bug
IDs: CSCvf79080, CSCvf79088.
|
| CVE-2017-12357 |
A vulnerability in the web-based management interface of Cisco Unified
Communications Manager could allow an authenticated, remote attacker to
conduct a cross-site scripting (XSS) attack against a user of the
web-based management interface of an affected device. The vulnerability
is due to insufficient validation of user-supplied input by the
web-based management interface of an affected device. An attacker could
exploit this vulnerability by persuading a user of the interface to
click a crafted link. A successful exploit could allow the attacker to
execute arbitrary script code in the context of the interface or allow
the attacker to access sensitive browser-based information. Cisco Bug
IDs: CSCvf79346.
|
| CVE-2017-12356 |
A vulnerability in the web-based management interface of Cisco Jabber
for Windows, Mac, Android, and iOS could allow an unauthenticated,
remote attacker to conduct a cross-site scripting (XSS) attack against
a user of the web-based management interface of an affected device. The
vulnerability is due to insufficient validation of user-supplied input
by the web-based management interface of an affected device. An
attacker could exploit this vulnerability by persuading a user of the
interface to click a crafted link. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the
interface or allow the attacker to access sensitive browser-based
information. Cisco Bug IDs: CSCvf50378, CSCvg56018.
|
| CVE-2017-12349 |
Multiple vulnerabilities in the web-based management interface of Cisco
UCS Central Software could allow a remote attacker to conduct a
cross-site scripting (XSS) attack against a user of the affected
interface or hijack a valid session ID from a user of the affected
interface. Cisco Bug IDs: CSCvf71978, CSCvf71986.
|
| CVE-2017-12348 |
Multiple vulnerabilities in the web-based management interface of Cisco
UCS Central Software could allow a remote attacker to conduct a
cross-site scripting (XSS) attack against a user of the affected
interface or hijack a valid session ID from a user of the affected
interface. Cisco Bug IDs: CSCvf71978, CSCvf71986.
|
| CVE-2017-12347 |
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM)
Software could allow a remote attacker to inject arbitrary values into
DCNM configuration parameters, redirect a user to a malicious website,
inject malicious content into a DCNM client interface, or conduct a
cross-site scripting (XSS) attack against a user of the affected
software. Cisco Bug IDs: CSCvf40477, CSCvf63150, CSCvf68218,
CSCvf68235, CSCvf68247.
|
| CVE-2017-12346 |
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM)
Software could allow a remote attacker to inject arbitrary values into
DCNM configuration parameters, redirect a user to a malicious website,
inject malicious content into a DCNM client interface, or conduct a
cross-site scripting (XSS) attack against a user of the affected
software. Cisco Bug IDs: CSCvf40477, CSCvf63150, CSCvf68218,
CSCvf68235, CSCvf68247.
|
| CVE-2017-12345 |
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM)
Software could allow a remote attacker to inject arbitrary values into
DCNM configuration parameters, redirect a user to a malicious website,
inject malicious content into a DCNM client interface, or conduct a
cross-site scripting (XSS) attack against a user of the affected
software. Cisco Bug IDs: CSCvf40477, CSCvf63150, CSCvf68218,
CSCvf68235, CSCvf68247.
|
| CVE-2017-12344 |
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM)
Software could allow a remote attacker to inject arbitrary values into
DCNM configuration parameters, redirect a user to a malicious website,
inject malicious content into a DCNM client interface, or conduct a
cross-site scripting (XSS) attack against a user of the affected
software. Cisco Bug IDs: CSCvf40477, CSCvf63150, CSCvf68218,
CSCvf68235, CSCvf68247.
|
| CVE-2017-12343 |
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM)
Software could allow a remote attacker to inject arbitrary values into
DCNM configuration parameters, redirect a user to a malicious website,
inject malicious content into a DCNM client interface, or conduct a
cross-site scripting (XSS) attack against a user of the affected
software. Cisco Bug IDs: CSCvf40477, CSCvf63150, CSCvf68218,
CSCvf68235, CSCvf68247.
|
| CVE-2017-12323 |
Multiple vulnerabilities in the web interface of the Cisco Registered
Envelope Service (a cloud-based service) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack or redirect a user of the affected service to an undesired
web page. The vulnerabilities are due to insufficient validation of
user-supplied input by the web-based management interface of the
affected service. An attacker could exploit these vulnerabilities by
persuading a user to click a malicious link or by sending an HTTP
request that could cause the affected service to redirect the request
to a specified malicious URL. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the web
interface of the affected system or allow the attacker to access
sensitive browser-based information on the affected system. These types
of exploits could also be used in phishing attacks that send users to
malicious websites without their knowledge. Cisco Bug IDs: CSCve77195,
CSCve90978, CSCvf42310, CSCvf42703, CSCvf42723, CSCvf46169, CSCvf49999.
|
| CVE-2017-12322 |
Multiple vulnerabilities in the web interface of the Cisco Registered
Envelope Service (a cloud-based service) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack or redirect a user of the affected service to an undesired
web page. The vulnerabilities are due to insufficient validation of
user-supplied input by the web-based management interface of the
affected service. An attacker could exploit these vulnerabilities by
persuading a user to click a malicious link or by sending an HTTP
request that could cause the affected service to redirect the request
to a specified malicious URL. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the web
interface of the affected system or allow the attacker to access
sensitive browser-based information on the affected system. These types
of exploits could also be used in phishing attacks that send users to
malicious websites without their knowledge. Cisco Bug IDs: CSCve77195,
CSCve90978, CSCvf42310, CSCvf42703, CSCvf42723, CSCvf46169, CSCvf49999.
|
| CVE-2017-12321 |
Multiple vulnerabilities in the web interface of the Cisco Registered
Envelope Service (a cloud-based service) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack or redirect a user of the affected service to an undesired
web page. The vulnerabilities are due to insufficient validation of
user-supplied input by the web-based management interface of the
affected service. An attacker could exploit these vulnerabilities by
persuading a user to click a malicious link or by sending an HTTP
request that could cause the affected service to redirect the request
to a specified malicious URL. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the web
interface of the affected system or allow the attacker to access
sensitive browser-based information on the affected system. These types
of exploits could also be used in phishing attacks that send users to
malicious websites without their knowledge. Cisco Bug IDs: CSCve77195,
CSCve90978, CSCvf42310, CSCvf42703, CSCvf42723, CSCvf46169, CSCvf49999.
|
| CVE-2017-12320 |
Multiple vulnerabilities in the web interface of the Cisco Registered
Envelope Service (a cloud-based service) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack or redirect a user of the affected service to an undesired
web page. The vulnerabilities are due to insufficient validation of
user-supplied input by the web-based management interface of the
affected service. An attacker could exploit these vulnerabilities by
persuading a user to click a malicious link or by sending an HTTP
request that could cause the affected service to redirect the request
to a specified malicious URL. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the web
interface of the affected system or allow the attacker to access
sensitive browser-based information on the affected system. These types
of exploits could also be used in phishing attacks that send users to
malicious websites without their knowledge. Cisco Bug IDs: CSCve77195,
CSCve90978, CSCvf42310, CSCvf42703, CSCvf42723, CSCvf46169, CSCvf49999.
|
| CVE-2017-12304 |
A vulnerability in the IOS daemon (IOSd) web-based management interface
of Cisco IOS and IOS XE Software could allow an unauthenticated, remote
attacker to conduct a cross-site scripting (XSS) attack against a user
of the web-based management interface on an affected device. The
vulnerability is due to insufficient validation of user-supplied input
by the web-based management interface. An attacker could exploit this
vulnerability by persuading a user of the interface to click a crafted
link. A successful exploit could allow the attacker to execute
arbitrary script code in the web-based management interface or allow
the attacker to access sensitive browser-based information. Cisco Bug
IDs: CSCvf60862.
|
| CVE-2017-12298 |
A vulnerability in Cisco WebEx Meeting Center could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack against a user of an affected system. The vulnerability is
due to insufficient input validation of some parameters that are passed
to the web server of the affected system. An attacker could exploit
this vulnerability by convincing a user to follow a malicious link or
by intercepting a user request and injecting malicious code into the
request. A successful exploit could allow the attacker to execute
arbitrary script code in the context of the affected web interface or
allow the attacker to access sensitive browser-based information. Cisco
Bug IDs: CSCvf78615, CSCvf78628.
|
| CVE-2017-12296 |
A vulnerability in Cisco WebEx Meetings Server could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack against a user of the affected system. The vulnerability
is due to insufficient input validation of some parameters that are
passed to the web server of the affected system. An attacker could
exploit this vulnerability by convincing a user to follow a malicious
link or by intercepting a user request and injecting malicious code
into the request. A successful exploit could allow the attacker to
execute arbitrary script code in the context of the affected web
interface or allow the attacker to access sensitive browser-based
information. Cisco Bug IDs: CSCvf51241, CSCvf51261.
|
| CVE-2017-12294 |
A vulnerability in Cisco WebEx Meetings Server could allow an
authenticated, remote attacker to conduct a cross-site scripting (XSS)
attack against a user of the affected system. The vulnerability is due
to insufficient input validation of some parameters that are passed to
the web server of the affected system. An attacker could exploit this
vulnerability by convincing a user to follow a malicious link or by
intercepting a user request and injecting malicious code into the
request. A successful exploit could allow the attacker to execute
arbitrary script code in the context of the affected web interface or
allow the attacker to access sensitive browser-based information. Cisco
Bug IDs: CSCvf85562.
|
| CVE-2017-12292 |
Multiple vulnerabilities in the web interface of the Cisco Registered
Envelope Service (a cloud-based service) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack or redirect a user of the affected service to an undesired
web page. The vulnerabilities are due to insufficient validation of
user-supplied input by the web-based management interface of the
affected service. An attacker could exploit these vulnerabilities by
persuading a user to click a malicious link or by sending an HTTP
request that could cause the affected service to redirect the request
to a specified malicious URL. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the web
interface of the affected system or allow the attacker to access
sensitive browser-based information on the affected system. These types
of exploits could also be used in phishing attacks that send users to
malicious websites without their knowledge. Cisco Bug IDs: CSCve77195,
CSCve90978, CSCvf42310, CSCvf42703, CSCvf42723, CSCvf46169, CSCvf49999.
|
| CVE-2017-12291 |
Multiple vulnerabilities in the web interface of the Cisco Registered
Envelope Service (a cloud-based service) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack or redirect a user of the affected service to an undesired
web page. The vulnerabilities are due to insufficient validation of
user-supplied input by the web-based management interface of the
affected service. An attacker could exploit these vulnerabilities by
persuading a user to click a malicious link or by sending an HTTP
request that could cause the affected service to redirect the request
to a specified malicious URL. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the web
interface of the affected system or allow the attacker to access
sensitive browser-based information on the affected system. These types
of exploits could also be used in phishing attacks that send users to
malicious websites without their knowledge. Cisco Bug IDs: CSCve77195,
CSCve90978, CSCvf42310, CSCvf42703, CSCvf42723, CSCvf46169, CSCvf49999.
|
| CVE-2017-12290 |
Multiple vulnerabilities in the web interface of the Cisco Registered
Envelope Service (a cloud-based service) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack or redirect a user of the affected service to an undesired
web page. The vulnerabilities are due to insufficient validation of
user-supplied input by the web-based management interface of the
affected service. An attacker could exploit these vulnerabilities by
persuading a user to click a malicious link or by sending an HTTP
request that could cause the affected service to redirect the request
to a specified malicious URL. A successful exploit could allow the
attacker to execute arbitrary script code in the context of the web
interface of the affected system or allow the attacker to access
sensitive browser-based information on the affected system. These types
of exploits could also be used in phishing attacks that send users to
malicious websites without their knowledge. Cisco Bug IDs: CSCve77195,
CSCve90978, CSCvf42310, CSCvf42703, CSCvf42723, CSCvf46169, CSCvf49999.
|
| CVE-2017-12288 |
A vulnerability in the web-based management interface of Cisco Unified
Contact Center Express could allow an unauthenticated, remote attacker
to conduct a cross-site scripting (XSS) attack against a user of an
affected device. The vulnerability is due to insufficient validation of
user-supplied input by the web-based management interface of the
affected device. An attacker could exploit this vulnerability by
persuading a user of the interface to click a malicious link. A
successful exploit could allow the attacker to execute arbitrary script
code in the context of the interface or allow the attacker to access
sensitive browser-based information. Cisco Bug IDs: CSCvf09173.
|
| CVE-2017-12272 |
A vulnerability in the web framework code of Cisco IOS XE Software
could allow an unauthenticated, remote attacker to conduct a cross-site
scripting (XSS) attack against a user of the web interface of the
affected software. The vulnerability is due to insufficient input
validation of some parameters that are passed to the web server of the
affected software. An attacker could exploit this vulnerability by
convincing a user of the web interface to access a malicious link or by
intercepting a user request for the affected web interface and
injecting malicious code into the request. A successful exploit could
allow the attacker to execute arbitrary script code in the context of
the affected web interface or allow the attacker to access sensitive
browser-based information. Cisco Bug IDs: CSCvb09516.
|
| CVE-2017-12269 |
A vulnerability in the web UI of Cisco Spark Messaging Software could
allow an authenticated, remote attacker to perform a stored cross-site
scripting (XSS) attack. The vulnerability is due to insufficient input
validation by the web UI of the affected software. An attacker could
exploit this vulnerability by injecting XSS content into the web UI of
the affected software. A successful exploit could allow the attacker to
force a user to execute code of the attacker's choosing or allow the
attacker to retrieve sensitive information from the user. Cisco Bug
IDs: CSCvf70587, CSCvf70592.
|
| CVE-2017-12265 |
A vulnerability in the web-based management interface of Cisco Adaptive
Security Appliance (ASA) Software could allow an unauthenticated,
remote attacker to conduct a cross-site scripting (XSS) attack against
a user of the web-based management interface of an affected device, aka
HREF XSS. The vulnerability is due to insufficient validation of
user-supplied input by the web-based management interface of an
affected device. An attacker could exploit this vulnerability by
persuading a user of the interface to click a crafted link. A
successful exploit could allow the attacker to execute arbitrary script
code in the context of the interface or allow the attacker to access
sensitive browser-based information. The vulnerability exists in the
Cisco Adaptive Security Appliance (ASA) Software when the WEBVPN
feature is enabled. Cisco Bug IDs: CSCve91068.
|
| CVE-2017-12257 |
A vulnerability in the web framework of Cisco WebEx Meetings Server
could allow an unauthenticated, remote attacker to conduct a cross-site
scripting (XSS) attack against a user of the web interface of an
affected system. The vulnerability is due to insufficient input
validation of some parameters that are passed to the web server of the
affected system. An attacker could exploit this vulnerability by
convincing a user to follow a malicious link or by intercepting a user
request and injecting malicious code into the request. A successful
exploit could allow the attacker to execute arbitrary script code in
the context of the affected web interface or allow the attacker to
access sensitive browser-based information. Cisco Bug IDs: CSCve96608.
|
| CVE-2017-12248 |
A vulnerability in the web framework code of Cisco Unified Intelligence
Center Software could allow an unauthenticated, remote attacker to
conduct a cross-site scripting (XSS) attack against a user of the web
interface of an affected system. The vulnerability is due to
insufficient input validation of some parameters that are passed to the
web server of the affected software. An attacker could exploit this
vulnerability by persuading a user to click a malicious link or by
intercepting a user request and injecting malicious code into the
request. A successful exploit could allow the attacker to execute
arbitrary script code in the context of the affected site or allow the
attacker to access sensitive browser-based information. Cisco Bug IDs:
CSCve76835.
|
| CVE-2017-12221 |
A vulnerability in the web framework of Cisco Firepower Management
Center could allow an authenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against a user of the web interface
of the affected software. The vulnerability is due to insufficient
validation of user-supplied input by the affected software. Successful
exploitation of this vulnerability could allow the attacker to execute
arbitrary code in the context of the affected system. Cisco Bug IDs:
CSCvc38983.
|
| CVE-2017-12220 |
A vulnerability in the web-based management interface of Cisco
Firepower Management Center could allow an unauthenticated, remote
attacker to conduct a reflected cross-site scripting (XSS) attack
against a user of the web-based management interface of an affected
device. The vulnerability is due to insufficient validation of
user-supplied input by the web-based management interface of an
affected device. An attacker could exploit this vulnerability by
persuading a user of the interface to click a crafted link. A
successful exploit could allow the attacker to execute arbitrary script
code in the context of the interface or allow the attacker to access
sensitive browser-based information. Cisco Bug IDs: CSCvc50771.
|
| CVE-2017-12212 |
A vulnerability in the web framework of Cisco Unity Connection could
allow an unauthenticated, remote attacker to conduct a reflected
cross-site scripting (XSS) attack against a user of the web interface
of an affected system. The vulnerability is due to insufficient input
validation of certain parameters that are passed to the affected
software via the HTTP GET and HTTP POST methods. An attacker who can
convince a user to follow an attacker-supplied link could execute
arbitrary script or HTML code in the user's browser in the context of
an affected site. Known Affected Releases 10.5(2). Cisco Bug IDs:
CSCvf25345.
|
| CVE-2017-12200 |
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS
in the Add Product Manually component.
|
| CVE-2017-12158 |
It was found that Keycloak would accept a HOST header URL in the admin
console and use it to determine web resource locations. An attacker
could use this flaw against an authenticated user to attain reflected
XSS via a malicious server.
|
| CVE-2017-12156 |
Moodle 3.x has XSS in the contact form on the "non-respondents" page in
non-anonymous feedback.
|
| CVE-2017-12139 |
XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing
MIME type validation in htdocs/class/uploader.php.
|
| CVE-2017-12131 |
The Easy Testimonials plugin 3.0.4 for WordPress has XSS in
include/settings/display.options.php, as demonstrated by the Default
Testimonials Width, View More Testimonials Link, and Testimonial
Excerpt Options screens.
|
| CVE-2017-12072 |
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in
Synology Photo Station before 6.8.0-3456 allows remote authenticated
users to inject arbitrary web scripts or HTML via the id parameter.
|
| CVE-2017-12068 |
The Event List plugin 0.7.9 for WordPress has XSS in the slug array
parameter to wp-admin/admin.php in an el_admin_categories delete_bulk
action.
|
| CVE-2017-12066 |
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti before 1.1.16 allows remote authenticated users to inject
arbitrary web script or HTML via specially crafted HTTP Referer
headers, related to the $cancel_url variable. NOTE: this vulnerability
exists because of an incomplete fix (lack of the htmlspecialchars
ENT_QUOTES flag) for CVE-2017-11163.
|
| CVE-2017-12062 |
An XSS issue was discovered in manage_user_page.php in MantisBT 2.x
before 2.5.2. The 'filter' field is not sanitized before being rendered
in the Manage User page, allowing remote attackers to execute arbitrary
JavaScript code if CSP is disabled.
|
| CVE-2017-12061 |
An XSS issue was discovered in admin/install.php in MantisBT before
1.3.12 and 2.x before 2.5.2. Some variables under user control in the
MantisBT installation script are not properly sanitized before being
output, allowing remote attackers to inject arbitrary JavaScript code,
as demonstrated by the $f_database, $f_db_username, and
$f_admin_username variables. This is mitigated by the fact that the
admin/ folder should be deleted after installation, and also prevented
by CSP.
|
| CVE-2017-11820 |
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft
SharePoint Enterprise Server 2016 allow an attacker to exploit a
cross-site scripting (XSS) vulnerability by sending a specially
crafted request to an affected SharePoint server, due to how
SharePoint Server sanitizes web requests, aka "Microsoft Office
SharePoint XSS Vulnerability". This CVE ID is unique from
CVE-2017-11775 and CVE-2017-11777.
|
| CVE-2017-11777 |
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft
SharePoint Enterprise Server 2016 allow an attacker to exploit a
cross-site scripting (XSS) vulnerability by sending a specially
crafted request to an affected SharePoint server, due to how
SharePoint Server sanitizes web requests, aka "Microsoft Office
SharePoint XSS Vulnerability". This CVE ID is unique from
CVE-2017-11775 and CVE-2017-11820.
|
| CVE-2017-11775 |
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft
SharePoint Enterprise Server 2016 allow an attacker to exploit a
cross-site scripting (XSS) vulnerability by sending a specially
crafted request to an affected SharePoint server, due to how
SharePoint Server sanitizes web requests, aka "Microsoft Office
SharePoint XSS Vulnerability". This CVE ID is unique from
CVE-2017-11777 and CVE-2017-11820.
|
| CVE-2017-11744 |
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System
Settings module are vulnerable to XSS. A malicious payload sent to
connectors/index.php will be triggered by every user, when they visit
this module.
|
| CVE-2017-11737 |
interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS
via the Subject and Message-Id headers, which are mishandled in the
history page.
|
| CVE-2017-11727 |
services/system_io/actionprocessor/Contact.rails in ConnectWise Manage
2017.5 allows arbitrary client-side JavaScript code execution
(involving a ContactCommon field) on victims who click on a crafted
link, aka XSS.
|
| CVE-2017-11716 |
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.
|
| CVE-2017-11691 |
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti
1.1.13 allows remote attackers to inject arbitrary web script or HTML
via specially crafted HTTP Referer headers.
|
| CVE-2017-11687 |
Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event
log parsing and Display functions in Zoho ManageEngine Event Log
Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web
script or HTML via syslog.
|
| CVE-2017-11686 |
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote
attackers to obtain an authenticated user's password via XSS
vulnerabilities or sniffing non-SSL traffic on the network, because the
password is represented in a cookie with a reversible encoding method.
|
| CVE-2017-11685 |
Multiple Reflective cross-site scripting (XSS) vulnerabilities in
search and display of event data in Zoho ManageEngine Event Log
Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web
script or HTML, as demonstrated by the fName parameter.
|
| CVE-2017-11677 |
Cross-site scripting (XSS) vulnerability in Hashtopus 1.5g allows
remote attackers to inject arbitrary web script or HTML via the query
string to admin.php.
|
| CVE-2017-11666 |
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the
file previewer plugin in Kopano WebApp versions 3.3.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
specially crafted previewable file.
|
| CVE-2017-11651 |
NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url
tag.
|
| CVE-2017-11647 |
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software:
V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to stored cross-site
scripting attacks. Creating an SSID with an XSS payload results in
successful exploitation.
|
| CVE-2017-11629 |
dayrui FineCms through 5.0.10 has Cross Site Scripting (XSS) in
controllers/api.php via the function parameter in a c=api&m=data2
request.
|
| CVE-2017-11617 |
Cross-site scripting (XSS) vulnerability in atmail prior to version
7.8.0.2 allows remote attackers to inject arbitrary web script or HTML
within the body of an email via an IMG element with both single quotes
and double quotes.
|
| CVE-2017-11612 |
In Joomla! before 3.7.4, inadequate filtering of potentially malicious
HTML tags leads to XSS vulnerabilities in various components.
|
| CVE-2017-11611 |
Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks. The
vulnerability exists due to insufficient sanitization of the file name
in a "create-file-popup" action, and the directory name in a
"create-directory-popup" action, in the HTTP POST method to the
"/plugin/file_manager/" script (aka an
/admin/plugin/file_manager/browse// URI).
|
| CVE-2017-11594 |
Cross-site scripting (XSS) vulnerability in the Markdown parser in
Loomio before 1.8.0 allows remote attackers to inject arbitrary web
script or HTML via non-sanitized Markdown content in a new thread or a
thread comment.
|
| CVE-2017-11593 |
Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus
extension before 0.5.7 for Chrome allows remote attackers to inject
arbitrary web script or HTML into some web applications via the upload
and display of crafted text, markdown, or rst files that are designed
to be viewed in the browser as plain text, but that will be converted
to HTML without proper sanitization.
|
| CVE-2017-11581 |
dayrui FineCms 5.0.9 has Cross Site Scripting (XSS) in admin/Login.php
via a payload in the username field that does not begin with a '<'
character.
|
| CVE-2017-11516 |
An XSS vulnerability exists in
framework/views/errorHandler/exception.php in Yii Framework 2.0.12
affecting the exception screen when debug mode is enabled, because
$exception->errorInfo is mishandled.
|
| CVE-2017-11507 |
A cross site scripting (XSS) vulnerability exists in Check_MK versions
1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an
unauthenticated attacker to inject arbitrary HTML or JavaScript via
the output_format parameter, and the username parameter of failed HTTP
basic authentication attempts, which is returned unencoded in an
internal server error page.
|
| CVE-2017-11503 |
PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email
Address" fields of code_generator.php.
|
| CVE-2017-11481 |
Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting
(XSS) vulnerability via URL fields that could allow an attacker to
obtain sensitive information from or perform destructive actions on
behalf of other Kibana users.
|
| CVE-2017-11479 |
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS)
vulnerability in Timelion that could allow an attacker to obtain
sensitive information from or perform destructive actions on behalf of
other Kibana users.
|
| CVE-2017-11460 |
Cross-site scripting (XSS) vulnerability in the DataArchivingService
servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject
arbitrary web script or HTML via the responsecode parameter to
shp/shp_result.jsp, aka SAP Security Note 2308535.
|
| CVE-2017-11458 |
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol
servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject
arbitrary web script or HTML via the sessionID parameter, aka SAP
Security Note 2406783.
|
| CVE-2017-11441 |
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before
58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33,
and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.
|
| CVE-2017-11439 |
In Sitecore 8.2, there is reflected XSS in the
shell/Applications/Tools/Run Program parameter.
|
| CVE-2017-11355 |
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform
7.2 ML0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) PATH_INFO to the main page; the (2)
beanReference parameter to the JavaBean viewer page; or the (3)
pyTableName to the System database schema modification page.
|
| CVE-2017-11320 |
Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor
TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning
and steal credentials from the router.
|
| CVE-2017-11285 |
Adobe ColdFusion has a cross-site scripting (XSS) vulnerability. This
affects Update 4 and earlier versions for ColdFusion 2016, and Update
12 and earlier versions for ColdFusion 11.
|
| CVE-2017-11202 |
FineCMS through 2017-07-12 allows XSS in visitors.php because
JavaScript in visited URLs is not restricted either during logging or
during the reading of logs, a different vulnerability than
CVE-2017-11180.
|
| CVE-2017-11201 |
application/core/controller/images.php in FineCMS through 2017-07-12
allows remote authenticated admins to conduct XSS attacks by uploading
an image via a route=images action.
|
| CVE-2017-11198 |
Cross-site scripting (XSS) vulnerability in
/application/lib/ajax/get_image.php in FineCMS through 2017-07-12
allows remote attackers to inject arbitrary web script or HTML via the
folder, id, or name parameter.
|
| CVE-2017-11195 |
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The
helpLaunchPage parameter is reflected in an IFRAME element, if the
value contains two quotes. It properly sanitizes quotes and tags, so
one cannot simply close the src with a quote and inject after that.
However, an attacker can use javascript: or data: to abuse this.
|
| CVE-2017-11194 |
Pulse Connect Secure 8.3R1 has Reflected XSS in
adminservercacertdetails.cgi. In the admin panel, the certid parameter
of adminservercacertdetails.cgi is reflected in the application's
response and is not properly sanitized, allowing an attacker to inject
tags. An attacker could come up with clever payloads to make the system
run commands such as ping, ping6, traceroute, nslookup, arp, etc.
|
| CVE-2017-11182 |
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found
in the My Profile section. All input fields are vulnerable.
|
| CVE-2017-11181 |
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found
in the Messaging section. Subject and Message fields are vulnerable.
|
| CVE-2017-11180 |
FineCMS through 2017-07-11 has stored XSS in the logging functionality,
as demonstrated by an XSS payload in (1) the User-Agent header of an
HTTP request or (2) the username entered on the login screen.
|
| CVE-2017-11179 |
FineCMS through 2017-07-11 has stored XSS in route=admin when modifying
user information, and in route=register when registering a user
account.
|
| CVE-2017-11163 |
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti 1.1.12 allows remote authenticated users to inject arbitrary web
script or HTML via specially crafted HTTP Referer headers, related to
the $cancel_url variable.
|
| CVE-2017-11128 |
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by
the Title field of a New Entry.
|
| CVE-2017-11127 |
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a
"Content-Type: image/svg+xml" header.
|
| CVE-2017-11107 |
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the
form, element, rdn, or container parameter.
|
| CVE-2017-10991 |
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the
rangestart and rangeend parameters on the wps_referrers_page page.
|
| CVE-2017-10975 |
Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might
allow remote attackers to inject arbitrary web script or HTML via a
crafted filename that is mishandled in an upload notification and in
the myfiles component, if the attacker can convince the victim to
proceed with an upload despite the appearance of an XSS payload in the
filename.
|
| CVE-2017-10970 |
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12
allows remote anonymous users to inject arbitrary web script or HTML
via the id parameter, related to the die_html_input_error function in
lib/html_validate.php.
|
| CVE-2017-10967 |
In FineCMS before 2017-07-06, application\core\controller\config.php
allows XSS in the (1) key_name, (2) key_value, and (3) meaning
parameters.
|
| CVE-2017-10962 |
REDCap before 7.5.1 has XSS via the query string.
|
| CVE-2017-10801 |
phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO
to the search/tag/ URI.
|
| CVE-2017-10798 |
In ObjectPlanet Opinio before 7.6.4, there is XSS.
|
| CVE-2017-10795 |
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows
remote attackers to inject arbitrary web script or HTML via the body to
blog/add/, a different vulnerability than CVE-2017-6069.
|
| CVE-2017-10711 |
In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send
Password Reset Email form) can insert XSS sequences via the user
parameter.
|
| CVE-2017-10701 |
Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50
allows remote attackers to inject arbitrary web script or HTML, aka
SAP Security Notes 2469860, 2471209, and 2488516.
|
| CVE-2017-10676 |
On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was
found in the form2userconfig.cgi username parameter.
|
| CVE-2017-10673 |
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
|
| CVE-2017-10667 |
In index.php in Zen Cart 1.6.0, the products_id parameter can cause
XSS.
|
| CVE-2017-1002017 |
Vulnerability in wordpress plugin gift-certificate-creator v1.0, The
code in gc-list.php doesn't sanitize user input to prevent a stored
XSS vulnerability.
|
| CVE-2017-1002011 |
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2,
There is a stored XSS vulnerability via the $value->gallery_name and
$value->gallery_description where anyone with privileges to modify or
add galleries/images and inject javascript into the database.
|
| CVE-2017-1000492 |
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to
code execution due to enabled node integration
|
| CVE-2017-1000491 |
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS
which leads to code execution due to enabled node integration.
|
| CVE-2017-1000488 |
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack
when using Mautic forms on a Mautic landing page using GET parameters
to pre-populate the form.
|
| CVE-2017-1000459 |
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input
in markdown notes
|
| CVE-2017-1000457 |
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal
version 2.5.0.0 allows remote attackers to inject arbitrary web script
or HTML via the helpkey parameter. Exploitation requires authenticated
reflected cross-site scripting for user accounts assigned either the
"Administrators" or "Content Administrators" role.
|
| CVE-2017-1000443 |
Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability
in the bank transactions component resulting in arbitrary code
execution in the browser.
|
| CVE-2017-1000442 |
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the
url field on the password workspace
|
| CVE-2017-1000431 |
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is
vulnerable to an XSS issue in the search module, resulting in a risk
of attackers injecting scripts which may e.g. steal authentication
credentials.
|
| CVE-2017-1000429 |
rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file
Weixin.php.
|
| CVE-2017-1000427 |
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the
data: URI parser.
|
| CVE-2017-1000425 |
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp
page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to
inject arbitrary web script or HTML via a javascript: URI in the
"movie" parameter.
|
| CVE-2017-1000240 |
The application OpenEMR is affected by multiple reflected & stored
Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and
prior versions. These vulnerabilities could allow remote authenticated
attackers to inject arbitrary web script or HTML.
|
| CVE-2017-1000227 |
Stored XSS in Salutation Responsive WordPress + BuddyPress Theme
version 3.0.15 could allow logged-in users to do almost anything an
admin can
|
| CVE-2017-1000225 |
Reflected XSS in Relevanssi Premium version 1.14.8 when using
relevanssi_didyoumean() could allow unauthenticated attacker to do
almost anything an admin can
|
| CVE-2017-1000223 |
A stored web content injection vulnerability (WCI, a.k.a XSS) is
present in MODX Revolution CMS version 2.5.6 and earlier. An
authenticated user with permissions to edit users can save malicious
JavaScript as a User Group name and potentially take control over
victims' accounts. This can lead to an escalation of privileges
providing complete administrative control over the CMS.
|
| CVE-2017-1000213 |
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST
parameter in /admin/admintools/tool.php?tool=user_search
|
| CVE-2017-1000193 |
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand
logo image name resulting in JavaScript code execution in the victim's
browser.
|
| CVE-2017-1000164 |
Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook
resulting code execution and privilege escalation
|
| CVE-2017-1000149 |
Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before
15.10.2 are vulnerable to XSS due to window.opener (target="_blank"
and window.open())
|
| CVE-2017-1000065 |
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in
OpenMediaVault release 2.1 in Access Rights Management(Users)
functionality allows attackers to inject arbitrary web scripts and
execute malicious scripts within an authenticated client's browser.
|
| CVE-2017-1000063 |
kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404
page resulting in information disclosure
|
| CVE-2017-1000058 |
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11,
one in the user profile and one in the Exif data parser.
|
| CVE-2017-1000054 |
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the
markdown link parsing code for messages.
|
| CVE-2017-1000051 |
Cross-site scripting (XSS) vulnerability in pad export in XWiki labs
CryptPad before 1.1.1 allows remote attackers to inject arbitrary web
script or HTML via the pad content
|
| CVE-2017-1000038 |
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored
XSS resulting in attacker being able to execute JavaScript on the
affected site
|
| CVE-2017-1000035 |
Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener
attack
|
| CVE-2017-1000032 |
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow
remote attackers to inject arbitrary web script or HTML via the
parent_id parameter to tree.php and drp_action parameter to
data_sources.php.
|
| CVE-2017-1000012 |
MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying
the data in the database to the user
|
| CVE-2017-1000011 |
MyWebSQL version 3.6 is vulnerable to stored XSS in the database
manager component resulting in account takeover or stealing of
information
|
| CVE-2017-1000006 |
Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an
XSS issue.
|
| CVE-2017-1000005 |
PHPMiniAdmin version 1.9.160630 is vulnerable to stored XSS in the
name of databases, tables and columns resulting in potential account
takeover and scraping of data (stealing data).
|
| CVE-2017-0893 |
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a
vulnerable JavaScript library for sanitizing untrusted user-input
which suffered from a XSS vulnerability caused by a behaviour change
in Safari 10.1 and 10.2. Note that Nextcloud employs a strict
Content-Security-Policy preventing exploitation of this XSS issue on
modern web browsers.
|
| CVE-2017-0891 |
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to
an inadequate escaping of error messages leading to XSS
vulnerabilities in multiple components.
|
| CVE-2017-0890 |
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping
leading to a XSS vulnerability in the search module. To be exploitable
a user has to write or paste malicious content into the search
dialogue.
|
| CVE-2017-0378 |
XSS exists in the login_form function in views/helpers.php in Phamm
before 0.6.7, exploitable via the PATH_INFO to main.php.
|
| CVE-2017-0255 |
Microsoft SharePoint Foundation 2013 SP1 allows an elevation of
privilege vulnerability when it does not properly sanitize a specially
crafted web request, aka "Microsoft SharePoint XSS Vulnerability".
|
| CVE-2017-0195 |
Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and
SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010
SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online
Server allows remote attackers to perform cross-site scripting and run
script with local user privileges via a crafted request, aka
"Microsoft Office XSS Elevation of Privilege Vulnerability."
|
| CVE-2017-0110 |
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook
Web Access (OWA) allows remote attackers to inject arbitrary web
script or HTML via a crafted email or chat client, aka "Microsoft
Exchange Server Elevation of Privilege Vulnerability."
|
| CVE-2017-0107 |
Microsoft SharePoint Server fails to sanitize crafted web requests,
allowing remote attackers to run cross-script in local security
context, aka "Microsoft SharePoint XSS Vulnerability."
|
| CVE-2017-0055 |
Microsoft Internet Information Server (IIS) in Windows Vista SP2;
Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows
Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and
1607; and Windows Server 2016 allows remote attackers to perform
cross-site scripting and run script with local user privileges via a
crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege
Vulnerability."
|
| CVE-2017-0017 |
The RegEx class in the XSS filter in Microsoft Edge allows remote
attackers to conduct cross-site scripting (XSS) attacks and obtain
sensitive information via unspecified vectors, aka "Microsoft Edge
Information Disclosure Vulnerability." This vulnerability is different
from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0065,
and CVE-2017-0068.
|
| CVE-2016-9910 |
The serializer in html5lib before 0.99999999 might allow remote
attackers to conduct cross-site scripting (XSS) attacks by leveraging
mishandling of special characters in attribute values, a different
vulnerability than CVE-2016-9909.
|
| CVE-2016-9909 |
The serializer in html5lib before 0.99999999 might allow remote
attackers to conduct cross-site scripting (XSS) attacks by leveraging
mishandling of the < (less than) character in attribute values.
|
| CVE-2016-9891 |
Cross-site scripting (XSS) vulnerability in admin/media.php and
admin/media_item.php in Dotclear before 2.11 allows remote
authenticated users to inject arbitrary web script or HTML via the
upfiletitle or media_title parameter (aka the media title).
|
| CVE-2016-9889 |
Some forms with the parameter geo_zoomlevel_to_found_location in Tiki
Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before
16.1 don't have the input sanitized, related to tiki-setup.php and
article_image.php. The impact is XSS.
|
| CVE-2016-9857 |
An issue was discovered in phpMyAdmin. XSS is possible because of a
weakness in a regular expression used in some JavaScript processing.
All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to
4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
|
| CVE-2016-9856 |
An XSS issue was discovered in phpMyAdmin because of an improper fix
for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a
copy of a hash to avoid a race condition. All 4.6.x versions (prior to
4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior
to 4.0.10.18) are affected.
|
| CVE-2016-9834 |
An XSS vulnerability allows remote attackers to execute arbitrary
client side script on vulnerable installations of Sophos Cyberoam
firewall devices with firmware through 10.6.4. User interaction is
required to exploit this vulnerability in that the target must visit a
malicious page or open a malicious file. The specific flaw exists
within the handling of a request to the "LiveConnectionDetail.jsp"
application. GET parameters "applicationname" and "username" are
improperly sanitized allowing an attacker to inject arbitrary
JavaScript into the page. This can be abused by an attacker to perform
a cross-site scripting attack on the user. A vulnerable URI is
/corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.
|
| CVE-2016-9757 |
In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user
interface, any authenticated user who has the capability to create
tags can inject cross-site scripting (XSS) elements in the tag name
field. Once this tag is viewed in the Tag Detail page of the Rapid7
Nexpose 6.4.12 UI by another authenticated user, the script is run in
that user's browser context.
|
| CVE-2016-9751 |
Cross-site scripting (XSS) vulnerability in the search results front
end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web
script or HTML via the search parameter.
|
| CVE-2016-9681 |
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity
before 2.0.5 allow remote authenticated users to inject arbitrary web
script or HTML via a category or directory name.
|
| CVE-2016-9472 |
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The
Revive Adserver web installer scripts were vulnerable to a reflected
XSS attack via the dbHost, dbUser, and possibly other parameters. It
has to be noted that the window for such attack vectors to be possible
is extremely narrow and it is very unlikely that such an attack could
be actually effective.
|
| CVE-2016-9466 |
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and
9.1.2 suffer from Reflected XSS in the Gallery application. The
gallery app was not properly sanitizing exception messages from the
Nextcloud/ownCloud server. Due to an endpoint where an attacker could
influence the error message, this led to a reflected
Cross-Site-Scripting vulnerability.
|
| CVE-2016-9465 |
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2
suffer from Stored XSS in CardDAV image export. The CardDAV image
export functionality as implemented in Nextcloud/ownCloud allows the
download of images stored within a vCard. Due to not performing any
kind of verification on the image content this is prone to a stored
Cross-Site Scripting attack.
|
| CVE-2016-9459 |
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are
vulnerable to a log pollution vulnerability potentially leading to a
local XSS. The download log functionality in the admin screen is
delivering the log in JSON format to the end-user. The file was
delivered with an attachment disposition forcing the browser to
download the document. However, Firefox running on Microsoft Windows
would offer the user to open the data in the browser as an HTML
document. Thus any injected data in the log would be executed.
|
| CVE-2016-9457 |
Revive Adserver before 3.2.3 suffers from Reflected XSS.
`www/admin/stats.php` is vulnerable to reflected XSS attacks via
multiple parameters that are not properly sanitised or escaped when
displayed, such as setPerPage, pageId, bannerid, period_start,
period_end, and possibly others.
|
| CVE-2016-9454 |
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for
persistent XSS attacks via the Revive Adserver user interface exists,
requiring a trusted (non-admin) account. The banner image URL for
external banners wasn't properly escaped when displayed in most of the
banner related pages.
|
| CVE-2016-9421 |
Cross-site scripting (XSS) vulnerability in the Users module in the
Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and
MyBB Merge System before 1.8.8 might allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-9419 |
Cross-site scripting (XSS) vulnerability in the Admin control panel in
MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before
1.8.8 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2016-9409 |
Cross-site scripting (XSS) vulnerability in the Admin control panel in
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before
1.8.7 might allow remote attackers to inject arbitrary web script or
HTML via vectors involving pruning logs.
|
| CVE-2016-9408 |
Cross-site scripting (XSS) vulnerability in the Mod control panel in
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before
1.8.7 might allow remote attackers to inject arbitrary web script or
HTML via vectors involving editing users.
|
| CVE-2016-9407 |
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard)
before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote
attackers to inject arbitrary web script or HTML via vectors involving
Mod control panel logs.
|
| CVE-2016-9406 |
Cross-site scripting (XSS) vulnerability in the User control panel in
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before
1.8.7 might allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-9405 |
Cross-site scripting (XSS) vulnerability in member validation in MyBB
(aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7
might allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2016-9404 |
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard)
before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote
attackers to inject arbitrary web script or HTML via vectors related
to login.
|
| CVE-2016-9316 |
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in
com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro
InterScan Web Security Virtual Appliance (IWSVA) version
6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users
with least privileges to inject arbitrary HTML/JavaScript code into web
pages. This was resolved in Version 6.5 CP 1737.
|
| CVE-2016-9261 |
Cross-site scripting (XSS) vulnerability in Tenable Log Correlation
Engine (aka LCE) before 4.8.1 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-9260 |
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9
allows remote authenticated users to inject arbitrary web script or
HTML via vectors related to handling of .nessus files.
|
| CVE-2016-9259 |
Cross-site scripting (XSS) vulnerability in Tenable Nessus before
6.9.1 allows remote authenticated users to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2016-9257 |
In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be
able to inject JavaScript into a request that will then be rendered
and executed in the context of the Administrative user when the
Administrative user is viewing the Access System Logs, allowing the
non-authenticated user to carry out a Cross Site Scripting (XSS)
attack against the Administrative user.
|
| CVE-2016-9222 |
A vulnerability in the web-based management interface of Cisco NetFlow
Generation Appliance could allow an unauthenticated, remote attacker to
conduct a cross-site scripting (XSS) attack against a user of the
web-based management interface of an affected device. More Information:
CSCvb15229. Known Affected Releases: 1.0(2).
|
| CVE-2016-9214 |
Cisco Identity Services Engine (ISE) contains a vulnerability that
could allow an unauthenticated, remote attacker to conduct a cross-site
scripting (XSS) attack against the user of the web interface of the
affected system. More Information: CSCvb86332 CSCvb86760. Known
Affected Releases: 2.0(101.130).
|
| CVE-2016-9206 |
A vulnerability in the ccmadmin page of Cisco Unified Communications
Manager (CUCM) could allow an unauthenticated, remote attacker to
conduct reflected cross-site scripting (XSS) attacks. More Information:
CSCvb64641. Known Affected Releases: 11.5(1.10000.6) 11.5(1.11007.2).
Known Fixed Releases: 11.5(1.12900.7) 11.5(1.12900.8) 12.0(0.98000.155)
12.0(0.98000.178) 12.0(0.98000.366) 12.0(0.98000.468) 12.0(0.98000.536)
12.0(0.98500.6).
|
| CVE-2016-9202 |
A vulnerability in the web-based management interface of Cisco Email
Security Appliance (ESA) Switches could allow an unauthenticated,
remote attacker to conduct a persistent cross-site scripting (XSS)
attack against a user of the affected interface on an affected device.
More Information: CSCvb37346. Known Affected Releases: 9.1.1-036
9.7.1-066.
|
| CVE-2016-9200 |
A vulnerability in the web framework code of Cisco Prime Collaboration
Assurance could allow an unauthenticated, remote attacker to conduct a
cross-site scripting (XSS) attack against the user of the web
interface. More Information: CSCut43268. Known Affected Releases:
10.5(1) 10.6.
|
| CVE-2016-9188 |
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before
3.1.2 allow remote attackers to inject arbitrary web script or HTML via
the s_additionalhtmlhead, s_additionalhtmltopofbody, and
s_additionalhtmlfooter parameters.
|
| CVE-2016-9169 |
A reflected XSS vulnerability exists in the web console of the Document
Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot
Patch 2 that may enable a remote attacker to execute JavaScript in the
context of a valid user's browser session by getting the user to click
on a specially crafted link. This could lead to session compromise or
other browser-based attacks.
|
| CVE-2016-9152 |
Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in
SPIP 3.1.3 allows remote attackers to inject arbitrary web script or
HTML via the rac parameter.
|
| CVE-2016-9148 |
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager
(formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to
inject arbitrary web script or HTML via the QBE.EQ.REF_NUM parameter.
|
| CVE-2016-9139 |
Cross-site scripting (XSS) vulnerability in Open Ticket Request System
(OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before
5.0.14 allows remote attackers to inject arbitrary web script or HTML
via a crafted attachment.
|
| CVE-2016-9130 |
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for
persistent XSS attacks via the Revive Adserver user interface exists,
requiring a trusted (non-admin) account. The website name wasn't
properly escaped when displayed in the campaign-zone.php script.
|
| CVE-2016-9128 |
Revive Adserver before 3.2.3 suffers from reflected XSS. The
affiliate-preview.php script in www/admin is vulnerable to a reflected
XSS attack. This vulnerability could be used by an attacker to steal
the session ID of an authenticated user, by tricking them into visiting
a specifically crafted URL.
|
| CVE-2016-9126 |
Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are
not properly escaped when displayed in the audit trail widget of the
dashboard upon login, allowing persistent XSS attacks. An authenticated
user with enough privileges to create other users could exploit the
vulnerability to access the administrator account.
|
| CVE-2016-9119 |
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI
editor in MoinMoin before 1.9.8 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-8855 |
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List
Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1
rev. 160519 (8.1 Update-3) allows remote attacks via the Name or
Description parameter. This is fixed in 8.2 Update-2.
|
| CVE-2016-8789 |
Huawei eSpace Integrated Access Device (IAD) with software
V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07
allows an attacker to trick a user into clicking a URL containing
malicious scripts to obtain user information or hijack the session,
aka XSS.
|
| CVE-2016-8583 |
Multiple GET parameters in the vulnerability scan scheduler of
AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.
|
| CVE-2016-8581 |
A persistent XSS vulnerability exists in the User-Agent header of the
login process of AlienVault OSSIM and USM before 5.3.2 that allows an
attacker to steal session IDs of logged in users when the current
sessions are viewed by an administrator.
|
| CVE-2016-8506 |
XSS in Yandex Browser Translator in Yandex browser for desktop for
versions from 15.12 to 16.2 could be used by remote attacker for
evaluation arbitrary javascript code.
|
| CVE-2016-8505 |
XSS in Yandex Browser BookReader in Yandex browser for desktop for
versions before 16.6. could be used by remote attacker for evaluation
arbitrary javascript code.
|
| CVE-2016-8019 |
Cross-site scripting (XSS) vulnerability in attributes in Intel
Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows
unauthenticated remote attackers to inject arbitrary web script or
HTML via a crafted user input.
|
| CVE-2016-7981 |
Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP
3.1.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via the var_url parameter in a valider_xml action.
|
| CVE-2016-7762 |
An issue was discovered in certain Apple products. iOS before 10.2 is
affected. The issue involves the "WebKit" component, which allows XSS
attacks against Safari.
|
| CVE-2016-7571 |
Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10
allows remote attackers to inject arbitrary web script or HTML via
vectors involving an HTTP exception.
|
| CVE-2016-7509 |
Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote
authenticated attackers to inject arbitrary web script or HTML by
attaching a crafted HTML file to a ticket.
|
| CVE-2016-7469 |
A stored cross-site scripting (XSS) vulnerability in the Configuration
utility device name change page in BIG-IP LTM, AAM, AFM, Analytics,
APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM,
WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11.4.0 -
11.6.1, and 11.2.1 allows an authenticated user to inject arbitrary
web script or HTML. Exploitation requires Resource Administrator or
Administrator privileges, and it could cause the Configuration utility
client to become unstable.
|
| CVE-2016-7463 |
Cross-site scripting (XSS) vulnerability in the Host Client in VMware
vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted VM.
|
| CVE-2016-7419 |
Cross-site scripting (XSS) vulnerability in share.js in the gallery
application in ownCloud Server before 9.0.4 and Nextcloud Server
before 9.0.52 allows remote authenticated users to inject arbitrary
web script or HTML via a crafted directory name.
|
| CVE-2016-7282 |
Cross-site scripting (XSS) vulnerability in Microsoft Internet
Explorer 9 through 11 and Microsoft Edge allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka
"Microsoft Browser Information Disclosure Vulnerability."
|
| CVE-2016-7280 |
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, aka "Microsoft Edge Information Disclosure
Vulnerability," a different vulnerability than CVE-2016-7206.
|
| CVE-2016-7251 |
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft
SQL Server 2016 allows remote attackers to inject arbitrary web script
or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
|
| CVE-2016-7239 |
The RegEx class in the XSS filter in Microsoft Internet Explorer 9
through 11 and Microsoft Edge allows remote attackers to conduct
cross-site scripting (XSS) attacks and obtain sensitive information
via unspecified vectors, aka "Microsoft Browser Information Disclosure
Vulnerability."
|
| CVE-2016-7206 |
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, aka "Microsoft Edge Information Disclosure
Vulnerability," a different vulnerability than CVE-2016-7280.
|
| CVE-2016-7168 |
Cross-site scripting (XSS) vulnerability in the media_handle_upload
function in wp-admin/includes/media.php in WordPress before 4.6.1
might allow remote attackers to inject arbitrary web script or HTML by
tricking an administrator into uploading an image file that has a
crafted filename.
|
| CVE-2016-7150 |
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and
earlier allows remote authenticated users to inject arbitrary web
script or HTML via the site name.
|
| CVE-2016-7149 |
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and
earlier allows remote attackers to inject arbitrary web script or HTML
via vectors related to the autolink function.
|
| CVE-2016-7148 |
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript
injection" attacks by using the "page creation" approach, related to a
"Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via
page name) component.
|
| CVE-2016-7147 |
Cross-site scripting (XSS) vulnerability in the manage_findResult
component in the search feature in Zope ZMI in Plone before 4.3.12 and
5.x before 5.0.7 allows remote attackers to inject arbitrary web script
or HTML via vectors involving double quotes, as demonstrated by the
obj_ids:tokens parameter. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2016-7140.
|
| CVE-2016-7146 |
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript
injection" attacks by using the "page creation or crafted URL"
approach, related to a "Cross Site Scripting (XSS)" issue affecting the
action=fckdialog&dialog=attachment (via page name) component.
|
| CVE-2016-7140 |
Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in
Zope2 in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x
through 3.3.6 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-7139 |
Cross-site scripting (XSS) vulnerability in an unspecified page
template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x
through 3.3.6 allows remote attackers to inject arbitrary web script
or HTML via unknown vectors.
|
| CVE-2016-7138 |
Cross-site scripting (XSS) vulnerability in the URL checking
infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and
3.3.x through 3.3.6 allows remote attackers to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2016-7136 |
z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows
remote attackers to conduct cross-site scripting (XSS) attacks via a
crafted GET request.
|
| CVE-2016-7119 |
Cross-site scripting (XSS) vulnerability in the user-profile biography
section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted onclick
attribute in an IMG element.
|
| CVE-2016-7111 |
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content
Security Policy when using the Gravatar plugin, which allows remote
attackers to conduct cross-site scripting (XSS) attacks via
unspecified vectors.
|
| CVE-2016-7103 |
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0
might allow remote attackers to inject arbitrary web script or HTML
via the closeText parameter of the dialog function.
|
| CVE-2016-7033 |
Multiple cross-site scripting (XSS) vulnerabilities in the admin pages
in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-6913 |
Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before
5.3 and USM before 5.3 allows remote attackers to inject arbitrary web
script or HTML via the back parameter to ossim/conf/reload.php.
|
| CVE-2016-6858 |
Cross-site scripting (XSS) vulnerability in the Create Employee
feature in Hybris Management Console (HMC) in SAP Hybris before
5.0.4.11, 5.1.0.x before 5.1.0.11, 5.1.1.x before 5.1.1.12, 5.2.0.x
and 5.3.0.x before 5.3.0.10, 5.4.x before 5.4.0.9, 5.5.0.x before
5.5.0.9, 5.5.1.x before 5.5.1.10, 5.6.x before 5.6.0.8, and 5.7.x
before 5.7.0.9 allows remote authenticated users to inject arbitrary
web script or HTML via the Name field.
|
| CVE-2016-6857 |
Cross-site scripting (XSS) vulnerability in the Create Catalogue
feature in Hybris Management Console (HMC) in SAP Hybris before
5.2.0.13, 5.3.x before 5.3.0.11, 5.4.x before 5.4.0.11, 5.5.0.x before
5.5.0.10, 5.5.1.x before 5.5.1.11, 5.6.x before 5.6.0.11, and 5.7.x
before 5.7.0.15 allows remote authenticated users to inject arbitrary
web script or HTML via the ID field.
|
| CVE-2016-6856 |
Cross-site scripting (XSS) vulnerability in the Inbox Search feature
in Hybris Management Console (HMC) in SAP Hybris before 6.0 allows
remote attackers to inject arbitrary web script or HTML via the
itemsperpage parameter.
|
| CVE-2016-6846 |
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite
backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before
7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before
7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before
7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before 7.8.2-rev5;
and Documentconverter-API before 7.8.2-rev5 allows remote attackers to
inject arbitrary web script or HTML.
|
| CVE-2016-6840 |
Cross-site scripting (XSS) vulnerability in the management interface
in Huawei OceanStor ISM before V200R001C04SPC200 allows remote
attackers to inject arbitrary web script or HTML via the loginName
parameter to cgi-bin/doLogin_CgiEntry and possibly other unspecified
vectors.
|
| CVE-2016-6837 |
Cross-site scripting (XSS) vulnerability in MantisBT Filter API in
MantisBT versions before 1.2.19, and versions 2.0.0-beta1, 1.3.0-beta1
allows remote attackers to inject arbitrary web script or HTML via the
'view_type' parameter.
|
| CVE-2016-6816 |
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6,
8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed
the HTTP request line permitted invalid characters. This could be
exploited, in conjunction with a proxy that also permitted the invalid
characters but with a different interpretation, to inject data into
the HTTP response. By manipulating the HTTP response the attacker
could poison a web-cache, perform an XSS attack and/or obtain
sensitive information from requests other then their own.
|
| CVE-2016-6812 |
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x
prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page
which lists the names and absolute URL addresses of the available
service endpoints. The module calculates the base URL using the
current HttpServletRequest. The calculated base URL is used by
FormattedServiceListWriter to build the service endpoint absolute
URLs. If the unexpected matrix parameters have been injected into the
request URL then these matrix parameters will find their way back to
the client in the services list page which represents an XSS risk to
the client.
|
| CVE-2016-6800 |
The default configuration of the OFBiz framework offers a blog
functionality. Different users are able to operate blogs which are
related to specific parties. In the form field for the creation of new
blog articles the user input of the summary field as well as the
article field is not properly sanitized. It is possible to inject
arbitrary JavaScript code in these form fields. This code gets
executed from the browser of every user who is visiting this article.
Mitigation: Upgrade to Apache OFBiz 16.11.01.
|
| CVE-2016-6798 |
In the XSS Protection API module before 1.0.12 in Apache Sling, the
method XSS.getValidXML() uses an insecure SAX parser to validate the
input string, which allows for XXE attacks in all scripts which use
this method to validate user input, potentially allowing an attacker
to read sensitive data on the filesystem, perform
same-site-request-forgery (SSRF), port-scanning behind the firewall or
DoS the application.
|
| CVE-2016-6647 |
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 4.0.1
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-6643 |
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-6641 |
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-6634 |
Cross-site scripting (XSS) vulnerability in the network settings page
in WordPress before 4.5 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2016-6615 |
XSS issues were discovered in phpMyAdmin. This affects navigation pane
and database/table hiding feature (a specially-crafted database name
can be used to trigger an XSS attack); the "Tracking" feature (a
specially-crafted query can be used to trigger an XSS attack); and GIS
visualization feature. All 4.6.x versions (prior to 4.6.4) and 4.4.x
versions (prior to 4.4.15.8) are affected.
|
| CVE-2016-6608 |
XSS issues were discovered in phpMyAdmin. This affects the database
privilege check and the "Remove partitioning" functionality. Specially
crafted database names can trigger the XSS attack. All 4.6.x versions
(prior to 4.6.4) are affected.
|
| CVE-2016-6607 |
XSS issues were discovered in phpMyAdmin. This affects Zoom search
(specially crafted column content can be used to trigger an XSS
attack); GIS editor (certain fields in the graphical GIS editor are
not properly escaped and can be used to trigger an XSS attack);
Relation view; the following Transformations: Formatted, Imagelink,
JPEG: Upload, RegexValidation, JPEG inline, PNG inline, and
transformation wrapper; XML export; MediaWiki export; Designer; When
the MySQL server is running with a specially-crafted log_bin
directive; Database tab; Replication feature; and Database search. All
4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8),
and 4.0.x versions (prior to 4.0.10.17) are affected.
|
| CVE-2016-6523 |
Multiple cross-site scripting (XSS) vulnerabilities in the media
manager in Dotclear before 2.10 allow remote attackers to inject
arbitrary web script or HTML via the (1) q or (2) link_type parameter
to admin/media.php.
|
| CVE-2016-6519 |
Cross-site scripting (XSS) vulnerability in the "Shares" overview in
Openstack Manila before 2.5.1 allows remote authenticated users to
inject arbitrary web script or HTML via the Metadata field in the
"Create Share" form.
|
| CVE-2016-6472 |
A vulnerability in several parameters of the ccmivr page of Cisco
Unified Communication Manager (CallManager) could allow an
unauthenticated, remote attacker to launch a cross-site scripting (XSS)
attack against a user of the web interface on the affected system. More
Information: CSCvb37121. Known Affected Releases: 11.5(1.2). Known
Fixed Releases: 11.5(1.11950.96) 11.5(1.12900.2) 12.0(0.98000.133)
12.0(0.98000.313) 12.0(0.98000.404).
|
| CVE-2016-6451 |
Multiple vulnerabilities in the web framework code of the Cisco Prime
Collaboration Provisioning could allow an unauthenticated, remote
attacker to conduct a cross-site scripting (XSS) attack against the
user of the web interface of the affected system. More Information:
CSCut43061 CSCut43066 CSCut43736 CSCut43738 CSCut43741 CSCut43745
CSCut43748 CSCut43751 CSCut43756 CSCut43759 CSCut43764 CSCut43766.
Known Affected Releases: 10.6.
|
| CVE-2016-6436 |
Cross-site scripting (XSS) vulnerability in HostScan Engine 3.0.08062
through 3.1.14018 in the Cisco Host Scan package, as used in ASA Web
VPN, allows remote attackers to inject arbitrary web script or HTML
via a crafted URL, aka Bug ID CSCuz14682.
|
| CVE-2016-6429 |
A vulnerability in the web framework code of the Cisco IP
Interoperability and Collaboration System (IPICS) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting
(XSS) attack. More Information: CSCva47092. Known Affected Releases:
4.10(1).
|
| CVE-2016-6425 |
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence
Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center
Express 10.0(1) through 11.0(1), allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020
and CSCuy81652.
|
| CVE-2016-6418 |
Cross-site scripting (XSS) vulnerability in Cisco Videoscape
Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka Bug ID CSCva14552.
|
| CVE-2016-6404 |
Cross-site scripting (XSS) vulnerability in the web framework in Cisco
IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers
to inject arbitrary web script or HTML via a crafted URL, aka Bug ID
CSCuy19854.
|
| CVE-2016-6395 |
Cross-site scripting (XSS) vulnerability in the web-based management
interface in Cisco Firepower Management Center before 6.1 and
FireSIGHT System Software before 6.1 allows remote authenticated users
to inject arbitrary web script or HTML via a crafted URL, aka Bug ID
CSCuz58658.
|
| CVE-2016-6365 |
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management
Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote
attackers to inject arbitrary web script or HTML via unspecified
parameters, aka Bug IDs CSCur25508 and CSCur25518.
|
| CVE-2016-6359 |
Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway
Installation Software 4.1(4.0) on Smart Call Home Transport Gateway
devices allows remote attackers to inject arbitrary web script or HTML
via a crafted value, aka Bug IDs CSCva40650 and CSCva40817.
|
| CVE-2016-6347 |
Cross-site scripting (XSS) vulnerability in the default exception
handler in RESTEasy allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-6334 |
Cross-site scripting (XSS) vulnerability in the
Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15,
1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers
to inject arbitrary web script or HTML via vectors involving
replacement of percent encoding in unclosed internal links.
|
| CVE-2016-6333 |
Cross-site scripting (XSS) vulnerability in the CSS user subpage
preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and
1.27.x before 1.27.1 allows remote attackers to inject arbitrary web
script or HTML via the edit box in Special:MyPage/common.css.
|
| CVE-2016-6320 |
Cross-site scripting (XSS) vulnerability in
app/assets/javascripts/host_edit_interfaces.js in Foreman before
1.12.2 allows remote authenticated users to inject arbitrary web
script or HTML via the network interface device identifier in the host
interface form.
|
| CVE-2016-6319 |
Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb
in Foreman before 1.12.2, as used by Remote Execution and possibly
other plugins, allows remote attackers to inject arbitrary web script
or HTML via the label parameter.
|
| CVE-2016-6316 |
Cross-site scripting (XSS) vulnerability in Action View in Ruby on
Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1
might allow remote attackers to inject arbitrary web script or HTML
via text declared as "HTML safe" and used as attribute values in tag
handlers.
|
| CVE-2016-6285 |
Cross-site scripting (XSS) vulnerability in
includes/decorators/global-translations.jsp in Atlassian JIRA before
7.2.2 allows remote attackers to inject arbitrary web script or HTML
via the HTTP Host header.
|
| CVE-2016-6283 |
Cross-site scripting (XSS) vulnerability in Atlassian Confluence
before 5.10.6 allows remote attackers to inject arbitrary web script
or HTML via the newFileName parameter to
pages/doeditattachment.action.
|
| CVE-2016-6209 |
Cross-site scripting (XSS) vulnerability in Nagios.
|
| CVE-2016-6204 |
Cross-site scripting (XSS) vulnerability in the integrated web server
in Siemens SINEMA Remote Connect Server before 1.2 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-6201 |
Cross-site scripting (XSS) vulnerability in Ektron Content Management
System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote
attackers to inject arbitrary web script or HTML via the ContType
parameter in a ViewContentByCategory action to WorkArea/content.aspx.
|
| CVE-2016-6191 |
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw
Source page in the Web Calendar in SOGo before 3.1.3 allow remote
attackers to inject arbitrary web script or HTML via the (1)
Description, (2) Location, (3) URL, or (4) Title field.
|
| CVE-2016-6190 |
SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to
the UID and DTSTAMP attributes, which allows remote authenticated
users to obtain sensitive information about appointments with the
"View the Date & Time" restriction, as demonstrated by correlating
UIDs and DTSTAMPs between all users.
|
| CVE-2016-6189 |
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows
remote authenticated users to obtain sensitive information by reading
the fields in the (1) ics or (2) XML calendar feeds.
|
| CVE-2016-6188 |
Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of
service (memory consumption) via a large number of attempts to upload
a large attachment, related to temporary files.
|
| CVE-2016-6186 |
Cross-site scripting (XSS) vulnerability in the
dismissChangeRelatedObjectPopup function in
contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django
before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows
remote attackers to inject arbitrary web script or HTML via vectors
involving unsafe usage of Element.innerHTML.
|
| CVE-2016-6133 |
Cross-site scripting (XSS) vulnerability in Ektron Content Management
System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to
inject arbitrary web script or HTML via the rptStatus parameter in a
Report action to WorkArea/SelectUserGroup.aspx.
|
| CVE-2016-6127 |
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x
before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the
AlwaysDownloadAttachments config setting is not in use, allows remote
attackers to inject arbitrary web script or HTML via a file upload
with an unspecified content type.
|
| CVE-2016-5981 |
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace XT
through 1.1.5.2-WPXT-LA011 and FileNet Workplace (Application Engine)
through 4.0.2.14-P8AE-IF001, when RegExpSecurityFilter and
ScriptSecurityFilter are misconfigured, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-5978 |
Cross-site scripting (XSS) vulnerability in the Web UI in the web
portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8
before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A
before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A
before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to
inject arbitrary web script or HTML via an embedded string, a
different vulnerability than CVE-2016-5975.
|
| CVE-2016-5975 |
Cross-site scripting (XSS) vulnerability in the Web UI in the web
portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8
before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A
before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A
before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to
inject arbitrary web script or HTML via an embedded string, a
different vulnerability than CVE-2016-5978.
|
| CVE-2016-5974 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security
Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2
FP8 allows remote authenticated users to inject arbitrary web script
or HTML via an embedded string.
|
| CVE-2016-5955 |
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next
Generation 6.0.2 before iFix004 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-5944 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum
Control (formerly Tivoli Storage Productivity Center) 5.2.x before
5.2.11 allows remote authenticated users to inject arbitrary web
script or HTML via an embedded string.
|
| CVE-2016-5920 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before
fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-5905 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-5901 |
Cross-site scripting (XSS) vulnerability in a test page in IBM
Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before
cumulative fix 2016.09 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-5892 |
Cross-site scripting (XSS) vulnerability in IBM 10x, as used in
Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B
Advanced Communications before 1.0.0.5_2, allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-5850 |
Cross-site scripting (XSS) vulnerability in the volume backup service
module in Huawei Public Cloud Solution before 1.0.5 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-5834 |
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link
function in wp-includes/post-template.php in WordPress before 4.5.3
allows remote attackers to inject arbitrary web script or HTML via a
crafted attachment name, a different vulnerability than CVE-2016-5833.
|
| CVE-2016-5833 |
Cross-site scripting (XSS) vulnerability in the column_title function
in wp-admin/includes/class-wp-media-list-table.php in WordPress before
4.5.3 allows remote attackers to inject arbitrary web script or HTML
via a crafted attachment name, a different vulnerability than
CVE-2016-5834.
|
| CVE-2016-5761 |
Cross-site scripting (XSS) vulnerability in Novell GroupWise before
2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject
arbitrary web script or HTML via a crafted email.
|
| CVE-2016-5760 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrator console in Novell GroupWise before 2014 R2 Service Pack
1 Hot Patch 1 allow remote attackers to inject arbitrary web script or
HTML via the (1) token parameter to gwadmin-console/install/login.jsp
or (2) PATH_INFO to gwadmin-console/index.jsp.
|
| CVE-2016-5751 |
An unfiltered finalizer target URL in the SAML processing feature in
Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2
before 4.2.2 could be used to trigger XSS and leak authentication
credentials.
|
| CVE-2016-5737 |
The Gerrit configuration in the Openstack Puppet module for Gerrit
(aka puppet-gerrit) improperly marks text/html as a safe mimetype,
which might allow remote attackers to conduct cross-site scripting
(XSS) attacks via a crafted review.
|
| CVE-2016-5733 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3
allow remote attackers to inject arbitrary web script or HTML via
vectors involving (1) a crafted table name that is mishandled during
privilege checking in table_row.phtml, (2) a crafted mysqld log_bin
directive that is mishandled in log_selector.phtml, (3) the
Transformation implementation, (4) AJAX error handling in js/ajax.js,
(5) the Designer implementation, (6) the charts implementation in
js/tbl_chart.js, or (7) the zoom-search implementation in
rows_zoom.phtml.
|
| CVE-2016-5732 |
Multiple cross-site scripting (XSS) vulnerabilities in the
partition-range implementation in
templates/table/structure/display_partitions.phtml in the
table-structure page in phpMyAdmin 4.6.x before 4.6.3 allow remote
attackers to inject arbitrary web script or HTML via crafted table
parameters.
|
| CVE-2016-5731 |
Cross-site scripting (XSS) vulnerability in examples/openid.php in
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x
before 4.6.3 allows remote attackers to inject arbitrary web script or
HTML via vectors involving an OpenID error message.
|
| CVE-2016-5721 |
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra
Collaboration before 8.7.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2016-5705 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to
inject arbitrary web script or HTML via vectors involving (1)
server-privileges certificate data fields on the user privileges page,
(2) an "invalid JSON" error message in the error console, (3) a
database name in the central columns implementation, (4) a group name,
or (5) a search name in the bookmarks implementation.
|
| CVE-2016-5704 |
Cross-site scripting (XSS) vulnerability in the table-structure page
in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject
arbitrary web script or HTML via vectors involving a comment.
|
| CVE-2016-5682 |
Swagger-UI before 2.2.1 has XSS via the Default field in the
Definitions section.
|
| CVE-2016-5663 |
Multiple cross-site scripting (XSS) vulnerabilities in
oauth_callback.php on Accellion Kiteworks appliances before
kw2016.03.00 allow remote attackers to inject arbitrary web script or
HTML via the (1) code, (2) error, or (3) error_description parameter.
|
| CVE-2016-5660 |
Cross-site scripting (XSS) vulnerability in AttachmentsList.aspx in
Accela Civic Platform Citizen Access portal allows remote attackers to
inject arbitrary web script or HTML via the iframeid parameter.
|
| CVE-2016-5642 |
Opmantek NMIS before 8.5.12G has XSS via SNMP.
|
| CVE-2016-5398 |
Cross-site scripting (XSS) vulnerability in Business Process Editor in
Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users
to inject arbitrary web script or HTML by levering permission to
create business processes.
|
| CVE-2016-5395 |
Cross-site scripting (XSS) vulnerability in the create user
functionality in the policy admin tool in Apache Ranger before 0.6.1
allows remote authenticated administrators to inject arbitrary web
script or HTML via vectors related to policies.
|
| CVE-2016-5394 |
In the XSS Protection API module before 1.0.12 in Apache Sling, the
encoding done by the XSSAPI.encodeForJSString() method is not
restrictive enough and for some input patterns allows script tags to
pass through unencoded, leading to potential XSS vulnerabilities.
|
| CVE-2016-5364 |
Cross-site scripting (XSS) vulnerability in
manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
return parameter.
|
| CVE-2016-5305 |
Multiple cross-site scripting (XSS) vulnerabilities in management
scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6
MP5 allow remote authenticated users to inject arbitrary web script or
HTML via a "DOM link manipulation" attack.
|
| CVE-2016-5303 |
Cross-site scripting (XSS) vulnerability in the Horde Text Filter API
in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16
allows remote attackers to inject arbitrary web script or HTML via
crafted data:text/html content in a form (1) action or (2) xlink
attribute.
|
| CVE-2016-5265 |
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow
user-assisted remote attackers to bypass the Same Origin Policy, and
conduct Universal XSS (UXSS) attacks or read arbitrary files, by
arranging for the presence of a crafted HTML document and a crafted
shortcut file in the same local directory.
|
| CVE-2016-5262 |
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process
JavaScript event-handler attributes of a MARQUEE element within a
sandboxed IFRAME element that lacks the sandbox="allow-scripts"
attribute value, which makes it easier for remote attackers to conduct
cross-site scripting (XSS) attacks via a crafted web site.
|
| CVE-2016-5226 |
Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and
Mac executed javascript: URLs entered in the URL bar in the context of
the current tab, which allowed a socially engineered user to XSS
themselves by dragging and dropping a javascript: URL into the URL
bar.
|
| CVE-2016-5165 |
Cross-site scripting (XSS) vulnerability in the Developer Tools (aka
DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows
and OS X and before 53.0.2785.92 on Linux allows remote attackers to
inject arbitrary web script or HTML via the settings parameter in a
chrome-devtools-frontend.appspot.com URL's query string.
|
| CVE-2016-5164 |
Cross-site scripting (XSS) vulnerability in
WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used
in Google Chrome before 53.0.2785.89 on Windows and OS X and before
53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web
script or HTML into the Developer Tools (aka DevTools) subsystem via a
crafted web site, aka "Universal XSS (UXSS)."
|
| CVE-2016-5148 |
Cross-site scripting (XSS) vulnerability in Blink, as used in Google
Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92
on Linux, allows remote attackers to inject arbitrary web script or
HTML via vectors related to widget updates, aka "Universal XSS
(UXSS)."
|
| CVE-2016-5147 |
Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS
X and before 53.0.2785.92 on Linux, mishandles deferred page loads,
which allows remote attackers to inject arbitrary web script or HTML
via a crafted web site, aka "Universal XSS (UXSS)."
|
| CVE-2016-5124 |
An issue was discovered in Open-Xchange OX App Suite before
7.8.1-rev14. Adding images from external sources to HTML editors by
drag&drop can potentially lead to script code execution in the context
of the active user. To exploit this, a user needs to be tricked to use
an image from a specially crafted website and add it to HTML editor
areas of OX App Suite, for example E-Mail Compose or OX Text. This
specific attack circumvents typical XSS filters and detection
mechanisms since the code is not loaded from an external service but
injected locally. Malicious script code can be executed within a
user's context. This can lead to session hijacking or triggering
unwanted actions via the web interface (sending mail, deleting data
etc.). To exploit this vulnerability, a attacker needs to convince a
user to follow specific steps (social-engineering).
|
| CVE-2016-5099 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before
4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject
arbitrary web script or HTML via special characters that are
mishandled during double URL decoding.
|
| CVE-2016-5078 |
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
|
| CVE-2016-5077 |
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
|
| CVE-2016-5075 |
CloudView NMS before 2.10a has XSS via a TELNET login.
|
| CVE-2016-5073 |
CloudView NMS before 2.10a has XSS via SNMP.
|
| CVE-2016-5061 |
Multiple cross-site scripting (XSS) vulnerabilities in the web server
in Aternity before 9.0.1 allow remote attackers to inject arbitrary
web script or HTML via the (1) HTTPAgent, (2) MacAgent, (3)
getExternalURL, or (4) retrieveTrustedUrl page.
|
| CVE-2016-5060 |
Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before
3.4 allow remote attackers to inject arbitrary web script or HTML via
the (1) description, (2) email, or (3) username parameter to
user/save.
|
| CVE-2016-5055 |
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the
username field and Wireless Client Mode configuration page.
|
| CVE-2016-5005 |
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and
earlier allows remote authenticated administrators to inject arbitrary
web script or HTML via the connector.sourceRepoId parameter to
admin/addProxyConnector_commit.action.
|
| CVE-2016-4988 |
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer
plugin before 1.16.0 in Jenkins allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter.
|
| CVE-2016-4969 |
Cross-site scripting (XSS) vulnerability in Fortinet FortiWan
(formerly AscernLink) before 4.2.5 allows remote attackers to inject
arbitrary web script or HTML via the IP parameter to
script/statistics/getconn.php.
|
| CVE-2016-4948 |
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera
Manager 5.5 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) Template Name field when renaming a
template; (2) KDC Server host, (3) Kerberos Security Realm, (4)
Kerberos Encryption Types, (5) Advanced Configuration Snippet (Safety
Valve) for [libdefaults] section of krb5.conf, (6) Advanced
Configuration Snippet (Safety Valve) for the Default Realm in
krb5.conf, (7) Advanced Configuration Snippet (Safety Valve) for
remaining krb5.conf, or (8) Active Directory Account Prefix fields in
the Kerberos wizard; or (9) classicWizard parameter to
cmf/cloudera-director/redirect.
|
| CVE-2016-4946 |
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE
3.9.0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) First name or (2) Last name field in the
HUE Users page.
|
| CVE-2016-4945 |
Cross-site scripting (XSS) vulnerability in
vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0
before Build 66.11 allows remote attackers to inject arbitrary web
script or HTML via the NSC_TMAC cookie.
|
| CVE-2016-4930 |
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2
allows remote attackers to steal sensitive information or perform
certain administrative actions.
|
| CVE-2016-4897 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in
Usermin before 1.690.
|
| CVE-2016-4888 |
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine
ServiceDesk Plus before 9.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-4875 |
Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1)
Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before
0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for
Geeklog allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2016-4851 |
Cross-site scripting (XSS) vulnerability in Let's PHP! simple chat
before 2016-08-15 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-4849 |
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog IVYWE
edition 2.1.1 allow remote attackers to inject arbitrary web script or
HTML by leveraging use of the COM_getCurrentURL function in (1)
public_html/layout/default/header.thtml, (2)
public_html/layout/bento/header.thtml, (3)
public_html/layout/fotos/header.thtml, or (4)
public_html/layout/default/article/article.thtml.
|
| CVE-2016-4848 |
Cross-site scripting (XSS) vulnerability in ClipBucket before 2.8.1
RC2 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-4847 |
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC
Web UI before 0.9 allows remote attackers to inject arbitrary web
script or HTML by leveraging an unanchored regex.
|
| CVE-2016-4833 |
Cross-site scripting (XSS) vulnerability in the Nofollow Links plugin
before 1.0.11 for WordPress allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-4827 |
Cross-site scripting (XSS) vulnerability in the Collne Welcart
e-Commerce plugin before 1.8.3 for WordPress allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors, a
different vulnerability than CVE-2016-4826.
|
| CVE-2016-4826 |
Cross-site scripting (XSS) vulnerability in the Collne Welcart
e-Commerce plugin before 1.8.3 for WordPress allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors, a
different vulnerability than CVE-2016-4827.
|
| CVE-2016-4812 |
Cross-site scripting (XSS) vulnerability in the Markdown on Save
Improved plugin before 2.5.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-4807 |
Web2py versions 2.14.5 and below was affected by Reflected XSS
vulnerability, which allows an attacker to perform an XSS attack on
logged in user (admin).
|
| CVE-2016-4790 |
Cross-site scripting (XSS) vulnerability in the administrative user
interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before
8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2016-4789 |
Cross-site scripting (XSS) vulnerability in the system configuration
section in the administrative user interface in Pulse Connect Secure
(PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4
before 7.4r13.4 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2016-4783 |
Cross-site scripting (XSS) vulnerability in Lenovo SHAREit before
3.5.98_ww on Android before 4.4 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, aka "Universal
XSS (UXSS)."
|
| CVE-2016-4651 |
Cross-site scripting (XSS) vulnerability in the WebKit JavaScript
bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows
remote attackers to inject arbitrary web script or HTML via a crafted
HTTP/0.9 response, related to a "cross-protocol cross-site scripting
(XPXSS)" vulnerability.
|
| CVE-2016-4618 |
Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS
before 10 and Safari before 10 allows remote attackers to inject
arbitrary web script or HTML via a crafted web site, aka "Universal
XSS (UXSS)."
|
| CVE-2016-4585 |
Cross-site scripting (XSS) vulnerability in the WebKit Page Loading
implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and
tvOS before 9.2.2 allows remote attackers to inject arbitrary web
script or HTML via an HTTP response specifying redirection that is
mishandled by Safari.
|
| CVE-2016-4575 |
Cross-site scripting (XSS) vulnerability in the email APP in Huawei
PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92
before AL10C92B211; ATH smartphones with software AL00C00 before
AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361,
and UL00C00 before UL00C00B361; CherryPlus smartphones with software
TL00C00 before TL00C00B553, UL00C00 before UL00C00B553, and TL00MC01
before TL00MC01B553; and RIO smartphones with software AL00C00 before
AL00C00B360 allows remote attackers to inject arbitrary web script or
HTML via an email message.
|
| CVE-2016-4567 |
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as
in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2,
allows remote attackers to inject arbitrary web script or HTML via an
obfuscated form of the jsinitfunction parameter, as demonstrated by
"jsinitfunctio%gn."
|
| CVE-2016-4566 |
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in
Plupload before 2.1.9, as used in WordPress before 4.5.2, allows
remote attackers to inject arbitrary web script or HTML via a
Same-Origin Method Execution (SOME) attack.
|
| CVE-2016-4561 |
Cross-site scripting (XSS) vulnerability in the cgierror function in
CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors involving
an error message.
|
| CVE-2016-4552 |
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before
1.2.0 allows remote attackers to inject arbitrary web script or HTML
via the href attribute in an area tag in an e-mail message.
|
| CVE-2016-4513 |
Cross-site scripting (XSS) vulnerability in the Schneider Electric
PowerLogic PM8ECC module before 2.651 for PowerMeter 800 devices
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-4508 |
Cross-site scripting (XSS) vulnerability in Rexroth Bosch
BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-4428 |
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard
(Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote
authenticated users to inject arbitrary web script or HTML by
injecting an AngularJS template in a dashboard form.
|
| CVE-2016-4393 |
HPE System Management Homepage before v7.6 allows "remote
authenticated" attackers to obtain sensitive information via
unspecified vectors, related to an "XSS" issue.
|
| CVE-2016-4380 |
Cross-site scripting (XSS) vulnerability in the AdminUI in HPE
Operations Manager 9.21.x before 9.21.130 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-4366 |
HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers
to obtain sensitive information, modify data, or cause a denial of
service via unspecified vectors.
|
| CVE-2016-4365 |
HPE Insight Control server deployment allows remote attackers to
obtain sensitive information via unspecified vectors.
|
| CVE-2016-4364 |
HPE Insight Control server deployment allows local users to gain
privileges via unspecified vectors.
|
| CVE-2016-4363 |
HPE Insight Control server deployment allows remote attackers to
modify data via unspecified vectors.
|
| CVE-2016-4362 |
HPE Insight Control server deployment allows remote authenticated
users to obtain sensitive information or modify data via unspecified
vectors.
|
| CVE-2016-4327 |
Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server
for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote
attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2016-4318 |
Atlassian JIRA Server before 7.1.9 has XSS in
project/ViewDefaultProjectRoleActors.jspa via a role name.
|
| CVE-2016-4317 |
Atlassian Confluence Server before 5.9.11 has XSS on the
viewmyprofile.action page.
|
| CVE-2016-4316 |
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon
4.4.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the
(2) webappType or (3) httpPort parameter to
webapp-list/webapp_info.jsp; the (4) dsName or (5) description
parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to
viewflows/handlers.jsp; or the (7) url parameter to
ndatasource/validateconnection-ajaxprocessor.jsp.
|
| CVE-2016-4170 |
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager
5.6.1, 6.0, 6.1, and 6.2 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2016-4168 |
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager
5.6.1, 6.0, and 6.1 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-4164 |
Cross-site scripting (XSS) vulnerability in Adobe Brackets before 1.7
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-4159 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before
Update 20, 11 before Update 9, and 2016 before Update 2 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2016-4069 |
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail
before 1.1.5 allows remote attackers to hijack the authentication of
users for requests that download attachments and cause a denial of
service (disk consumption) via unspecified vectors.
|
| CVE-2016-4068 |
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before
1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject
arbitrary web script or HTML via a crafted SVG, a different
vulnerability than CVE-2015-8864.
|
| CVE-2016-4058 |
Cross-site scripting (XSS) vulnerability in Huawei Policy Center
before V100R003C10SPC020 allows remote authenticated users to inject
arbitrary web script or HTML via vectors related to "special
characters on pages."
|
| CVE-2016-4056 |
Cross-site scripting (XSS) vulnerability in the Backend component in
TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary
web script or HTML via the module parameter when creating a bookmark.
|
| CVE-2016-4016 |
Cross-site scripting (XSS) vulnerability in SAP Manufacturing
Integration and Intelligence (aka MII, formerly xMII) 15 allows remote
attackers to inject arbitrary web script or HTML via the title
parameter to
webdynpro/resources/sap.com/xapps~xmii~ui~admin~navigation/NavigationApplication,
aka SAP Security Note 2201295.
|
| CVE-2016-4003 |
Cross-site scripting (XSS) vulnerability in the URLDecoder function in
JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using
a single byte page encoding, allows remote attackers to inject
arbitrary web script or HTML via multi-byte characters in a
url-encoded parameter.
|
| CVE-2016-3999 |
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra
Collaboration before 8.7.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors, aka bugs 104552 and
104703.
|
| CVE-2016-3978 |
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x
before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to
redirect users to arbitrary web sites and conduct phishing attacks or
cross-site scripting (XSS) attacks via the "redirect" parameter to
"login."
|
| CVE-2016-3975 |
Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1
through 7.5 allows remote attackers to inject arbitrary web script or
HTML via the navigationTarget parameter to
irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigation.testComponent.NavigationURLTester,
aka SAP Security Note 2238375.
|
| CVE-2016-3971 |
Cross-site scripting (XSS) vulnerability in lucene_search.jsp in
dotCMS before 3.5.1 allows remote attackers to inject arbitrary web
script or HTML via the query parameter to c/portal/layout.
|
| CVE-2016-3969 |
Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG)
7.6.x before 7.6.404, when File Filtering is enabled with the action
set to ESERVICES:REPLACE, allows remote attackers to inject arbitrary
web script or HTML via an attachment in a blocked email.
|
| CVE-2016-3968 |
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam
CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG
UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM
appliance with firmware 10.6.2 Build 378 allow remote attackers to
inject arbitrary web script or HTML via the (1) ipFamily parameter to
corporate/webpages/trafficdiscovery/LiveConnections.jsp; the (2)
ipFamily, (3) applicationname, or (4) username parameter to
corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp; or the
(5) X-Forwarded-For HTTP header.
|
| CVE-2016-3670 |
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile
Search functionality in Liferay before 7.0.0 CE RC1 allows remote
attackers to inject arbitrary web script or HTML via the FirstName
field.
|
| CVE-2016-3652 |
Multiple cross-site scripting (XSS) vulnerabilities in management
scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6
MP5 allow remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-3536 |
Unspecified vulnerability in the Oracle Marketing component in Oracle
E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to
affect confidentiality and integrity via vectors related to
Deliverables. NOTE: the previous information is from the July 2016
CPU. Oracle has not commented on third-party claims that this issue
involves multiple cross-site scripting (XSS) vulnerabilities, which
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-3535 |
Unspecified vulnerability in the Oracle CRM Technical Foundation
component in Oracle E-Business Suite 12.1.3 allows remote attackers to
affect confidentiality and integrity via vectors related to Remote
Launch. NOTE: the previous information is from the July 2016 CPU.
Oracle has not commented on third-party claims that this issue is a
cross-site scripting (XSS) vulnerability, which allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2016-3532 |
Unspecified vulnerability in the Oracle Advanced Inbound Telephony
component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows
remote attackers to affect confidentiality and integrity via vectors
related to SDK client integration. NOTE: the previous information is
from the July 2016 CPU. Oracle has not commented on third-party claims
that this issue involves multiple cross-site scripting (XSS)
vulnerabilities, which allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-3491 |
Unspecified vulnerability in the Oracle CRM Technical Foundation
component in Oracle E-Business Suite 12.1.3 allows remote attackers to
affect confidentiality and integrity via vectors related to Wireless
Framework. NOTE: the previous information is from the July 2016 CPU.
Oracle has not commented on third-party claims that this issue is a
cross-site scripting (XSS) vulnerability, which allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2016-3438 |
Unspecified vulnerability in the Oracle Configurator component in
Oracle Supply Chain Products Suite 12.0.6, 12.1, and 12.2 allows
remote attackers to affect confidentiality and integrity via vectors
related to JRAD Heartbeat. NOTE: the previous information is from the
April 2016 CPU. Oracle has not commented on third-party claims that
that this issue involves multiple cross-site scripting (XSS)
vulnerabilities, which allow remote attackers to inject arbitrary web
script or HTML via three unspecified parameters in an unknown JSP
file.
|
| CVE-2016-3412 |
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra
Collaboration before 8.7.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors, aka bugs 103997, 104413,
104414, 104777, and 104791.
|
| CVE-2016-3411 |
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration
before 8.7.0 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, aka bug 103609.
|
| CVE-2016-3410 |
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra
Collaboration before 8.7.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors, aka bugs 103956, 103995,
104475, 104838, and 104839.
|
| CVE-2016-3409 |
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration
before 8.7.0 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, aka bug 102637.
|
| CVE-2016-3408 |
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration
before 8.7.0 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, aka bug 101813.
|
| CVE-2016-3407 |
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra
Collaboration before 8.7.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors, aka bugs 104222, 104910,
105071, and 105175.
|
| CVE-2016-3379 |
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server
2016 Cumulative Update 1 and 2 allows remote attackers to inject
arbitrary web script or HTML via a meeting-invitation request, aka
"Microsoft Exchange Elevation of Privilege Vulnerability."
|
| CVE-2016-3273 |
The XSS Filter in Microsoft Internet Explorer 9 through 11 and
Microsoft Edge does not properly restrict JavaScript code, which
allows remote attackers to obtain sensitive information via a crafted
web site, aka "Microsoft Browser Information Disclosure
Vulnerability."
|
| CVE-2016-3212 |
The XSS Filter in Microsoft Internet Explorer 9 through 11 does not
properly identify JavaScript, which makes it easier for remote
attackers to conduct cross-site scripting (XSS) attacks via a crafted
web site, aka "Internet Explorer XSS Filter Vulnerability."
|
| CVE-2016-3196 |
Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x
before 5.0.12 and 5.2.x before 5.2.6 and FortiManager 5.x before
5.0.12 and 5.2.x before 5.2.6 allows remote authenticated users to
inject arbitrary web script or HTML via the filename of an image
uploaded in the report section.
|
| CVE-2016-3195 |
Cross-site scripting (XSS) vulnerability in the Web-UI in Fortinet
FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 and
FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.6 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2016-3194 |
Cross-site scripting (XSS) vulnerability in the address added page in
Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 and
FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.6 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2016-3193 |
Cross-site scripting (XSS) vulnerability in the appliance
web-application in Fortinet FortiManager 5.x before 5.0.12, 5.2.x
before 5.2.6, and 5.4.x before 5.4.1 and FortiAnalyzer 5.x before
5.0.13, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-3150 |
Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base
Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03,
CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with
firmware before 01.03.02 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2016-3144 |
Cross-site scripting (XSS) vulnerability in the Block Class module
7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users
with the "Administer block classes" permission to inject arbitrary web
script or HTML via a class name.
|
| CVE-2016-3126 |
Cross-site scripting (XSS) vulnerability in the Management Console in
BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-3113 |
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote
attackers to inject arbitrary web script or HTML.
|
| CVE-2016-3101 |
Cross-site scripting (XSS) vulnerability in the Extra Columns plugin
before 1.17 in Jenkins allows remote attackers to inject arbitrary web
script or HTML by leveraging failure to filter tool tips through the
configured markup formatter.
|
| CVE-2016-3097 |
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat
Satellite 5.7 allows remote attackers to inject arbitrary web script
or HTML via a group name, related to viewing snapshot data.
|
| CVE-2016-3089 |
Cross-site scripting (XSS) vulnerability in the SWF panel in Apache
OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary
web script or HTML via the swf parameter.
|
| CVE-2016-3080 |
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat
Satellite 5.7 allows remote attackers to inject arbitrary web script
or HTML via the (1) RHNMD User or (2) Filesystem parameters, related
to display of monitoring probes.
|
| CVE-2016-3079 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in
Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject
arbitrary web script or HTML via (1) the PATH_INFO to
systems/SystemEntitlements.do; (2) the label parameter to
admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot
tag or (4) system group in System Set Manager (SSM).
|
| CVE-2016-3057 |
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B
Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-3056 |
Cross-site scripting (XSS) vulnerability in Business Space in IBM
Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and
8.5 before 8.5.7.0 CF2016.09 allows remote authenticated users to
inject arbitrary web script or HTML via crafted content.
|
| CVE-2016-3054 |
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace
4.0.2 allows remote authenticated users to inject arbitrary web script
or HTML by uploading a file.
|
| CVE-2016-3042 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows
remote authenticated users to inject arbitrary web script or HTML via
vectors involving OpenID Connect clients.
|
| CVE-2016-3014 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative
Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2
iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0
before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and
5.0 before 5.0.2 iFix17, Rational DOORS Next Generation 4.0 before
4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Engineering
Lifecycle Manager 4.x before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17,
Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11 and 5.0
before 5.0.2 iFix17, and Rational Software Architect Design Manager
4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-3010 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5
before CR1 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2016-2995, CVE-2016-2997, and CVE-2016-3005.
|
| CVE-2016-3008 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 5.0 before CR4 and 5.5 before CR1 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2016-2954 and
CVE-2016-2956.
|
| CVE-2016-3006 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1
allows remote authenticated users to inject arbitrary web script or
HTML via an embedded string, a different vulnerability than
CVE-2016-3001 and CVE-2016-3003.
|
| CVE-2016-3005 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5
before CR1 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2016-2995, CVE-2016-2997, and CVE-2016-3010.
|
| CVE-2016-3003 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1
allows remote authenticated users to inject arbitrary web script or
HTML via an embedded string, a different vulnerability than
CVE-2016-3001 and CVE-2016-3006.
|
| CVE-2016-3001 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1
allows remote authenticated users to inject arbitrary web script or
HTML via an embedded string, a different vulnerability than
CVE-2016-3003 and CVE-2016-3006.
|
| CVE-2016-2997 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5
before CR1 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2016-2995, CVE-2016-3005, and CVE-2016-3010.
|
| CVE-2016-2995 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5
before CR1 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2016-2997, CVE-2016-3005, and CVE-2016-3010.
|
| CVE-2016-2994 |
Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x
before 6.2.1.2 allows remote authenticated users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2016-2991 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus
Protector for Mail Security 2.8.0.0 through 2.8.1.0 before
2.8.1.0-22115 allow remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-2986 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative
Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager
6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6,
Rational DOORS Next Generation 6.x before 6.0.1 iFix6, Rational
Engineering Lifecycle Manager 6.x before 6.0.1 iFix6, and Rational
Rhapsody Design Manager 6.x before 6.0.1 iFix6 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-2963 |
Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote
Control before 9.1.3 allows remote attackers to hijack the
authentication of arbitrary users for requests that insert XSS
sequences.
|
| CVE-2016-2956 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 5.0 before CR4 and 5.5 before CR1 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2016-2954 and
CVE-2016-3008.
|
| CVE-2016-2955 |
Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before
CR4 and 5.5 before CR1 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-2954 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
Connections 5.0 before CR4 and 5.5 before CR1 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2016-2956 and
CVE-2016-3008.
|
| CVE-2016-2934 |
Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control
before 9.1.3 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-2926 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative
Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19,
and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7
iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational
Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0
before 6.0.2 iFix3; Rational DOORS Next Generation 4.0 before 4.0.7
iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational
Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before
5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Rhapsody Design
Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0
before 6.0.2 iFix3; and Rational Software Architect Design Manager 4.0
before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2
iFix3 allows remote authenticated users to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2016-2925 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal
6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x
through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before
CF10 allows remote authenticated users to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2016-2912 |
Cross-site scripting (XSS) vulnerability in the Document Builder in
IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted URL.
|
| CVE-2016-2901 |
Cross-site request forgery (CSRF) vulnerability in the
PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through
CF10 and Web Content Manager allows remote attackers to hijack the
authentication of arbitrary users for requests that insert XSS
sequences.
|
| CVE-2016-2888 |
Cross-site scripting (XSS) vulnerability in the Report Builder and
Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS)
5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL, a different vulnerability than CVE-2016-0313 and
CVE-2016-0350.
|
| CVE-2016-2884 |
Cross-site request forgery (CSRF) vulnerability in IBM Forms
Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified
non-default configuration, allows remote authenticated users to hijack
the authentication of arbitrary users for requests that insert XSS
sequences.
|
| CVE-2016-2883 |
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application
Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before
3.5.0.2 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, a different vulnerability than
CVE-2016-0387.
|
| CVE-2016-2878 |
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM
QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote
attackers to hijack the authentication of arbitrary users for requests
that insert XSS sequences.
|
| CVE-2016-2869 |
Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM
QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote
authenticated users to inject arbitrary web script or HTML via crafted
fields in a URL.
|
| CVE-2016-2864 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative
Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11,
5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality
Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before
5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert
3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2
iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0
before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2
iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11,
5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody
Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and
6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager
4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2
iFix5 allows remote authenticated users to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2016-2863 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere
Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x
before 8.0.1.2 allows remote authenticated users to hijack the
authentication of arbitrary users for requests that insert XSS
sequences.
|
| CVE-2016-2862 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0
through 6.0.0.11, 7.0 before 7.0.0.9 cumulative iFix 3, and 8.0 before
8.0.0.5 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL.
|
| CVE-2016-2833 |
Mozilla Firefox before 47.0 ignores Content Security Policy (CSP)
directives for cross-domain Java applets, which makes it easier for
remote attackers to conduct cross-site scripting (XSS) attacks via a
crafted applet.
|
| CVE-2016-2817 |
The WebExtension sandbox feature in
browser/components/extensions/ext-tabs.js in Mozilla Firefox before
46.0 does not properly restrict principal inheritance during
chrome.tabs.create and chrome.tabs.update API calls, which allows
remote attackers to conduct Universal XSS (UXSS) attacks via a crafted
extension that accesses a (1) javascript: or (2) data: URL.
|
| CVE-2016-2816 |
Mozilla Firefox before 46.0 allows remote attackers to bypass the
Content Security Policy (CSP) protection mechanism via the
multipart/x-mixed-replace content type.
|
| CVE-2016-2803 |
Cross-site scripting (XSS) vulnerability in the dependency graphs in
Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote
attackers to inject arbitrary web script or HTML.
|
| CVE-2016-2789 |
Cross-site scripting (XSS) vulnerability in the Web User Interface in
Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3
before Rolling Patch 1 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-2784 |
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty
Cache is activated, allow remote attackers to conduct cache poisoning
attacks, modify links, and conduct cross-site scripting (XSS) attacks
via a crafted HTTP Host header in a request.
|
| CVE-2016-2561 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote
authenticated users to inject arbitrary web script or HTML via (1)
normalization.php or (2) js/normalization.js in the database
normalization page, (3)
templates/database/structure/sortable_header.phtml in the database
structure page, or (4) the pos parameter to db_central_columns.php in
the central columns page.
|
| CVE-2016-2560 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before
4.5.5.1 allow remote attackers to inject arbitrary web script or HTML
via (1) a crafted Host HTTP header, related to
libraries/Config.class.php; (2) crafted JSON data, related to
file_echo.php; (3) a crafted SQL query, related to js/functions.js;
(4) the initial parameter to libraries/server_privileges.lib.php in
the user accounts page; or (5) the it parameter to
libraries/controllers/TableSearchController.class.php in the zoom
search page.
|
| CVE-2016-2559 |
Cross-site scripting (XSS) vulnerability in the format function in
libraries/sql-parser/src/Utils/Error.php in the SQL parser in
phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted query.
|
| CVE-2016-2512 |
The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x
before 1.9.3 allows remote attackers to redirect users to arbitrary
web sites and conduct phishing attacks or possibly conduct cross-site
scripting (XSS) attacks via a URL containing basic authentication, as
demonstrated by http://mysite.example.com\@attacker.com.
|
| CVE-2016-2511 |
Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
path parameter to log.php.
|
| CVE-2016-2387 |
Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy
Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote
attackers to inject arbitrary web script or HTML via the (1) ns or (2)
interface parameter to ProxyServer/register, aka SAP Security Note
2220571.
|
| CVE-2016-2350 |
Multiple cross-site scripting (XSS) vulnerabilities on the Accellion
File Transfer Appliance (FTA) before FTA_9_12_40 allow remote
attackers to inject arbitrary web script or HTML via unspecified input
to (1) getimageajax.php, (2) move_partition_frame.html, or (3)
wmInfo.html.
|
| CVE-2016-2305 |
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before
5.0 build 4522 allows remote attackers to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2016-2287 |
Cross-site scripting (XSS) vulnerability in XZERES 442SR OS on 442SR
wind turbines allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2016-2279 |
Cross-site scripting (XSS) vulnerability in the web server in Rockwell
Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-2228 |
Cross-site scripting (XSS) vulnerability in
horde/templates/topbar/_menubar.html.php in Horde Groupware before
5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote
attackers to inject arbitrary web script or HTML via the searchfield
parameter, as demonstrated by a request to xplorer/gollem/manager.php.
|
| CVE-2016-2219 |
Cross-site scripting (XSS) vulnerability in the management interface
in Palo Alto Networks PAN-OS 7.x before 7.0.8 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-2214 |
Cross-site scripting (XSS) vulnerability in an unspecified portal
authentication page in Huawei Agile Controller-Campus with software
before V100R001C00SPC319 allows remote attackers to inject arbitrary
web script or HTML via unknown vectors.
|
| CVE-2016-2163 |
Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before
3.1.1 allows remote attackers to inject arbitrary web script or HTML
via the event description when creating an event.
|
| CVE-2016-2162 |
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale
object constructed by I18NInterceptor, which might allow remote
attackers to conduct cross-site scripting (XSS) attacks via
unspecified vectors involving language display.
|
| CVE-2016-2153 |
Cross-site scripting (XSS) vulnerability in the advanced-search
feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13,
2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows
remote attackers to inject arbitrary web script or HTML via a crafted
field in a URL, as demonstrated by a search form field.
|
| CVE-2016-2152 |
Multiple cross-site scripting (XSS) vulnerabilities in
auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x
before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote
attackers to inject arbitrary web script or HTML via an external DB
profile field.
|
| CVE-2016-2104 |
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat
Satellite 5 allow remote attackers to inject arbitrary web script or
HTML via (1) the label parameter to admin/BunchDetail.do; (2) the
package_name, (3) search_subscribed_channels, or (4) channel_filter
parameter to software/packages/NameOverview.do; or unspecified vectors
related to (5) <input:hidden> or (6) <bean:message> tags.
|
| CVE-2016-2103 |
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat
Satellite 5 allow remote attackers to inject arbitrary web script or
HTML via (1) the list_1680466951_oldfilterval parameter to
systems/PhysicalList.do or (2) unspecified vectors involving
systems/VirtualSystemsList.do.
|
| CVE-2016-2081 |
Cross-site scripting (XSS) vulnerability in VMware vRealize Log
Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-2078 |
Cross-site scripting (XSS) vulnerability in the Web Client in VMware
vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0
before update 2 on Windows allows remote attackers to inject arbitrary
web script or HTML via the flashvars parameter.
|
| CVE-2016-2075 |
Cross-site scripting (XSS) vulnerability in VMware vRealize Business
Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-2058 |
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x,
4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to
inject arbitrary web script or HTML via a status-message, which is not
properly handled in the "detailed status" page, or (2) remote
authenticated users to inject arbitrary web script or HTML via an
acknowledgement message, which is not properly handled in the "status"
page.
|
| CVE-2016-2046 |
Cross-site scripting (XSS) vulnerability in the UserPortal page in
SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary
web script or HTML via the lang parameter.
|
| CVE-2016-2045 |
Cross-site scripting (XSS) vulnerability in the SQL editor in
phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to
inject arbitrary web script or HTML via a SQL query that triggers JSON
data in a response.
|
| CVE-2016-2043 |
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function
in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x
before 4.5.4 allows remote authenticated users to inject arbitrary web
script or HTML via a table name to the normalization page.
|
| CVE-2016-2040 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4
allow remote authenticated users to inject arbitrary web script or
HTML via a (1) table name, (2) SET value, (3) search query, or (4)
hostname in a Location header.
|
| CVE-2016-2030 |
HPE Systems Insight Manager (SIM) before 7.5.1 allows remote
authenticated users to obtain sensitive information or modify data via
unspecified vectors, a different vulnerability than CVE-2016-2017,
CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, and CVE-2016-2022.
|
| CVE-2016-2022 |
HPE Systems Insight Manager (SIM) before 7.5.1 allows remote
authenticated users to obtain sensitive information or modify data via
unspecified vectors, a different vulnerability than CVE-2016-2017,
CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, and CVE-2016-2030.
|
| CVE-2016-2021 |
HPE Systems Insight Manager (SIM) before 7.5.1 allows remote
authenticated users to obtain sensitive information or modify data via
unspecified vectors, a different vulnerability than CVE-2016-2017,
CVE-2016-2019, CVE-2016-2020, CVE-2016-2022, and CVE-2016-2030.
|
| CVE-2016-2020 |
HPE Systems Insight Manager (SIM) before 7.5.1 allows remote
authenticated users to obtain sensitive information or modify data via
unspecified vectors, a different vulnerability than CVE-2016-2017,
CVE-2016-2019, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.
|
| CVE-2016-2019 |
HPE Systems Insight Manager (SIM) before 7.5.1 allows remote
authenticated users to obtain sensitive information or modify data via
unspecified vectors, a different vulnerability than CVE-2016-2017,
CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.
|
| CVE-2016-2018 |
HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers
to obtain sensitive information or modify data via unspecified
vectors.
|
| CVE-2016-2017 |
HPE Systems Insight Manager (SIM) before 7.5.1 allows remote
authenticated users to obtain sensitive information or modify data via
unspecified vectors, a different vulnerability than CVE-2016-2019,
CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.
|
| CVE-2016-2011 |
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i
(NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2016-2010.
|
| CVE-2016-2010 |
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i
(NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2016-2011.
|
| CVE-2016-1954 |
The nsCSPContext::SendReports function in
dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP
report-uri for a Content Security Policy (CSP) violation report, which
allows remote attackers to cause a denial of service (data overwrite)
or possibly gain privileges by specifying a URL of a local file.
|
| CVE-2016-1926 |
Cross-site scripting (XSS) vulnerability in the charts module in
Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote
attackers to inject arbitrary web script or HTML via the
aggregate_type parameter in a get_aggregate command to omp.
|
| CVE-2016-1918 |
Cross-site scripting (XSS) vulnerability in the Management Console in
BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL, a
different vulnerability than CVE-2016-1917.
|
| CVE-2016-1917 |
Cross-site scripting (XSS) vulnerability in the Management Console in
BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL, a
different vulnerability than CVE-2016-1918.
|
| CVE-2016-1916 |
Cross-site scripting (XSS) vulnerability in the Management Console in
BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote
authenticated users to inject arbitrary web script or HTML by
leveraging basic administrative access to create a crafted policy,
leading to improper rendering on a certain Export IT screen.
|
| CVE-2016-1915 |
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry
Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote
attackers to inject arbitrary web script or HTML via the locale
parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp.
|
| CVE-2016-1914 |
Multiple SQL injection vulnerabilities in the
com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise
Server 12 (BES12) Self-Service before 12.4 allow remote attackers to
execute arbitrary SQL commands via the imageName parameter to (1)
mydevice/client/image, (2) admin/client/image, (3)
myapps/client/image, (4) ssam/client/image, or (5) all/client/image.
|
| CVE-2016-1913 |
Multiple cross-site scripting (XSS) vulnerabilities in the Redhen
module 7.x-1.x before 7.x-1.11 for Drupal allow remote authenticated
users with certain access to inject arbitrary web script or HTML via
unspecified vectors, related to (1) individual contacts, (2) notes, or
(3) engagement scores.
|
| CVE-2016-1912 |
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr
ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web
script or HTML via the (1) lastname, (2) firstname, (3) email, (4)
job, or (5) signature parameter to htdocs/user/card.php.
|
| CVE-2016-1911 |
Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver
7.4 allow remote attackers to inject arbitrary web script or HTML via
vectors related to the (1) Runtime Workbench (RWB) or (2) Pmitest
servlet in the Process Monitoring Infrastructure (PMI), aka SAP
Security Notes 2206793 and 2234918.
|
| CVE-2016-1900 |
CRLF injection vulnerability in the cgit_print_http_headers function
in ui-shared.c in CGit before 0.12 allows remote attackers with
permission to write to a repository to inject arbitrary HTTP headers
and conduct HTTP response splitting attacks or cross-site scripting
(XSS) attacks via newline characters in a filename.
|
| CVE-2016-1899 |
CRLF injection vulnerability in the ui-blob handler in CGit before
0.12 allows remote attackers to inject arbitrary HTTP headers and
conduct HTTP response splitting attacks or cross-site scripting (XSS)
attacks via CRLF sequences in the mimetype parameter, as demonstrated
by a request to blob/cgit.c.
|
| CVE-2016-1864 |
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari
before 9.1, does not properly handle redirects in block mode, which
allows remote attackers to obtain sensitive information via a crafted
URL.
|
| CVE-2016-1652 |
Cross-site scripting (XSS) vulnerability in the
ModuleSystem::RequireForJsInner function in
extensions/renderer/module_system.cc in the Extensions subsystem in
Google Chrome before 50.0.2661.75 allows remote attackers to inject
arbitrary web script or HTML via a crafted web site, aka "Universal
XSS (UXSS)."
|
| CVE-2016-1609 |
Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr
before 1.2 Security Update 3 and 2.0 before Security Update 2 allow
remote authenticated users to inject arbitrary web script or HTML via
crafted input, as demonstrated by a crafted attribute of an IMG
element in the phone field of a user profile.
|
| CVE-2016-1599 |
Cross-site scripting (XSS) vulnerability in NetIQ Self Service
Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-1598 |
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows
attackers able to change their username to inject arbitrary HTML code
into the Role Assignment administrator HTML pages.
|
| CVE-2016-1596 |
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus
Novell Service Desk before 7.2 allow remote authenticated users to
inject arbitrary web script or HTML via a certain (1) user name, (2)
tf_aClientFirstName, (3) tf_aClientLastName, (4)
ta_selectedTopicContent, (5) tf_orgUnitName, (6)
tf_aManufacturerFullName, (7) tf_aManufacturerName, (8)
tf_aManufacturerAddress, or (9) tf_aManufacturerCity parameter.
|
| CVE-2016-1595 |
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in
Micro Focus Novell Service Desk before 7.2 allows remote authenticated
users to conduct Hibernate Query Language (HQL) injection attacks and
obtain sensitive information via the entityName parameter.
|
| CVE-2016-1594 |
Micro Focus Novell Service Desk before 7.2 allows remote authenticated
users to read arbitrary attachments via a request to a LiveTime.woa
URL, as demonstrated by obtaining sensitive information via a (1)
downloadLogFiles or (2) downloadFile action.
|
| CVE-2016-1593 |
Directory traversal vulnerability in the import users feature in Micro
Focus Novell Service Desk before 7.2 allows remote authenticated
administrators to upload and execute arbitrary JSP files via a .. (dot
dot) in a filename within a multipart/form-data POST request to a
LiveTime.woa URL.
|
| CVE-2016-1592 |
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote
attackers to inject arbitrary HTML code via the nrfEntitlementReport.do
CGI.
|
| CVE-2016-1566 |
Cross-site scripting (XSS) vulnerability in the file browser in
Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location
shared by multiple users, allows remote authenticated users to inject
arbitrary web script or HTML via a crafted filename. NOTE: this
vulnerability was fixed in guacamole.war on 2016-01-13, but the
version number was not changed.
|
| CVE-2016-1565 |
Cross-site scripting (XSS) vulnerability in the Field Group module
7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users
with permission to configure field display settings to inject
arbitrary web script or HTML via an element attribute.
|
| CVE-2016-1564 |
Multiple cross-site scripting (XSS) vulnerabilities in
wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote
attackers to inject arbitrary web script or HTML via a (1) stylesheet
name or (2) template name to wp-admin/customize.php.
|
| CVE-2016-1498 |
Cross-site scripting (XSS) vulnerability in the OCS discovery provider
component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x
before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors involving a URL.
|
| CVE-2016-1488 |
Cross-site scripting (XSS) vulnerability in the login form in the
integrated web server on Siemens OZW OZW672 devices before 6.00 and
OZW772 devices before 6.00 allows remote attackers to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2016-1485 |
Cross-site scripting (XSS) vulnerability in Cisco Identity Services
Engine 1.3(0.876) allows remote attackers to inject arbitrary web
script or HTML via crafted parameters, aka Bug ID CSCva46497.
|
| CVE-2016-1476 |
Cross-site scripting (XSS) vulnerability on Cisco IP Phone 8800
devices with software 11.0 allows remote authenticated users to inject
arbitrary web script or HTML via crafted parameters, aka Bug ID
CSCuz03024.
|
| CVE-2016-1471 |
Cross-site scripting (XSS) vulnerability in the web-based management
interface on Cisco Small Business 220 devices with firmware before
1.0.1.1 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL, aka Bug ID CSCuz76232.
|
| CVE-2016-1462 |
Cross-site scripting (XSS) vulnerability in the web-based management
interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote
attackers to inject arbitrary web script or HTML via a crafted value,
aka Bug ID CSCuz63795.
|
| CVE-2016-1451 |
Cross-site scripting (XSS) vulnerability in the web-based management
interface in Cisco Meeting Server (formerly Acano Conferencing Server)
1.7 through 1.9 allows remote attackers to inject arbitrary web script
or HTML via crafted parameters, aka Bug ID CSCva19922.
|
| CVE-2016-1449 |
Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings
Server 2.6 allows remote attackers to inject arbitrary web script or
HTML via a crafted URL, aka Bug ID CSCuy92711.
|
| CVE-2016-1447 |
Cross-site scripting (XSS) vulnerability in the administrator
interface in Cisco WebEx Meetings Server 2.6 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors, aka
Bug ID CSCuy83194.
|
| CVE-2016-1439 |
Cross-site scripting (XSS) vulnerability in the management interface
in Cisco Unified Contact Center Enterprise through 10.5(2) allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka Bug ID CSCux59650.
|
| CVE-2016-1431 |
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management
Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers
to inject arbitrary web script or HTML via a crafted URL, aka Bug ID
CSCur25516.
|
| CVE-2016-1423 |
A vulnerability in the display of email messages in the Messages in
Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security
Appliance (ESA) could allow an unauthenticated, remote attacker to
cause a user to click a malicious link in the MIQ view. The malicious
link could be used to facilitate a cross-site scripting (XSS) or HTML
injection attack. More Information: CSCuz02235. Known Affected
Releases: 8.0.2-069. Known Fixed Releases: 9.1.1-038 9.7.2-047.
|
| CVE-2016-1401 |
Cross-site scripting (XSS) vulnerability in the management interface
in Cisco Unified Computing System (UCS) Central Software 1.4(1a)
allows remote attackers to inject arbitrary web script or HTML via a
crafted value, aka Bug ID CSCuy91250.
|
| CVE-2016-1396 |
Cross-site scripting (XSS) vulnerability in the web-based management
interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W
devices with firmware before 1.0.3.16, and RV215W devices with
firmware before 1.3.0.8 allows remote attackers to inject arbitrary
web script or HTML via a crafted parameter, aka Bug ID CSCux82583.
|
| CVE-2016-1377 |
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection
through 11.0 allows remote attackers to inject arbitrary web script or
HTML via unspecified parameters, aka Bug ID CSCus21776.
|
| CVE-2016-1375 |
Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability
and Collaboration System 4.10(1) allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy12339.
|
| CVE-2016-1355 |
Cross-site scripting (XSS) vulnerability in the Device Management UI
in the management interface in Cisco FireSIGHT System Software 6.1.0
allows remote attackers to inject arbitrary web script or HTML via a
crafted value, aka Bug ID CSCuy41687.
|
| CVE-2016-1354 |
Cross-site scripting (XSS) vulnerability in Cisco Unified
Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote
attackers to inject arbitrary web script or HTML via crafted markup
data, aka Bug ID CSCud41176.
|
| CVE-2016-1331 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency
Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary
web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.
|
| CVE-2016-1318 |
Cross-site scripting (XSS) vulnerability in Cisco Application Policy
Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows
remote attackers to inject arbitrary web script or HTML via crafted
markup data, aka Bug ID CSCux15489.
|
| CVE-2016-1314 |
Cross-site scripting (XSS) vulnerability in Cisco Unified
Communications Domain Manager (CDM) 8.1(1) allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL, aka
Bug ID CSCux80760.
|
| CVE-2016-1311 |
Cross-site scripting (XSS) vulnerability in the management interface
in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject
arbitrary web script or HTML via the host tag parameter, aka Bug ID
CSCuy08224.
|
| CVE-2016-1310 |
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection
11.5(0.199) allows remote attackers to inject arbitrary web script or
HTML via a crafted URL, aka Bug ID CSCuy09033.
|
| CVE-2016-1309 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx
Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web
script or HTML via unspecified parameters, aka Bug ID CSCuy01843.
|
| CVE-2016-1306 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog
Director 1.0(0) allow remote attackers to inject arbitrary web script
or HTML via a crafted parameter, aka Bug ID CSCux80466.
|
| CVE-2016-1305 |
Cross-site scripting (XSS) vulnerability in Cisco Application Policy
Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows
remote attackers to inject arbitrary web script or HTML via vectors
involving HTML entities, aka Bug ID CSCux15511.
|
| CVE-2016-1304 |
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection
10.5(2.3009) allows remote attackers to inject arbitrary web script or
HTML via a crafted value, aka Bug ID CSCux82596.
|
| CVE-2016-1300 |
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection
(UC) 10.5(2.3009) allows remote attackers to inject arbitrary web
script or HTML via a crafted URL, aka Bug ID CSCux82582.
|
| CVE-2016-1298 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified
Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow
remote attackers to inject arbitrary web script or HTML via vectors
related to permalinks, aka Bug ID CSCux92033.
|
| CVE-2016-1294 |
Cross-site scripting (XSS) vulnerability in the Management Center in
Cisco FireSIGHT System Software 6.0.1 allows remote attackers to
inject arbitrary web script or HTML via a crafted cookie, aka Bug ID
CSCuw89094.
|
| CVE-2016-1293 |
Multiple cross-site scripting (XSS) vulnerabilities in the Management
Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote
attackers to inject arbitrary web script or HTML via unspecified
parameters, aka Bug ID CSCux40414.
|
| CVE-2016-1236 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN
allow context-dependent attackers to inject arbitrary web script or
HTML via the name of a (a) file or (b) directory in a repository.
|
| CVE-2016-1230 |
Cross-site scripting (XSS) vulnerability in NTT PC Communications
WebARENA Service formmail before 2.2.1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-1229 |
Cross-site scripting (XSS) vulnerability in HumHub 0.20.0-beta.1
through 0.20.1 and 1.0.0-beta before 1.0.0-beta.3 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-1226 |
Cross-site scripting (XSS) vulnerability in Trend Micro Internet
Security 8 and 10 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-1224 |
CRLF injection vulnerability in Trend Micro Worry-Free Business
Security Service 5.x and Worry-Free Business Security 9.0 allows
remote attackers to inject arbitrary HTTP headers and conduct
cross-site scripting (XSS) attacks via unspecified vectors.
|
| CVE-2016-1222 |
Cross-site scripting (XSS) vulnerability in Kobe Beauty
php-contact-form before 2016-05-18 allows remote attackers to inject
arbitrary web script or HTML via a crafted URI.
|
| CVE-2016-1217 |
Cross-site scripting (XSS) vulnerability in the "Check available
times" function in Cybozu Garoon before 4.2.2.
|
| CVE-2016-1216 |
Cross-site scripting (XSS) vulnerability in the "New appointment"
function in Cybozu Garoon before 4.2.2.
|
| CVE-2016-1215 |
Cross-site scripting (XSS) vulnerability in the "User details"
function in Cybozu Garoon before 4.2.2.
|
| CVE-2016-1214 |
Cross-site scripting (XSS) vulnerability in the "Response request"
function in Cybozu Garoon before 4.2.2.
|
| CVE-2016-1211 |
Cross-site scripting (XSS) vulnerability in Epoch Web Mailing List
0.31 and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-1207 |
Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R
devices with firmware 1.12 and earlier, WN-G300R2 devices with
firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01
and earlier allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-1205 |
Cross-site scripting (XSS) vulnerability in the shiro8 (1)
category_freearea_ addition_plugin plugin 1.0 and (2)
itemdetail_freearea_ addition_plugin plugin 1.0 for EC-CUBE allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-1197 |
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before
4.2.1 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, a different vulnerability than CVE-2015-7775.
|
| CVE-2016-1182 |
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not
properly restrict the Validator configuration, which allows remote
attackers to conduct cross-site scripting (XSS) attacks or cause a
denial of service via crafted input, a related issue to CVE-2015-0899.
|
| CVE-2016-1180 |
Cross-site scripting (XSS) vulnerability in the Cyber-Will
Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-1179 |
Cross-site scripting (XSS) vulnerability in the standard template of
the comment functionality in appleple a-blog cms 2.6.0.1 and earlier
allows remote attackers to inject arbitrary web script or HTML.
|
| CVE-2016-1173 |
Cross-site scripting (XSS) vulnerability in the Menubook plugin before
0.9.3 for baserCMS allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-1171 |
Cross-site scripting (XSS) vulnerability in the Recruit plugin before
0.9.3 for baserCMS allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-1169 |
Cross-site scripting (XSS) vulnerability in the Casebook plugin before
0.9.4 for baserCMS allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-1160 |
Cross-site scripting (XSS) vulnerability in the WP Favorite Posts
plugin before 1.6.6 for WordPress allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-1157 |
Cross-site scripting (XSS) vulnerability in log_chat.cgi in Script*
Log-Chat before 2.0 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2016-1150 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0
through 10.3.0 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and
CVE-2016-1149.
|
| CVE-2016-1149 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0
through 10.3.0 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and
CVE-2016-1150.
|
| CVE-2016-1144 |
Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM
before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 and earlier allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2016-1143 |
Cross-site scripting (XSS) vulnerability in main.rb in Vine MV before
2015-11-08 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-1136 |
Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE
devices before 2 allows remote authenticated users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2016-1135 |
Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices
with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and
earlier, WHR-1166DHP devices with firmware 1.90 and earlier,
WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices
with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and
earlier, WMR-433 devices with firmware 1.01 and earlier, and
WSR-1166DHP devices with firmware 1.01 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2016-1113 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before
Update 19, 11 before Update 8, and 2016 before Update 1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2016-10704 |
Magento Community Edition and Enterprise Edition before 2.0.10 and
2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled
during a preview, aka APPSEC-1503.
|
| CVE-2016-10699 |
D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS
attacks in the username and password fields: a remote unauthenticated
user may craft logins and passwords with script tags in them. Because
there is no sanitization in the input fields, an unaware logged-in
administrator may be a victim when checking the router logs.
|
| CVE-2016-10516 |
Cross-site scripting (XSS) vulnerability in the render_full function in
debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as
used in Pallets Flask and other products) allows remote attackers to
inject arbitrary web script or HTML via a field that contains an
exception message.
|
| CVE-2016-10515 |
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting
Textile and Markdown text formatting, and project homepages.
|
| CVE-2016-10513 |
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted
search expression to include/functions_search.inc.php.
|
| CVE-2016-10510 |
Cross-site scripting (XSS) vulnerability in the Security component of
Kohana before 3.3.6 allows remote attackers to inject arbitrary web
script or HTML by bypassing the strip_image_tags protection mechanism
in system/classes/Kohana/Security.php.
|
| CVE-2016-10508 |
Multiple cross-site scripting (XSS) vulnerabilities in phpThumb()
before 1.7.14 allow remote attackers to inject arbitrary web script or
HTML via parameters in demo/phpThumb.demo.showpic.php.
|
| CVE-2016-10404 |
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect
field to
modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
|
| CVE-2016-10366 |
Kibana versions after and including 4.3 and before 4.6.2 are
vulnerable to a cross-site scripting (XSS) attack.
|
| CVE-2016-1036 |
Cross-site scripting (XSS) vulnerability in Adobe Analytics
AppMeasurement for Flash Library before 4.0.1, when debugTracking is
enabled, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-10203 |
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the name when creating a new monitor.
|
| CVE-2016-10202 |
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the path info to index.php.
|
| CVE-2016-10201 |
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the format parameter in a download log request to index.php.
|
| CVE-2016-10112 |
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin
before 2.6.9 for WordPress allows remote authenticated administrators
to inject arbitrary web script or HTML by providing crafted tax-rate
table values in CSV format.
|
| CVE-2016-10083 |
Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo
through 2.8.3 allows remote attackers to inject arbitrary web script or
HTML via a crafted filename that is mishandled in a certain error case.
|
| CVE-2016-10006 |
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input
(a tag that supports style with active content), you could bypass the
library protections and supply executable code. The impact is XSS.
|
| CVE-2016-1000307 |
Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket
v2.8.1 and probably prior allow Remote Attackers to inject arbitrary
web script or HTML via (1) profile_desc, about_me, schools,
occupation, companies, hobbies, fav_movies, fav_music, fav_books
parameters to ProfileSettings page; (2) note parameter to
PersonalNotes Section; (3) closed_msg, description, allowed_types
parameters to WebsiteConfigurations Section. NOTE: the
collection_description vector is already covered by CVE-2015-4673.
|
| CVE-2016-1000220 |
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that
would allow an attacker to execute arbitrary JavaScript in users'
browsers.
|
| CVE-2016-1000155 |
Reflected XSS in wordpress plugin wpsolr-search-engine v7.6
|
| CVE-2016-1000154 |
Reflected XSS in wordpress plugin whizz v1.0.7
|
| CVE-2016-1000153 |
Reflected XSS in wordpress plugin tidio-gallery v1.1
|
| CVE-2016-1000152 |
Reflected XSS in wordpress plugin tidio-form v1.0
|
| CVE-2016-1000151 |
Reflected XSS in wordpress plugin tera-charts v1.0
|
| CVE-2016-1000150 |
Reflected XSS in wordpress plugin simplified-content v1.0.0
|
| CVE-2016-1000149 |
Reflected XSS in wordpress plugin simpel-reserveren v3.5.2
|
| CVE-2016-1000148 |
Reflected XSS in wordpress plugin s3-video v0.983
|
| CVE-2016-1000147 |
Reflected XSS in wordpress plugin recipes-writer v1.0.4
|
| CVE-2016-1000146 |
Reflected XSS in wordpress plugin pondol-formmail v1.1
|
| CVE-2016-1000145 |
Reflected XSS in wordpress plugin pondol-carousel v1.0
|
| CVE-2016-1000144 |
Reflected XSS in wordpress plugin photoxhibit v2.1.8
|
| CVE-2016-1000143 |
Reflected XSS in wordpress plugin photoxhibit v2.1.8
|
| CVE-2016-1000142 |
Reflected XSS in wordpress plugin parsi-font v4.2.5
|
| CVE-2016-1000141 |
Reflected XSS in wordpress plugin page-layout-builder v1.9.3
|
| CVE-2016-1000140 |
Reflected XSS in wordpress plugin new-year-firework v1.1.9
|
| CVE-2016-1000139 |
Reflected XSS in wordpress plugin infusionsoft v1.5.11
|
| CVE-2016-1000138 |
Reflected XSS in wordpress plugin indexisto v1.0.5
|
| CVE-2016-1000137 |
Reflected XSS in wordpress plugin hero-maps-pro v2.1.0
|
| CVE-2016-1000136 |
Reflected XSS in wordpress plugin heat-trackr v1.0
|
| CVE-2016-1000135 |
Reflected XSS in wordpress plugin hdw-tube v1.2
|
| CVE-2016-1000134 |
Reflected XSS in wordpress plugin hdw-tube v1.2
|
| CVE-2016-1000133 |
Reflected XSS in wordpress plugin forget-about-shortcode-buttons
v1.1.1
|
| CVE-2016-1000132 |
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
|
| CVE-2016-1000131 |
Reflected XSS in wordpress plugin e-search v1.0
|
| CVE-2016-1000130 |
Reflected XSS in wordpress plugin e-search v1.0
|
| CVE-2016-1000129 |
Reflected XSS in wordpress plugin defa-online-image-protector v3.3
|
| CVE-2016-1000128 |
Reflected XSS in wordpress plugin anti-plagiarism v3.60
|
| CVE-2016-1000127 |
Reflected XSS in wordpress plugin ajax-random-post v2.00
|
| CVE-2016-1000126 |
Reflected XSS in wordpress plugin admin-font-editor v1.8
|
| CVE-2016-1000122 |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
|
| CVE-2016-1000121 |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
|
| CVE-2016-1000120 |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
|
| CVE-2016-1000119 |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
|
| CVE-2016-1000118 |
XSS & SQLi in HugeIT slideshow v1.0.4
|
| CVE-2016-1000117 |
XSS & SQLi in HugeIT slideshow v1.0.4
|
| CVE-2016-1000116 |
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
|
| CVE-2016-1000115 |
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
|
| CVE-2016-1000114 |
XSS in huge IT gallery v1.1.5 for Joomla
|
| CVE-2016-1000113 |
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
|
| CVE-2016-1000007 |
Pagure 2.2.1 XSS in raw file endpoint
|
| CVE-2016-0955 |
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager
(AEM) 6.1.0 allows remote authenticated users to inject arbitrary web
script or HTML via a folder title field that is mishandled in the
Deletion popup dialog.
|
| CVE-2016-0927 |
Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry
(PCF) Ops Manager before 1.6.17 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-0926 |
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal
Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before
1.7.8 allows remote attackers to inject arbitrary web script or HTML
via unspecified input that improperly interacts with the AngularJS
framework.
|
| CVE-2016-0925 |
Cross-site scripting (XSS) vulnerability in the Case Management
application in EMC RSA Adaptive Authentication (On-Premise) before
6.0.2.1.SP3.P4 HF210, 7.0.x and 7.1.x before 7.1.0.0.SP0.P6 HF50, and
7.2.x before 7.2.0.0.SP0.P0 HF20 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-0901 |
Cross-site scripting (XSS) vulnerability in EMC RSA Authentication
Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, a different vulnerability
than CVE-2016-0900.
|
| CVE-2016-0900 |
Cross-site scripting (XSS) vulnerability in EMC RSA Authentication
Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, a different vulnerability
than CVE-2016-0901.
|
| CVE-2016-0892 |
Cross-site scripting (XSS) vulnerability in EMC RSA Data Loss
Prevention 9.6 before SP2 P5 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2016-0866 |
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid
LightHouse Sensor Management System (SMS) Software EMS before 5.1, and
4.1.0 Build 16, allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2016-0782 |
The administration web console in Apache ActiveMQ 5.x before 5.11.4,
5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote
authenticated users to conduct cross-site scripting (XSS) attacks and
consequently obtain sensitive information from a Java memory dump via
vectors related to creating a queue.
|
| CVE-2016-0781 |
The UAA OAuth approval pages in Cloud Foundry v208 to v231,
Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to
v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x
versions prior to 1.6.20 are vulnerable to an XSS attack by specifying
malicious java script content in either the OAuth scopes (SCIM groups)
or SCIM group descriptions.
|
| CVE-2016-0770 |
Cross-site scripting (XSS) vulnerability in
includes/admin/pages/manage.php in the Connections Business Directory
plugin before 8.5.9 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the s variable.
|
| CVE-2016-0769 |
Multiple SQL injection vulnerabilities in eshop-orders.php in the
eShop plugin 6.3.14 for WordPress allow (1) remote administrators to
execute arbitrary SQL commands via the delid parameter or remote
authenticated users to execute arbitrary SQL commands via the (2)
view, (3) mark, or (4) change parameter.
|
| CVE-2016-0765 |
Multiple cross-site scripting (XSS) vulnerabilities in
eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) page or
(2) action parameter.
|
| CVE-2016-0725 |
Cross-site scripting (XSS) vulnerability in the search_pagination
function in course/classes/management_renderer.php in Moodle 2.8.x
before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows
remote attackers to inject arbitrary web script or HTML via a crafted
search string.
|
| CVE-2016-0713 |
Gorouter in Cloud Foundry cf-release v141 through v228 allows
man-in-the-middle attackers to conduct cross-site scripting (XSS)
attacks via vectors related to modified requests.
|
| CVE-2016-0712 |
Cross-site scripting (XSS) vulnerability in Apache Jetspeed before
2.3.1 allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to portal.
|
| CVE-2016-0711 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed
before 2.3.1 allow remote attackers to inject arbitrary web script or
HTML via the title parameter when adding a (1) link, (2) page, or (3)
folder resource.
|
| CVE-2016-0399 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.9 IFIX007, and 7.6
before 7.6.0.5 FP005 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-0390 |
Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One
Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2016-0387 |
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application
Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before
3.5.0.2 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, a different vulnerability than
CVE-2016-2883.
|
| CVE-2016-0370 |
Cross-site scripting (XSS) vulnerability in IBM Forms Experience
Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users
to inject arbitrary web script or HTML via crafted input to an
application that was built with this product.
|
| CVE-2016-0350 |
Cross-site scripting (XSS) vulnerability in the Report Builder and
Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS)
5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL, a different vulnerability than CVE-2016-2888 and
CVE-2016-0313.
|
| CVE-2016-0346 |
Cross-site scripting (XSS) vulnerability in IBM Cognos Business
Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before
IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2016-0331 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert
6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative
Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2016-0322 |
Cross-site scripting (XSS) vulnerability in IBM Connections 4.0
through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1
allows remote authenticated users to inject arbitrary web script or
HTML by uploading an HTML document.
|
| CVE-2016-0316 |
Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine
(LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006
and 6.0.2 before iFix003 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-0313 |
Cross-site scripting (XSS) vulnerability in the Report Builder and
Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS)
5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL, a different vulnerability than CVE-2016-2888 and
CVE-2016-0350.
|
| CVE-2016-0293 |
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform
(formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before
9.2.8 allows remote attackers to inject arbitrary web script or HTML
via a modified .beswrpt file.
|
| CVE-2016-0285 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative
Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11,
5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality
Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before
5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert
3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2
iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0
before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2
iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11,
5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody
Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and
6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager
4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2
iFix5 allows remote authenticated users to inject arbitrary web script
or HTML via a crafted field.
|
| CVE-2016-0283 |
Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC)
client web application in IBM WebSphere Application Server (WAS)
Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-0282 |
Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3
FP6 IF2 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, aka SPR KLYHAAHNUS.
|
| CVE-2016-0280 |
Cross-site scripting (XSS) vulnerability in IBM Information Server
Framework 8.5, Information Server Framework and InfoSphere Information
Server Business Glossary 8.7 before FP2, Information Server Framework
and InfoSphere Information Server Business Glossary 9.1 before
9.1.2.0, Information Server Framework and InfoSphere Information
Governance Catalog 11.3 before 11.3.1.2, and Information Server
Framework and InfoSphere Information Governance Catalog 11.5 before
11.5.0.1 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2016-0273 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative
Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11,
5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality
Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before
5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert
3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2
iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0
before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2
iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11,
5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody
Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and
6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager
4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2
iFix5 allows remote authenticated users to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2016-0269 |
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x
before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users
to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-0262 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.1.1 through 7.1.1.3, 7.5.0 before 7.5.0.9 IFIX004, and
7.6.0 before 7.6.0.3 IFIX001 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-0246 |
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2
before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before
p100 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL.
|
| CVE-2016-0244 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal
6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x
through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before
8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or
HTML via a crafted URL, a different vulnerability than CVE-2016-0243.
|
| CVE-2016-0243 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal
6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x
through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before
8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or
HTML via a crafted URL, a different vulnerability than CVE-2016-0244.
|
| CVE-2016-0229 |
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform
8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2016-0227 |
Cross-site scripting (XSS) vulnerability in the document-list control
implementation in IBM Business Process Manager (BPM) 8.0 through
8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2016-0221 |
Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in
IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17,
10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19,
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2016-0209 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0
before CF09 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2016-0039 |
Cross-site scripting (XSS) vulnerability in SharePoint Server in
Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to
inject arbitrary web script or HTML via a crafted request, aka
"Microsoft SharePoint XSS Vulnerability."
|
| CVE-2016-0032 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013
Cumulative Update 11, and 2016 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing
Vulnerability."
|
| CVE-2016-0031 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
in Microsoft Exchange Server 2016 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing
Vulnerability," a different vulnerability than CVE-2016-0029.
|
| CVE-2016-0030 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, and
2016 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL, aka "Exchange Spoofing Vulnerability."
|
| CVE-2016-0029 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
in Microsoft Exchange Server 2016 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing
Vulnerability," a different vulnerability than CVE-2016-0031.
|
| CVE-2016-0011 |
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013
SP1 allow remote authenticated users to bypass intended Access Control
Policy restrictions and conduct cross-site scripting (XSS) attacks by
modifying a webpart, aka "Microsoft SharePoint Security Feature
Bypass," a different vulnerability than CVE-2015-6117.
|
| CVE-2015-9233 |
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal)
plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related
to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
|
| CVE-2015-9230 |
In the admin/db-backup-security/db-backup-security.php page in the
BulletProof Security plugin before .52.5 for WordPress, XSS is possible
for remote authenticated administrators via the DBTablePrefix
parameter.
|
| CVE-2015-9229 |
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery
plugin 2.1.15 for WordPress, XSS is possible for remote authenticated
administrators via the images[1][alttext] parameter.
|
| CVE-2015-9105 |
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video
Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before
1.6-0847 allow remote authenticated attackers to inject arbitrary web
script or HTML via the (1) file name or (2) collection name of videos.
|
| CVE-2015-9104 |
Cross-site scripting (XSS) vulnerabilities in Synology Audio Station
5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows remote
authenticated attackers to inject arbitrary web script or HTML via the
album title.
|
| CVE-2015-9103 |
Multiple cross-site scripting (XSS) vulnerabilities in Synology Note
Station 1.1-0212 and earlier allow remote authenticated attackers to
inject arbitrary web script or HTML via the (1) note title or (2) file
name of attachments.
|
| CVE-2015-9102 |
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo
Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote
authenticated attackers to inject arbitrary web script or HTML via the
(1) album name, (2) file name of uploaded photos, (3) description of
photos, or (4) tag of the photos.
|
| CVE-2015-9057 |
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail
Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject
arbitrary web script or HTML via multiple parameters, related to
/users/index.htm, /quarantine/spam/manage.htm,
/quarantine/spam/whitelist.htm, /queues/mail/index/, /system/ssh.htm,
/queues/mail/?domain=, and /quarantine/virus/manage.htm.
|
| CVE-2015-9056 |
Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS
attack.
|
| CVE-2015-8976 |
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard)
before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before
1.8.6 might allow remote attackers to inject arbitrary web script or
HTML via vectors related to "old upgrade files."
|
| CVE-2015-8975 |
Cross-site scripting (XSS) vulnerability in the error handler in MyBB
(aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB
Merge System before 1.8.6 might allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-8936 |
Cross-site scripting (XSS) vulnerability in squidGuard.cgi in
squidGuard before 1.5 allows remote attackers to inject arbitrary web
script or HTML via a blocked site link.
|
| CVE-2015-8935 |
The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x
before 5.5.22, and 5.6.x before 5.6.6 supports deprecated line folding
without considering browser compatibility, which allows remote
attackers to conduct cross-site scripting (XSS) attacks against
Internet Explorer by leveraging (1) %0A%20 or (2) %0D%0A%20
mishandling in the header function.
|
| CVE-2015-8864 |
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before
1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject
arbitrary web script or HTML via a crafted SVG, a different
vulnerability than CVE-2016-4068.
|
| CVE-2015-8862 |
mustache package before 2.2.1 for Node.js allows remote attackers to
conduct cross-site scripting (XSS) attacks by leveraging a template
with an attribute that is not quoted.
|
| CVE-2015-8861 |
The handlebars package before 4.0.0 for Node.js allows remote
attackers to conduct cross-site scripting (XSS) attacks by leveraging
a template with an attribute that is not quoted.
|
| CVE-2015-8856 |
Cross-site scripting (XSS) vulnerability in the serve-index package
before 1.6.3 for Node.js allows remote attackers to inject arbitrary
web script or HTML via a crafted file or directory name.
|
| CVE-2015-8834 |
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in
WordPress before 4.2.2 allows remote attackers to inject arbitrary web
script or HTML via a long comment that is improperly stored because of
limitations on the MySQL TEXT data type. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2015-3440.
|
| CVE-2015-8832 |
Multiple incomplete blacklist vulnerabilities in
inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote
authenticated users with "manage their own media items" and "manage
their own entries and comments" permissions to execute arbitrary PHP
code by uploading a file with a (1) .pht, (2) .phps, or (3) .phtml
extension.
|
| CVE-2015-8831 |
Cross-site scripting (XSS) vulnerability in admin/comments.php in
Dotclear before 2.8.2 allows remote attackers to inject arbitrary web
script or HTML via the author name in a comment.
|
| CVE-2015-8815 |
Multiple cross-site scripting (XSS) vulnerabilities in Umbraco before
7.4.0 allow remote attackers to inject arbitrary web script or HTML
via the name parameter to (1) the media page, (2) the developer data
edit page, or (3) the form page.
|
| CVE-2015-8807 |
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number
function in
horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde
Groupware before 5.2.12 and Horde Groupware Webmail Edition before
5.2.12 allows remote attackers to inject arbitrary web script or HTML
via vectors involving numeric form fields.
|
| CVE-2015-8797 |
Cross-site scripting (XSS) vulnerability in
webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in
Apache Solr before 5.3.1 allows remote attackers to inject arbitrary
web script or HTML via the entry parameter to a plugins/cache URI.
|
| CVE-2015-8796 |
Cross-site scripting (XSS) vulnerability in
webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr
before 5.3 allows remote attackers to inject arbitrary web script or
HTML via a crafted schema-browse URL.
|
| CVE-2015-8795 |
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in
Apache Solr before 5.1 allow remote attackers to inject arbitrary web
script or HTML via crafted fields that are mishandled during the
rendering of the (1) Analysis page, related to
webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related
to webapp/web/js/scripts/schema-browser.js.
|
| CVE-2015-8793 |
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php
in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote
attackers to inject arbitrary web script or HTML via the _mbox
parameter in a mail task to the default URL, a different vulnerability
than CVE-2011-2937.
|
| CVE-2015-8766 |
Multiple cross-site scripting (XSS) vulnerabilities in
content/content.systempreferences.php in Symphony CMS before 2.6.4
allow remote attackers to inject arbitrary web script or HTML via the
(1) email_sendmail[from_name], (2) email_sendmail[from_address], (3)
email_smtp[from_name], (4) email_smtp[from_address], (5)
email_smtp[host], (6) email_smtp[port], (7)
jit_image_manipulation[trusted_external_sites], or (8)
maintenance_mode[ip_whitelist] parameters to system/preferences.
|
| CVE-2015-8759 |
Cross-site scripting (XSS) vulnerability in the typoLink function in
TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote
authenticated editors to inject arbitrary web script or HTML via a
link field.
|
| CVE-2015-8758 |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified
frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1
allow remote authenticated editors to inject arbitrary web script or
HTML via unknown vectors.
|
| CVE-2015-8757 |
Cross-site scripting (XSS) vulnerability in the Extension Manager in
TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors related
to extension data during an extension installation.
|
| CVE-2015-8756 |
Cross-site scripting (XSS) vulnerability in the search result view in
the Indexed Search (indexed_search) component in TYPO3 6.2.x before
6.2.16 allows remote authenticated editors to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-8755 |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified
backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1
allow remote authenticated editors to inject arbitrary web script or
HTML via unknown vectors.
|
| CVE-2015-8699 |
Multiple cross-site scripting (XSS) vulnerabilities in CA Release
Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227,
5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before
6.1.0-1026 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-8687 |
Multiple cross-site scripting (XSS) vulnerabilities in the Management
Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) deviceTypeID parameter to DeviceType/getDeviceType.do; the (2)
policyActionClass or (3) policyActionName parameter to
PolicyAction/findPolicyActions.do; the deviceID parameter to (4)
SingleDeviceMgmt/getDevice.do or (5) device/editDevice.do; the
operation parameter to (6) ajax.do or (7) xmlHttp.do; or the (8)
policyAction, (9) policyClass, or (10) policyName parameter to
policy/findPolicies.do.
|
| CVE-2015-8685 |
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr
ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) external calendar url or (2) the bank
name field in the "import external calendar" page.
|
| CVE-2015-8684 |
Exponent CMS before 2.3.7 does not properly restrict the types of
files that can be uploaded, which allows remote attackers to conduct
cross-site scripting (XSS) attacks and possibly have other unspecified
impact as demonstrated by uploading a file with an .html extension,
then accessing it via the elFinder functionality.
|
| CVE-2015-8667 |
Cross-site scripting (XSS) vulnerability in Reset Your Password module
in Exponent CMS before 2.3.5 allows remote attackers to inject
arbitrary web script or HTML via the Username/Email.
|
| CVE-2015-8622 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12,
1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1,
when is configured with a relative URL, allows remote authenticated
users to inject arbitrary web script or HTML via wikitext, as
demonstrated by a wikilink to a page named "javascript:alert('XSS!')."
|
| CVE-2015-8606 |
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe
CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote
attackers to inject arbitrary web script or HTML via the (1) Locale or
(2) FailedLoginCount parameter to
admin/security/EditForm/field/Members/item/new/ItemEditForm.
|
| CVE-2015-8603 |
Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3
allows remote attackers to inject arbitrary web script or HTML via the
serendipity[entry_id] parameter in an "edit" admin action to
serendipity_admin.php.
|
| CVE-2015-8531 |
Cross-site scripting (XSS) vulnerability in IBM Security Access
Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2015-8524 |
Cross-site scripting (XSS) vulnerability in Process Portal in IBM
Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through
8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-8510 |
Cross-site scripting (XSS) vulnerability in the internationalization
feature in the default homescreen app in Mozilla Firefox OS before 2.5
allows user-assisted remote attackers to inject arbitrary web script
or HTML via a crafted web site that is mishandled during "Add to home
screen" bookmarking.
|
| CVE-2015-8508 |
Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in
Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before
4.4.11, and 4.5.x and 5.0.x before 5.0.2, when a local dot
configuration is used, allows remote attackers to inject arbitrary web
script or HTML via a crafted bug summary.
|
| CVE-2015-8477 |
Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2
allows remote attackers to inject arbitrary web script or HTML via
vectors involving flash message rendering.
|
| CVE-2015-8398 |
Cross-site scripting (XSS) vulnerability in Atlassian Confluence
before 5.8.17 allows remote attackers to inject arbitrary web script
or HTML via the PATH_INFO to rest/prototype/1/session/check.
|
| CVE-2015-8376 |
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS
2.6.3 allow remote attackers to inject arbitrary web script or HTML
via the (1) Name, (2) Navigation Group, or (3) Label parameter to
blueprints/sections/edit/1.
|
| CVE-2015-8375 |
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
|
| CVE-2015-8354 |
Cross-site scripting (XSS) vulnerability in the Ultimate Member
WordPress plugin before 1.3.29 for WordPress allows remote attackers
to inject arbitrary web script or HTML via the _refer parameter to
wp-admin/users.php.
|
| CVE-2015-8353 |
Cross-site scripting (XSS) vulnerability in the Role Scoper plugin
before 1.3.67 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the object_name parameter in a
rs-object_role_edit page to wp-admin/admin.php.
|
| CVE-2015-8350 |
Multiple cross-site scripting (XSS) vulnerabilities in the Calls to
Action plugin before 2.5.1 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) open-tab parameter in
a wp_cta_global_settings action to wp-admin/edit.php or (2)
wp-cta-variation-id parameter to ab-testing-call-to-action-example/.
|
| CVE-2015-8349 |
Cross-site scripting (XSS) vulnerability in SourceBans before 2.0
pre-alpha allows remote attackers to inject arbitrary web script or
HTML via the advSearch parameter to index.php.
|
| CVE-2015-8310 |
Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0
allows remote authenticated users to inject arbitrary web script or
HTML via the playlistname field when creating a new playlist.
|
| CVE-2015-8256 |
Multiple cross-site scripting (XSS) vulnerabilities in Axis network
cameras.
|
| CVE-2015-8247 |
Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo
Internet Management Software (IMS) 2015 allows remote attackers to
inject arbitrary web script or HTML via the plan_name parameter to
packagehistory/listusagesdata.
|
| CVE-2015-8233 |
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x
before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal allows remote
administrators with the "Administer themes" permission to inject
arbitrary web script or HTML via unspecified vectors related to theme
settings.
|
| CVE-2015-8105 |
Cross-site scripting (XSS) vulnerability in program/js/app.js in
Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote
authenticated users to inject arbitrary web script or HTML via the
file name in a drag-n-drop file upload.
|
| CVE-2015-8053 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before
Update 18 and 11 before Update 7 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2015-8052.
|
| CVE-2015-8052 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before
Update 18 and 11 before Update 7 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2015-8053.
|
| CVE-2015-8038 |
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical
User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow
remote attackers to inject arbitrary web script or HTML via the (1)
sharedjobmanager or (2) SOMServiceObjDialog.
|
| CVE-2015-8037 |
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical
User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow
remote attackers to inject arbitrary web script or HTML via the (1)
SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory.
|
| CVE-2015-8010 |
Cross-site scripting (XSS) vulnerability in the Classic-UI with the
CSV export link and pagination feature in Icinga before 1.14 allows
remote attackers to inject arbitrary web script or HTML via the query
string to cgi-bin/status.cgi.
|
| CVE-2015-8006 |
Cross-site scripting (XSS) vulnerability in the PageTriage toolbar in
the PageTriage extension for MediWiki allows remote attackers to
inject arbitrary web script or HTML via the page title.
|
| CVE-2015-7997 |
Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API
in Citrix NetScaler Application Delivery Controller (ADC) and
NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11,
and 10.5.e before Build 56.1505.e on NetScaler Service Delivery
Appliance Service VM (SVM) devices allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-7989 |
Cross-site scripting (XSS) vulnerability in the user list table in
WordPress before 4.3.1 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted e-mail address, a different
vulnerability than CVE-2015-5714.
|
| CVE-2015-7980 |
Cross-site scripting (XSS) vulnerability in the Compass Rose module
6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to
"embedding a JavaScript library from an external source that was not
reliable."
|
| CVE-2015-7927 |
Cross-site scripting (XSS) vulnerability on eWON devices with firmware
through 10.1s0 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2015-7916 |
Cross-site scripting (XSS) vulnerability in Sauter EY-WS505F0x0
moduWeb Vision before 1.6.0 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted query.
|
| CVE-2015-7879 |
Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x
before 7.x-1.3 for Drupal allows remote authenticated users with
permission to create or edit a stickynote to inject arbitrary web
script or HTML via note text on the admin listing page.
|
| CVE-2015-7878 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Find module
6.x-2.x through 6.x-1.2 and 7.x-2.x through 7.x-1.0 in Drupal allows
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via taxonomy vocabulary and term names.
|
| CVE-2015-7822 |
Multiple cross-site scripting (XSS) vulnerabilities in Kentico CMS 8.2
allow remote attackers to inject arbitrary web script or HTML via a
(1) parameter name to CMSModules/AdminControls/Pages/UIPage.aspx or
the (2) CMSBodyClass cookie variable to the default URI.
|
| CVE-2015-7798 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0
through 10.3.0 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2016-1149, and
CVE-2016-1150.
|
| CVE-2015-7797 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0
through 10.3.0 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2015-7795, CVE-2015-7796, CVE-2015-7798, CVE-2016-1149, and
CVE-2016-1150.
|
| CVE-2015-7796 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0
through 10.3.0 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2015-7795, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and
CVE-2016-1150.
|
| CVE-2015-7795 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0
through 10.3.0 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and
CVE-2016-1150.
|
| CVE-2015-7790 |
Cross-site scripting (XSS) vulnerability on ASUS Japan WL-330NUL
devices with firmware before 3.0.0.42 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-7786 |
Cross-site scripting (XSS) vulnerability in the NTT DATA Smart
Sourcing JavaScript module 2003-11-26 through 2013-07-09 for Web
Analytics Service allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-7783 |
Cross-site scripting (XSS) vulnerability in Let's PHP! p++BBS before
4.10 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2015-7782 |
Cross-site scripting (XSS) vulnerability in Let's PHP! Frame
high-speed chat before 2015-09-22 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-7777 |
Cross-site scripting (XSS) vulnerability in index.php in JosephErnest
Void before 2015-10-02 allows remote attackers to inject arbitrary web
script or HTML via a crafted URI.
|
| CVE-2015-7775 |
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2016-1197.
|
| CVE-2015-7772 |
Cross-site scripting (XSS) vulnerability in the runtime engine in the
Newphoria applican framework before 1.13.0 for Android and iOS allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL that triggers WebView anchor attachment in an applican
application, a different vulnerability than CVE-2015-7771.
|
| CVE-2015-7771 |
Cross-site scripting (XSS) vulnerability in the runtime engine in the
Newphoria applican framework before 1.13.0 for Android and iOS allows
remote attackers to inject arbitrary web script or HTML via a crafted
SSID that is encountered by an applican application, a different
vulnerability than CVE-2015-7772.
|
| CVE-2015-7728 |
Cross-site scripting (XSS) vulnerability in user creation in the
Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160
(NewDB100_REL) allows remote authenticated users to inject arbitrary
web script or HTML via the username, aka SAP Security Note 2153898.
|
| CVE-2015-7726 |
Cross-site scripting (XSS) vulnerability in role deletion in the
Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308
allows remote authenticated users to inject arbitrary web script or
HTML via the role name, aka SAP Security Note 2153898.
|
| CVE-2015-7711 |
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor
2.2 and earlier allows remote attackers to inject arbitrary web script
or HTML via the h parameter.
|
| CVE-2015-7708 |
Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
cat_description parameter in an updatecat action to
admin/categories.php.
|
| CVE-2015-7706 |
Multiple cross-site scripting (XSS) vulnerabilities in Secure Data
Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary
web script or HTML via the (1) PATH_INFO to
api/v3/public/shares/downloads/, the (2) authType parameter to
api/v3/auth/login, or the (3) login parameter to
api/v3/auth/reset_password.
|
| CVE-2015-7679 |
Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile
before 1.2.2 allows remote attackers to inject arbitrary web script or
HTML via the query string to mobile/.
|
| CVE-2015-7676 |
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when
configured to support file view on download, allows remote
authenticated users to conduct cross-site scripting (XSS) attacks by
uploading HTML files.
|
| CVE-2015-7672 |
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1.
|
| CVE-2015-7668 |
Cross-site scripting (XSS) vulnerability in
includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the map_id parameter.
|
| CVE-2015-7667 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
templates/admanagement/admanagement.php and (2)
templates/adspot/adspot.php in the ResAds plugin before 1.0.2 for
WordPress allow remote attackers to inject arbitrary web script or
HTML via the page parameter.
|
| CVE-2015-7666 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1)
cp_updateMessageItem and (2) cp_deleteMessageItem functions in
cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal
Pro plugin before 1.0.2 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the cal parameter.
|
| CVE-2015-7604 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk
Enterprise 6.2.x before 6.2.6 and Splunk Light 6.2.x before 6.2.6
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-7580 |
Cross-site scripting (XSS) vulnerability in
lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before
1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to
inject arbitrary web script or HTML via a crafted CDATA node.
|
| CVE-2015-7579 |
Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer
gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to
inject arbitrary web script or HTML via an HTML entity that is
mishandled by the Rails::Html::FullSanitizer class.
|
| CVE-2015-7578 |
Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer
gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote
attackers to inject arbitrary web script or HTML via crafted tag
attributes.
|
| CVE-2015-7565 |
Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through
1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before
1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before
2.2.1 allows remote attackers to inject arbitrary web script or HTML.
|
| CVE-2015-7562 |
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) label value of an item or (2) name of a role.
|
| CVE-2015-7536 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and
LTS before 1.625.2 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors related to
workspaces and archived artifacts.
|
| CVE-2015-7520 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1)
RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket
1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow
remote attackers to inject arbitrary web script or HTML via a crafted
"value" attribute in a <input> element.
|
| CVE-2015-7518 |
Multiple cross-site scripting (XSS) vulnerabilities in information
popups in Foreman before 1.10.0 allow remote attackers to inject
arbitrary web script or HTML via (1) global parameters, (2) smart
class parameters, or (3) smart variables in the (a) host or (b)
hostgroup edit forms.
|
| CVE-2015-7492 |
Cross-site scripting (XSS) vulnerability in Reference Data Management
(RDM) in IBM InfoSphere Master Data Management 10.1, 11.0 before FP5,
11.3, 11.4, and 11.5 before FP1 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-7491 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x
before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2015-7467 |
Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz
Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0
before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-7465 |
Cross-site request forgery (CSRF) vulnerability in Lifecycle Query
Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before
6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack
the authentication of arbitrary users for requests that insert XSS
sequences.
|
| CVE-2015-7457 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x
before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-7451 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and
Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before
7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-7446 |
Cross-site request forgery (CSRF) vulnerability in IBM Flash System
V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4
allows remote attackers to hijack the authentication of arbitrary
users for requests that insert XSS sequences.
|
| CVE-2015-7439 |
Cross-site scripting (XSS) vulnerability in InfoSphere Data Architect
(IDA), as distributed in IBM Rational Software Architect 8.5 through
9.5, Rational Software Architect for WebSphere Software (RSA4WS) 8.5
through 9.5, and Rational Software Architect RealTime (RSART) 8.5
through 9.5, allows remote attackers to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2015-7431 |
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM
Sterling B2B Integrator 5.2 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-7417 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application
Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before
8.5.5.9 allows remote authenticated users to inject arbitrary web
script or HTML via crafted data from an OAuth provider.
|
| CVE-2015-7415 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode
Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2
allow remote authenticated users to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2015-7414 |
Cross-site scripting (XSS) vulnerability in the GDS component in IBM
InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1,
11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before
11.4.0.4 IF1 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2015-7413 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0
before 8.0.0.1 CF19 and 8.5.0 through CF08 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-7409 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM
7.2.x before 7.2.6 allows remote authenticated users to inject
arbitrary web script or HTML via an unspecified field.
|
| CVE-2015-7407 |
Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in
IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the
authentication of arbitrary users for requests that insert XSS
sequences.
|
| CVE-2015-7402 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program
Management 6.1 before 6.1.1.1 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-7398 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract
Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before
10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before
10.0.4.0 iFix3 allows remote authenticated users to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2015-7391 |
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before
1.9.14 allow remote attackers to inject arbitrary web script or HTML
via the (1) selected_end_date or (2) selected_start_date parameter to
lib/results/tcCreatedPerUserOnTestProject.php; the (3) containerType
parameter to lib/testcases/containerEdit.php; the (4) filter_tc_id or
(5) filter_testcase_name parameter to lib/testcases/listTestCases.php;
the (6) useRecursion parameter to lib/testcases/tcImport.php; the (7)
targetTestCase or (8) created_by parameter to
lib/testcases/tcSearch.php; or the (9) HTTP Referer header to
third_party/user_contribution/fakeRemoteExecServer/client4fakeXMLRPCTestRunner.php.
|
| CVE-2015-7386 |
Multiple cross-site scripting (XSS) vulnerabilities in
includes/metaboxes.php in the Gallery - Photo Albums - Portfolio
plugin 1.3.47 for WordPress allow remote authenticated users to inject
arbitrary web script or HTML via the (1) Media Title or (2) Media
Subtitle fields.
|
| CVE-2015-7385 |
Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard
before 2.0.0-rev11 allows remote attackers to inject arbitrary web
script or HTML via the uid field in a PGP public key, which is not
properly handled in "Guard PGP Settings."
|
| CVE-2015-7383 |
Multiple cross-site scripting (XSS) vulnerabilities in Web Reference
Database (aka refbase) through 0.9.6 and bleeding-edge through
2015-04-28 allow remote attackers to inject arbitrary web script or
HTML via the (1) adminUserName, (2) pathToMYSQL, (3)
databaseStructureFile, or (4) pathToBibutils parameter to install.php
or the (5) adminUserName parameter to update.php.
|
| CVE-2015-7377 |
Cross-site scripting (XSS) vulnerability in
pie-register/pie-register.php in the Pie Register plugin before 2.0.19
for WordPress allows remote attackers to inject arbitrary web script
or HTML via the invitaion_code parameter in a pie-register page to the
default URI.
|
| CVE-2015-7373 |
Cross-site scripting (XSS) vulnerability in the "magic-macros" feature
in Revive Adserver before 3.2.2 allows remote attackers to inject
arbitrary web script or HTML via a GET parameter, which is not
properly handled in a banner.
|
| CVE-2015-7370 |
Multiple cross-site scripting (XSS) vulnerabilities in
open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds
plugin in Revive Adserver before 3.2.2 and CA Release Automation
(formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1
before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before
6.1.0-1026, allow remote attackers to inject arbitrary web script or
HTML via the (1) id or (2) data-file parameter.
|
| CVE-2015-7365 |
Cross-site scripting (XSS) vulnerability in the plugin upgrade form in
Revive Adserver before 3.2.2 allows remote attackers to inject
arbitrary web script or HTML via the filename of an uploaded file
containing errors.
|
| CVE-2015-7363 |
Cross-site scripting (XSS) vulnerability in the advanced settings page
in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in
hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13
and 5.2.x before 5.2.3 allows remote administrators to inject
arbitrary web script or HTML via vectors related to report filters.
|
| CVE-2015-7360 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web User
Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote
attackers to inject arbitrary web script or HTML via the (1) serial
parameter to alerts/summary/profile/; the (2) urlForCreatingReport
parameter to csearch/report/export/; the (3) id parameter to
analysis/detail/download/screenshot; or vectors related to (4)
"Fortiview threats by users search filtered by vdom" or (5) "PCAP file
download generated by the VM scan feature."
|
| CVE-2015-7357 |
Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design)
theme 2.3.0 before 2.7.10 for WordPress allows remote attackers to
inject arbitrary web script or HTML via a fragment identifier, as
demonstrated by #<svg onload=alert(1)>.
|
| CVE-2015-7349 |
Cross-site scripting (XSS) vulnerability in the sample feedback.inc
file in VASCO DIGIPASS authentication plug-in for Citrix Web Interface
allows remote attackers to inject arbitrary web script or HTML via the
failmessage parameter.
|
| CVE-2015-7348 |
Cross-site scripting (XSS) vulnerability in zTree 3.5.19.1 and
possibly earlier allows remote attackers to inject arbitrary web
script or HTML via the id parameter to
demo/en/asyncData/getNodesForBigData.php.
|
| CVE-2015-7347 |
Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages
Content Management System 1.1.
|
| CVE-2015-7324 |
Multiple cross-site scripting (XSS) vulnerabilities in
helpers/comment.php in the StackIdeas Komento (com_komento) component
before 2.0.5 for Joomla! allow remote attackers to inject arbitrary
web script or HTML via the (1) img or (2) url tag of a new comment.
|
| CVE-2015-7320 |
Multiple cross-site scripting (XSS) vulnerabilities in
cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment
Booking Calendar plugin before 1.1.8 for WordPress allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-7316 |
Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6,
4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x
before 4.3.7, and 5.0rc1.
|
| CVE-2015-7307 |
Cross-site scripting (XSS) vulnerability in the CMS Updater module
7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors involving the
configuration page.
|
| CVE-2015-7304 |
Cross-site scripting (XSS) vulnerability in the amoCRM module 7.x-1.x
before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary
web script or HTML via unspecified HTTP POST data.
|
| CVE-2015-7290 |
Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web
management interface on Arris DG860A, TG862A, and TG862G devices with
firmware TS0703128_100611 through TS0705125D_031115 allows remote
attackers to inject arbitrary web script or HTML via the pwd
parameter.
|
| CVE-2015-7275 |
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8
before 2.30.30.30 has XSS.
|
| CVE-2015-7252 |
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE
ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote
attackers to inject arbitrary web script or HTML via the errorpage
parameter.
|
| CVE-2015-7242 |
Cross-site scripting (XSS) vulnerability in the Push-Service-Mails
feature in AVM FRITZ!OS before 6.30 allows remote attackers to inject
arbitrary web script or HTML via the display name in the FROM field of
an SIP INVITE message.
|
| CVE-2015-7232 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the
OSF Ontology module is enabled, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-7223 |
The WebExtension APIs in Mozilla Firefox before 43.0 allow remote
attackers to gain privileges, and possibly obtain sensitive
information or conduct cross-site scripting (XSS) attacks, via a
crafted web site.
|
| CVE-2015-7191 |
Mozilla Firefox before 42.0 on Android improperly restricts URL
strings in intents, which allows attackers to conduct cross-site
scripting (XSS) attacks via vectors involving an intent: URL and
fallback navigation, aka "Universal XSS (UXSS)."
|
| CVE-2015-7188 |
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow
remote attackers to bypass the Same Origin Policy for an IP address
origin, and conduct cross-site scripting (XSS) attacks, by appending
whitespace characters to an IP address string.
|
| CVE-2015-7187 |
The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script:
false" panel setting, which makes it easier for remote attackers to
conduct cross-site scripting (XSS) attacks via inline JavaScript code
that is executed within a third-party extension.
|
| CVE-2015-6972 |
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime
Openfire 3.10.2 allow remote attackers to inject arbitrary web script
or HTML via the (1) groupchatName parameter to
plugins/clientcontrol/create-bookmark.jsp; the (2) urlName parameter
to plugins/clientcontrol/create-bookmark.jsp; the (3) hostname
parameter to server-session-details.jsp; or the (4) search parameter
to group-summary.jsp.
|
| CVE-2015-6969 |
Cross-site scripting (XSS) vulnerability in js/2k11.min.js in the 2k11
theme in Serendipity before 2.0.2 allows remote attackers to inject
arbitrary web script or HTML via a user name in a comment, which is
not properly handled in a Reply link.
|
| CVE-2015-6966 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
Nibbleblog before 4.0.5 allow remote attackers to hijack the
authentication of administrators for requests that (1) create a post
via a new_simple action to admin.php or (2) conduct cross-site
scripting (XSS) attacks via the content parameter in a new_simple
action to admin.php.
|
| CVE-2015-6965 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Contact Form Generator plugin 2.0.1 and earlier for WordPress allow
remote attackers to hijack the authentication of administrators for
requests that (1) create a field, (2) update a field, (3) delete a
field, (4) create a form, (5) update a form, (6) delete a form, (7)
create a template, (8) update a template, (9) delete a template, or
(10) conduct cross-site scripting (XSS) attacks via a crafted request
to the cfg_forms page in wp-admin/admin.php.
|
| CVE-2015-6959 |
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
|
| CVE-2015-6945 |
Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador
Web 1 allows remote attackers to inject arbitrary web script or HTML
via the bd parameter to sys/sys/listaBD2.jsp.
|
| CVE-2015-6944 |
Cross-site request forgery (CSRF) vulnerability in JSP/MySQL
Administrador Web 1 allows remote attackers to hijack the
authentication of users for requests that execute arbitrary SQL
commands via the cmd parameter to sys/sys/listaBD2.jsp.
|
| CVE-2015-6942 |
Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows
remote attackers to inject arbitrary web script or HTML via a
hyperlink in a document attachment.
|
| CVE-2015-6939 |
Cross-site scripting (XSS) vulnerability in the login module in
Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2015-6938 |
Cross-site scripting (XSS) vulnerability in the file browser in
notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter
Notebook 4.0.x before 4.0.5 allows remote attackers to inject
arbitrary web script or HTML via a folder name. NOTE: this was
originally reported as a cross-site request forgery (CSRF)
vulnerability, but this may be inaccurate.
|
| CVE-2015-6931 |
Cross-site scripting (XSS) vulnerability in the vSphere Web Client in
VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before
U2d allows remote attackers to inject arbitrary web script or HTML via
a crafted URL.
|
| CVE-2015-6929 |
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks
(formerly Nokia Solutions and Networks and Nokia Siemens Networks)
@vantage Commander allow remote attackers to inject arbitrary web
script or HTML via the (1) idFilter or (2) nameFilter parameter to
cftraces/filter/fl_copy.jsp; the (3) flName parameter to
cftraces/filter/fl_crea1.jsp; the (4) serchStatus, (5) refreshTime, or
(6) serchNode parameter to cftraces/process/pr_show_process.jsp; the
(7) MaxActivationTime, (8) NumberOfBytes, (9) NumberOfTracefiles, (10)
SessionName, or (11) serchSessionkind parameter to
cftraces/session/se_crea.jsp; the (12) serchSessionDescription
parameter to cftraces/session/se_show.jsp; the (13) serchApplication
or (14) serchApplicationkind parameter to
cftraces/session/tr_crea_filter.jsp; the (15) columKeyUnique, (16)
columParameter, (17) componentName, (18) criteria1, (19) criteria2,
(20) criteria3, (21) description, (22) filter, (23) id, (24) pathName,
(25) tableName, or (26) component parameter to
cftraces/session/tr_create_tagg_para.jsp; or the (27) userid parameter
to home/certificate_association.jsp.
|
| CVE-2015-6921 |
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab
module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators
with the "Configure Zendesk Feedback Tab" permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-6920 |
Cross-site scripting (XSS) vulnerability in js/window.php in the
sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the wpbase parameter.
|
| CVE-2015-6919 |
Cross-site scripting (XSS) vulnerability in the googleSearch (CSE)
(com_googlesearch_cse) component 3.0.2 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via the q parameter
to index.php.
|
| CVE-2015-6913 |
Cross-site scripting (XSS) vulnerability in the "Create download task
via URL" feature in Synology Download Station before 3.5-2967 allows
remote attackers to inject arbitrary web script or HTML via the urls
parameter in an add_url_task action to dlm/downloadman.cgi.
|
| CVE-2015-6909 |
Cross-site scripting (XSS) vulnerability in the "Create download task
via file upload" feature in Synology Download Station before 3.5-2962
allows remote attackers to inject arbitrary web script or HTML via the
name element in the Info dictionary in a torrent file.
|
| CVE-2015-6844 |
Cross-site scripting (XSS) vulnerability in Reviewer in EMC SourceOne
Email Supervisor before 7.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-6810 |
Cross-site scripting (XSS) vulnerability in Invision Power Services
IPS Community Suite (aka Invision Power Board, IPB, or Power Board)
4.x before 4.0.12.1 allows remote authenticated users to inject
arbitrary web script or HTML via the event_location[address] array
parameter to calendar/submit/.
|
| CVE-2015-6809 |
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before
3.6.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) cfg[projectName] parameter to index.php/admin/saveConfig,
the (2) data[stats_provider_url] parameter to
index.php/areas/saveArea, or the (3) data[description] parameter to
index.php/areas/saveSection.
|
| CVE-2015-6808 |
Cross-site scripting (XSS) vulnerability in the Spotlight module
7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via a
node title.
|
| CVE-2015-6807 |
Cross-site scripting (XSS) vulnerability in the Mass Contact module
6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows
remote authenticated users with the "administer mass contact"
permission to inject arbitrary web script or HTML via a category
label.
|
| CVE-2015-6805 |
Cross-site scripting (XSS) vulnerability in the MDC Private Message
plugin 1.0.0 for WordPress allows remote authenticated users to inject
arbitrary web script or HTML via the message field in a private
message.
|
| CVE-2015-6754 |
Cross-site scripting (XSS) vulnerability in the administration
interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for
Drupal allows remote authenticated users with the "Administer Path
Breadcrumbs" permission to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-6753 |
Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit
module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via an (1) entity title, related to in-place editing, or a (2) node
title.
|
| CVE-2015-6752 |
Cross-site scripting (XSS) vulnerability in the Search API
Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when the search
index is configured to use the HTML filter processor, allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via unspecified vectors, which are not properly handled
in the returned suggestions.
|
| CVE-2015-6751 |
Multiple cross-site scripting (XSS) vulnerabilities in the Time
Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via a (1) note added to a time entry or an (2) activity
used to categorize time tracker entries.
|
| CVE-2015-6748 |
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
|
| CVE-2015-6737 |
Cross-site scripting (XSS) vulnerability in the Widgets extension for
MediaWiki allows remote attackers to inject arbitrary web script or
HTML via vectors involving base64 encoded content.
|
| CVE-2015-6734 |
Cross-site scripting (XSS) vulnerability in contrib/cssgen.php in the
GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki
before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-6732 |
Multiple cross-site scripting (XSS) vulnerabilities in the
SemanticForms extension for MediaWiki allow remote attackers to inject
arbitrary web script or HTML via the (1) wpSummary parameter to
Special:FormEdit, the (2) "Template label (optional)" field in a form,
or a (3) Field name in a template.
|
| CVE-2015-6731 |
Multiple cross-site scripting (XSS) vulnerabilities in the
SemanticForms extension for MediaWiki allow remote attackers to inject
arbitrary web script or HTML via a (1) section_*, (2) template_*, (3)
label_*, or (4) new_template parameter to Special:CreateForm or (5)
target or (6) alt_form parameter to Special:FormEdit.
|
| CVE-2015-6730 |
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki
before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows
remote attackers to inject arbitrary web script or HTML via the f
parameter, which is not properly handled in an error page, related to
"ForeignAPI images."
|
| CVE-2015-6729 |
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki
before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows
remote attackers to inject arbitrary web script or HTML via the rel404
parameter, which is not properly handled in an error page.
|
| CVE-2015-6672 |
Cross-site scripting (XSS) vulnerability in the Administrative Web
Interface in Citrix NetScaler Application Delivery Controller (ADC)
and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7,
and 10.5e before Build 56.1505.e allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-6665 |
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal
7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for
Drupal allows remote attackers to inject arbitrary web script or HTML
via vectors involving a whitelisted HTML element, possibly related to
the "a" tag.
|
| CVE-2015-6663 |
Cross-site scripting (XSS) vulnerability in the Client form in the
Device Inspector page in SAP Afaria 7 allows remote attackers to
inject arbitrary web script or HTML via crafted client name data, aka
SAP Security Note 2152669.
|
| CVE-2015-6658 |
Cross-site scripting (XSS) vulnerability in the Autocomplete system in
Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL, related to
uploading files.
|
| CVE-2015-6588 |
Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX
Revolution before 1.9.1 allows remote attackers to inject arbitrary
web script or HTML via the QUERY_STRING.
|
| CVE-2015-6584 |
Cross-site scripting (XSS) vulnerability in the DataTables plugin
1.10.8 and earlier for jQuery allows remote attackers to inject
arbitrary web script or HTML via the scripts parameter to
media/unit_testing/templates/6776.php.
|
| CVE-2015-6549 |
Cross-site scripting (XSS) vulnerability in an application console in
the server in Symantec NetBackup OpsCenter before 7.7.1 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-6540 |
Cross-site scripting (XSS) vulnerability in Intellect Design Arena
Intellect Core banking software.
|
| CVE-2015-6535 |
Cross-site scripting (XSS) vulnerability in
includes/options-profiles.php in the YouTube Embed plugin before 3.3.3
for WordPress allows remote administrators to inject arbitrary web
script or HTML via the Profile name field (youtube_embed_name
parameter).
|
| CVE-2015-6530 |
Cross-site scripting (XSS) vulnerability in OpenText Secure MFT 2013
before 2013 R3 P6 and 2014 before 2014 R2 P2 allows remote attackers
to inject arbitrary web script or HTML via the querytext parameter to
userdashboard.jsp.
|
| CVE-2015-6529 |
Multiple cross-site scripting (XSS) vulnerabilities in phpipam 1.1.010
allow remote attackers to inject arbitrary web script or HTML via the
(1) section parameter to site/error.php or (2) ip parameter to
site/tools/searchResults.php.
|
| CVE-2015-6528 |
Multiple cross-site scripting (XSS) vulnerabilities in
install_classic.php in Coppermine Photo Gallery (CPG) 1.5.36 allow
remote attackers to inject arbitrary web script or HTML via the (1)
admin_username, (2) admin_password, (3) admin_email, (4) dbserver, (5)
dbname, (6) dbuser, (7) dbpass, (8) table_prefix, or (9) impath
parameter.
|
| CVE-2015-6521 |
Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS
version 2.2.
|
| CVE-2015-6518 |
Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin
1.1 allow remote attackers to inject arbitrary web script or HTML via
the (1) PATH_INFO, (2) droptable parameter, or (3) table parameter to
phpliteadmin.php.
|
| CVE-2015-6517 |
Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1
allows remote attackers to hijack the authentication of users for
requests that drop database tables via the droptable parameter to
phpliteadmin.php.
|
| CVE-2015-6515 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk
Enterprise 6.2.x before 6.2.4, 6.1.x before 6.1.8, 6.0.x before 6.0.9,
and 5.0.x before 5.0.13 and Splunk Light 6.2.x before 6.2.4 allows
remote attackers to inject arbitrary web script or HTML via a header.
|
| CVE-2015-6514 |
Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk
Enterprise 6.2.x before 6.2.4 and Splunk Light 6.2.x before 6.2.4
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-6511 |
Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3
allows remote attackers to inject arbitrary web script or HTML via the
server[] parameter to services_ntpd.php.
|
| CVE-2015-6510 |
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before
2.2.3 allow remote attackers to inject arbitrary web script or HTML
via the (1) srctrack, (2) use_mfs_tmp_size, or (3) use_mfs_var_size
parameter to system_advanced_misc.php; the (4) port, (5) snaplen, or
(6) count parameter to diag_packet_capture.php; the (7)
pppoe_resethour, (8) pppoe_resetminute, (9) wpa_group_rekey, or (10)
wpa_gmk_rekey parameter to interfaces.php; the (11) pppoe_resethour or
(12) pppoe_resetminute parameter to interfaces_ppps_edit.php; the (13)
member[] parameter to interfaces_qinq_edit.php; the (14) port or (15)
retry parameter to load_balancer_pool_edit.php; the (16) pkgrepourl
parameter to pkg_mgr_settings.php; the (17) zone parameter to
services_captiveportal.php; the port parameter to (18)
services_dnsmasq.php or (19) services_unbound.php; the (20)
cache_max_ttl or (21) cache_min_ttl parameter to
services_unbound_advanced.php; the (22) sshport parameter to
system_advanced_admin.php; the (23) id, (24) tunable, (25) descr, or
(26) value parameter to system_advanced_sysctl.php; the (27)
firmwareurl, (28) repositoryurl, or (29) branch parameter to
system_firmware_settings.php; the (30) pfsyncpeerip, (31)
synchronizetoip, (32) username, or (33) passwordfld parameter to
system_hasync.php; the (34) maxmss parameter to
vpn_ipsec_settings.php; the (35) ntp_server1, (36) ntp_server2, (37)
wins_server1, or (38) wins_server2 parameter to vpn_openvpn_csc.php;
or unspecified parameters to (39) load_balancer_relay_action.php, (40)
load_balancer_relay_action_edit.php, (41)
load_balancer_relay_protocol.php, or (42)
load_balancer_relay_protocol_edit.php.
|
| CVE-2015-6509 |
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before
2.2.3 allow remote attackers to inject arbitrary web script or HTML
via the (1) proxypass parameter to system_advanced_misc.php; (2)
adaptiveend, (3) adaptivestart, (4) maximumstates, (5)
maximumtableentries, or (6) aliasesresolveinterval parameter to
system_advanced_firewall.php; (7) proxyurl, (8) proxyuser, or (9)
proxyport parameter to system_advanced_misc.php; or (10) name, (11)
notification_name, (12) ipaddress, (13) password, (14) smtpipaddress,
(15) smtpport, (16) smtpfromaddress, (17) smtpnotifyemailaddress, (18)
smtpusername, or (19) smtppassword parameter to
system_advanced_notifications.php.
|
| CVE-2015-6508 |
Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3
allows remote attackers to inject arbitrary web script or HTML via the
descr parameter in a "new" action to system_authservers.php.
|
| CVE-2015-6506 |
Cross-site scripting (XSS) vulnerability in the cryptography interface
in Request Tracker (RT) before 4.2.12 allows remote attackers to
inject arbitrary web script or HTML via a crafted public key.
|
| CVE-2015-6502 |
Cross-site scripting (XSS) vulnerability in the console in Puppet
Enterprise before 2015.2.1 allows remote attackers to inject arbitrary
web script or HTML via the string parameter, related to Login
Redirect.
|
| CVE-2015-6494 |
Cross-site scripting (XSS) vulnerability in Infinite Automation Mango
Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-6488 |
Cross-site scripting (XSS) vulnerability in the web server on
Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400
devices before B FRN 15.003 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-6477 |
Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm
Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-6475 |
Multiple cross-site scripting (XSS) vulnerabilities in IBC Solar
ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-6466 |
Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature
in the administrative web interface on Moxa EDS-405A and EDS-408A
switches with firmware before 3.6 allows remote attackers to inject
arbitrary web script or HTML via an unspecified field.
|
| CVE-2015-6416 |
Cross-site scripting (XSS) vulnerability in Cisco Unified Email
Interaction Manager and Unified Web Interaction Manager 11.0(1) allows
remote attackers to inject arbitrary web script or HTML a crafted URL,
aka Bug ID CSCuw24479.
|
| CVE-2015-6402 |
Cross-site scripting (XSS) vulnerability in the management interface
on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows
remote attackers to inject arbitrary web script or HTML via an
unspecified value, aka Bug ID CSCux24935.
|
| CVE-2015-6400 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency
Responder 10.5(1a) allow remote attackers to inject arbitrary web
script or HTML via unspecified fields, aka Bug ID CSCuv25547.
|
| CVE-2015-6390 |
Cross-site scripting (XSS) vulnerability in the management interface
in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject
arbitrary web script or HTML via a crafted value in a URL, aka Bug ID
CSCup92741.
|
| CVE-2015-6387 |
Cross-site scripting (XSS) vulnerability in Cisco Unified Computing
System (UCS) Central Software 1.3(0.1) allows remote attackers to
inject arbitrary web script or HTML via a crafted value in a URL, aka
Bug ID CSCux33573.
|
| CVE-2015-6372 |
Cross-site scripting (XSS) vulnerability in the web-based management
interface in Cisco Firepower Extensible Operating System 1.1(1.160) on
Firepower 9000 devices allows remote attackers to inject arbitrary web
script or HTML via a crafted value, aka Bug ID CSCux10614.
|
| CVE-2015-6363 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
framework in Cisco FireSIGHT Management Center (MC) 5.4.1.4 and 6.0.1
allow remote authenticated users to inject arbitrary web script or
HTML via unspecified parameters, aka Bug ID CSCuw88396.
|
| CVE-2015-6356 |
Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco
Social Miner 10.0(1) allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, aka Bug ID CSCuw60212.
|
| CVE-2015-6354 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight
Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated
users to inject arbitrary web script or HTML via unspecified
parameters, aka Bug ID CSCuv73338.
|
| CVE-2015-6353 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight
Management Center (MC) 5.3.1.5 and 5.4.x through 5.4.1.3 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified parameters, aka Bug ID CSCuu28922.
|
| CVE-2015-6349 |
Cross-site scripting (XSS) vulnerability in the web interface in the
Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15)
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2015-6346 |
Cross-site scripting (XSS) vulnerability in Cisco Secure Access
Control Server (ACS) 5.7(0.15) allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-6337 |
Cross-site scripting (XSS) vulnerability in Cisco Application Policy
Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows
remote attackers to inject arbitrary web script or HTML via a crafted
hostname in an SNMP response, aka Bug ID CSCuw47238.
|
| CVE-2015-6255 |
Cross-site scripting (XSS) vulnerability in Cisco Unified Web and
E-Mail Interaction Manager 9.0(2) allows remote attackers to inject
arbitrary web script or HTML via a crafted chat message, aka Bug ID
CSCuo89051.
|
| CVE-2015-6238 |
Multiple cross-site scripting (XSS) vulnerabilities in the Google
Analyticator plugin before 6.4.9.6 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1)
ga_adsense, (2) ga_admin_disable_DimentionIndex, (3)
ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix
parameter in the google-analyticator page to wp-admin/admin.php.
|
| CVE-2015-6176 |
Microsoft Edge mishandles HTML attributes in HTTP responses, which
allows remote attackers to bypass a cross-site scripting (XSS)
protection mechanism via unspecified vectors, aka "Microsoft Edge XSS
Filter Bypass Vulnerability."
|
| CVE-2015-6164 |
Microsoft Internet Explorer 9 through 11 improperly implements a
cross-site scripting (XSS) protection mechanism, which allows remote
attackers to bypass the Same Origin Policy via a crafted web site, aka
"Internet Explorer XSS Filter Bypass Vulnerability."
|
| CVE-2015-6144 |
Microsoft Internet Explorer 8 through 11 and Microsoft Edge mishandle
HTML attributes in HTTP responses, which allows remote attackers to
bypass a cross-site scripting (XSS) protection mechanism via
unspecified vectors, aka "Microsoft Browser XSS Filter Bypass
Vulnerability."
|
| CVE-2015-6138 |
Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in
HTTP responses, which allows remote attackers to bypass a cross-site
scripting (XSS) protection mechanism via unspecified vectors, aka
"Internet Explorer XSS Filter Bypass Vulnerability."
|
| CVE-2015-6123 |
Cross-site scripting (XSS) vulnerability in Microsoft Excel for Mac
2011 and Excel 2016 for Mac allows remote attackers to inject
arbitrary web script or HTML via a crafted e-mail message that is
mishandled by Outlook for Mac, aka "Microsoft Outlook for Mac Spoofing
Vulnerability."
|
| CVE-2015-6117 |
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013
SP1 allow remote authenticated users to bypass intended Access Control
Policy restrictions and conduct cross-site scripting (XSS) attacks by
modifying a webpart, aka "Microsoft SharePoint Security Feature
Bypass," a different vulnerability than CVE-2016-0011.
|
| CVE-2015-6099 |
Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET
Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to
inject arbitrary web script or HTML via a crafted value, aka ".NET
Elevation of Privilege Vulnerability."
|
| CVE-2015-6061 |
Cross-site scripting (XSS) vulnerability in Microsoft Skype for
Business 2016, Lync 2010 and 2013 SP1, Lync 2010 Attendee, and Lync
Room System allows remote attackers to inject arbitrary web script or
HTML via an instant-message session, aka "Server Input Validation
Information Disclosure Vulnerability."
|
| CVE-2015-6058 |
Microsoft Edge mishandles HTML attributes in HTTP responses, which
allows remote attackers to bypass a cross-site scripting (XSS)
protection mechanism via unspecified vectors, aka "Microsoft Edge XSS
Filter Bypass."
|
| CVE-2015-6039 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Server 2013 SP1 and SharePoint Foundation 2013 SP1 allows remote
authenticated users to inject arbitrary web script or HTML via crafted
content in an Office Marketplace instance, aka "Microsoft SharePoint
Security Feature Bypass Vulnerability."
|
| CVE-2015-6037 |
Cross-site scripting (XSS) vulnerability in Microsoft Excel Services
on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2,
Excel Web App 2010 SP2, Office Web Apps Server 2013 SP1, and
SharePoint Foundation 2013 SP1 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL, aka "Microsoft
Office Web Apps XSS Spoofing Vulnerability."
|
| CVE-2015-6035 |
Opsview before 2015-11-06 has XSS via SNMP.
|
| CVE-2015-6027 |
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
|
| CVE-2015-6021 |
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
|
| CVE-2015-6017 |
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1
on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow
remote attackers to inject arbitrary web script or HTML via the (1)
LoginPassword or (2) hiddenPassword parameter.
|
| CVE-2015-6010 |
Multiple cross-site scripting (XSS) vulnerabilities in Web Reference
Database (aka refbase) through 0.9.6 and bleeding-edge before
2015-01-08 allow remote attackers to inject arbitrary web script or
HTML via the (1) errorNo or (2) errorMsg parameter to error.php; the
(3) viewType parameter to duplicate_manager.php; the (4) queryAction,
(5) displayType, (6) citeOrder, (7) sqlQuery, (8) showQuery, (9)
showLinks, (10) showRows, or (11) queryID parameter to
query_manager.php; the (12) sourceText or (13) sourceIDs parameter to
import.php; or the (14) typeName or (15) fileName parameter to
modify.php.
|
| CVE-2015-6005 |
Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch
WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary
web script or HTML via (1) an SNMP OID object, (2) an SNMP trap
message, (3) the View Names field, (4) the Group Names field, (5) the
Flow Monitor Credentials field, (6) the Flow Monitor Threshold Name
field, (7) the Task Library Name field, (8) the Task Library
Description field, (9) the Policy Library Name field, (10) the Policy
Library Description field, (11) the Template Library Name field, (12)
the Template Library Description field, (13) the System Script Library
Name field, (14) the System Script Library Description field, or (15)
the CLI Settings Library Description field.
|
| CVE-2015-5992 |
Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on
Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with
firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows
remote attackers to inject arbitrary web script or HTML via the ssid
parameter.
|
| CVE-2015-5968 |
Cross-site scripting (XSS) vulnerability in Novell Filr 1.2 before Hot
Patch 4 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL.
|
| CVE-2015-5956 |
The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before
7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass
the XSS filter and conduct cross-site scripting (XSS) attacks via a
base64 encoded data URI, as demonstrated by the (1) returnUrl
parameter to show_rechis.php and the (2) redirect_url parameter to
index.php.
|
| CVE-2015-5953 |
Cross-site scripting (XSS) vulnerability in the activity application
in ownCloud Server before 7.0.5 and 8.0.x before 8.0.4 allows remote
authenticated users to inject arbitrary web script or HTML via a "
(double quote) character in a filename in a shared folder.
|
| CVE-2015-5875 |
Cross-site scripting (XSS) vulnerability in Notes in Apple OS X before
10.11 allows local users to inject arbitrary web script or HTML via
crafted text.
|
| CVE-2015-5734 |
Cross-site scripting (XSS) vulnerability in the legacy theme preview
implementation in wp-includes/theme.php in WordPress before 4.2.4
allows remote attackers to inject arbitrary web script or HTML via a
crafted string.
|
| CVE-2015-5733 |
Cross-site scripting (XSS) vulnerability in the
refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js
in WordPress before 4.2.4 allows remote attackers to inject arbitrary
web script or HTML via an accessibility-helper title.
|
| CVE-2015-5732 |
Cross-site scripting (XSS) vulnerability in the form function in the
WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in
WordPress before 4.2.4 allows remote attackers to inject arbitrary web
script or HTML via a widget title.
|
| CVE-2015-5720 |
Multiple cross-site scripting (XSS) vulnerabilities in the
template-creation feature in Malware Information Sharing Platform
(MISP) before 2.3.90 allow remote attackers to inject arbitrary web
script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and
(3) ajaxification.js.
|
| CVE-2015-5714 |
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1
allows remote attackers to inject arbitrary web script or HTML by
leveraging the mishandling of unclosed HTML elements during processing
of shortcode tags.
|
| CVE-2015-5691 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in
the management console on Symantec Web Gateway (SWG) appliances with
software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors, as demonstrated
an attack against admin_messages.php.
|
| CVE-2015-5670 |
Cross-site scripting (XSS) vulnerability in Techno Project Japan
Enisys Gw before 1.4.1 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5667 |
Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module
before 0.15 for Perl, when the comment feature is enabled, allows
remote attackers to inject arbitrary web script or HTML via a crafted
comment.
|
| CVE-2015-5664 |
Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS
before 4.2.0 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-5654 |
Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-5651 |
Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-5630 |
Cross-site scripting (XSS) vulnerability in the NTT Broadband Platform
Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android
and 1.0.2 and earlier for iOS allows remote attackers to inject
arbitrary web script or HTML via a crafted SSID.
|
| CVE-2015-5625 |
Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4
allows remote attackers to inject arbitrary web script or HTML via the
redirection parameter.
|
| CVE-2015-5622 |
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3
allows remote authenticated users to inject arbitrary web script or
HTML by leveraging the Author or Contributor role to place a crafted
shortcode inside an HTML element, related to wp-includes/kses.php and
wp-includes/shortcodes.php.
|
| CVE-2015-5613 |
Cross-site scripting (XSS) vulnerability in October CMS build 271 and
earlier allows remote attackers to inject arbitrary web script or HTML
via vectors involving a file title, a different vulnerability than
CVE-2015-5612.
|
| CVE-2015-5612 |
Cross-site scripting (XSS) vulnerability in October CMS build 271 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the caption tag of a profile image.
|
| CVE-2015-5594 |
The sanitize_string function in ZenPhoto before 1.4.9 utilized the
html_entity_decode function after input sanitation, which might allow
remote attackers to perform a cross-site scripting (XSS) via a crafted
string.
|
| CVE-2015-5535 |
Cross-site scripting (XSS) vulnerability in the qTranslate plugin
2.5.39 and earlier for WordPress allows remote attackers to inject
arbitrary web script or HTML via the edit parameter in the qtranslate
page to wp-admin/options-general.php.
|
| CVE-2015-5534 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall
before 1.8 allow remote attackers to hijack the authentication of
administrators for requests that (1) put the website under maintenance
via the maintenance_enable parameter or (2) conduct cross-site
scripting (XSS) attacks via the maintenance_text parameter to
admin/pages/maintenance.
|
| CVE-2015-5532 |
Multiple cross-site scripting (XSS) vulnerabilities in the Paid
Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow
remote attackers to inject arbitrary web script or HTML via the (1) s
parameter to membershiplevels.php, (2) memberslist.php, or (3)
orders.php in adminpages/ or the (4) edit parameter to
adminpages/membershiplevels.php.
|
| CVE-2015-5529 |
Multiple cross-site scripting (XSS) vulnerabilities in Free
Reprintables ArticleFR 3.0.6 allow remote attackers to inject
arbitrary web script or HTML via the (1) name parameter to
dashboard/settings/categories/, (2) title or (3) rel parameter to
dashboard/settings/links/, or (4) url parameter to
dashboard/tools/pingservers/.
|
| CVE-2015-5528 |
Cross-site scripting (XSS) vulnerability in the save_order function in
class-floating-social-bar.php in the Floating Social Bar plugin before
1.1.6 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the items[] parameter in an fsb_save_order action
to wp-admin/admin-ajax.php.
|
| CVE-2015-5521 |
Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows
remote attackers to inject arbitrary web script or HTML via the name
in a new group to backend/groups/index.php.
|
| CVE-2015-5520 |
Cross-site scripting (XSS) vulnerability in the Users module in
Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote
attackers to inject arbitrary web script or HTML via the username when
creating a new user account, which is not properly handled when
deleting an account.
|
| CVE-2015-5519 |
Cross-site scripting (XSS) vulnerability in the applyConvolution demo
in WideImage 11.02.19 allows remote attackers to inject arbitrary web
script or HTML via the matrix parameter to demo/index.php.
|
| CVE-2015-5514 |
Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x
before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled,
allows user-assisted remote attackers to inject arbitrary web script
or HTML via a destination field label.
|
| CVE-2015-5513 |
Cross-site scripting (XSS) vulnerability in the Shibboleth
authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before
7.x-4.2 for Drupal allows remote authenticated users with the
"Administer blocks" permission to inject arbitrary web script or HTML
via unspecified vectors related to a login link.
|
| CVE-2015-5507 |
Cross-site scripting (XSS) vulnerability in the Inline Entity Form
module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated
users with permission to create or edit fields to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5500 |
Cross-site scripting (XSS) vulnerability in the Navigate module for
Drupal allows remote authenticated users with certain permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-5497 |
Cross-site scripting (XSS) vulnerability in the Web Links module
6.x-2.x before 6.x-2.6 and 7.x-1.x before 7.x-1.0 for Drupal allows
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-5495 |
Cross-site scripting (XSS) vulnerability in the Mobile sliding menu
module 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated
users with the "administer menu" permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5494 |
Cross-site scripting (XSS) vulnerability in the Webform Matrix
Component module 7.x-4.x before 7.x-4.13 for Drupal allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5492 |
Cross-site scripting (XSS) vulnerability in the Video Consultation
module for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5489 |
Cross-site scripting (XSS) vulnerability in the Smart Trim module
7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
vectors involving the field settings form.
|
| CVE-2015-5488 |
Cross-site scripting (XSS) vulnerability in the MailChimp Signup
submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal
allows remote authenticated users with the "administer mailchimp"
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-5487 |
Cross-site scripting (XSS) vulnerability in the Camtasia Relay module
6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows
remote authenticated users with the "view meta information" permission
to inject arbitrary web script or HTML via unspecified vectors related
to the meta access tab.
|
| CVE-2015-5485 |
Cross-site scripting (XSS) vulnerability in the Event Import page
(import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets
plugin before 3.10.2 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the "error" parameter to
wp-admin/edit.php.
|
| CVE-2015-5481 |
Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD
bbPress Attachments plugin before 2.3 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the tab parameter
in the gdbbpress_attachments page to wp-admin/edit.php.
|
| CVE-2015-5475 |
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker
(RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web
script or HTML via vectors related to the (1) user and (2) group
rights management pages.
|
| CVE-2015-5460 |
Cross-site scripting (XSS) vulnerability in
app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote
attackers to inject arbitrary web script or HTML via the title
(cls.name variable) when creating a classification.
|
| CVE-2015-5458 |
Session fixation vulnerability in fileupload.php in PivotX before
2.3.11 allows remote attackers to hijack web sessions via the sess
parameter.
|
| CVE-2015-5457 |
PivotX before 2.3.11 does not validate the new file extension when
renaming a file with multiple extensions, which allows remote
attackers to execute arbitrary code by uploading a crafted file, as
demonstrated by a file named foo.php.php.
|
| CVE-2015-5456 |
Cross-site scripting (XSS) vulnerability in the form method in
modules/formclass.php in PivotX before 2.3.11 allows remote attackers
to inject arbitrary web script or HTML via the PATH_INFO, related to
the "PHP_SELF" variable and form actions.
|
| CVE-2015-5455 |
Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors to install/.
|
| CVE-2015-5454 |
Cross-site scripting (XSS) vulnerability in Nucleus CMS 3.65 allows
remote attackers to inject arbitrary web script or HTML via the title
parameter when adding a new item.
|
| CVE-2015-5447 |
Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system
software before 3.13.1 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-5444 |
Multiple cross-site scripting (XSS) vulnerabilities in HP Smart
Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-5441 |
Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight
Management Center before 2.1 and ArcSight Logger before 6.1 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-5399 |
Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows
remote authenticated users to inject arbitrary web script or HTML via
a comment.
|
| CVE-2015-5381 |
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php
in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to
inject arbitrary web script or HTML via the _mbox parameter to the
default URI.
|
| CVE-2015-5379 |
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax
WebMail interface in AXIGEN Mail Server before 9.0 allows remote
attackers to inject arbitrary web script or HTML via an email
attachment.
|
| CVE-2015-5375 |
Cross-site scripting (XSS) vulnerability in unspecified dialogs for
printing content in the Front End in Open-Xchange Server 6 and OX App
Suite before 6.22.8-rev8, 6.22.9 before 6.22.9-rev15m, 7.x before
7.6.1-rev25, and 7.6.2 before 7.6.2-rev20 allows remote attackers to
inject arbitrary web script or HTML via unknown vectors related to
object properties.
|
| CVE-2015-5365 |
Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows
remote authenticated users to inject arbitrary web script or HTML via
the "What's going on?" profile field.
|
| CVE-2015-5356 |
Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in
GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary
web script or HTML via the func parameter.
|
| CVE-2015-5355 |
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS
before 3.3.6 allow remote attackers to inject arbitrary web script or
HTML via the (1) post-content or (2) post-title parameter to
admin/edit.php.
|
| CVE-2015-5354 |
Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote
attackers to redirect users to arbitrary web sites and conduct
phishing attacks via a URL in the redirect parameter to
admin/nos/login.
|
| CVE-2015-5353 |
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows
remote attackers to include and execute arbitrary local files via a ..
(dot dot) in the tab parameter to admin/.
|
| CVE-2015-5347 |
Cross-site scripting (XSS) vulnerability in the
getWindowOpenJavaScript function in
org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in
Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before
7.2.0 might allow remote attackers to inject arbitrary web script or
HTML via a ModalWindow title.
|
| CVE-2015-5337 |
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and
2.9.x before 2.9.3 does not properly restrict the availability of
Flowplayer, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via a crafted .swf file.
|
| CVE-2015-5336 |
Multiple cross-site scripting (XSS) vulnerabilities in the survey
module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before
2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to
inject arbitrary web script or HTML by leveraging the student role and
entering a crafted survey answer.
|
| CVE-2015-5326 |
Cross-site scripting (XSS) vulnerability in the slave overview page in
Jenkins before 1.638 and LTS before 1.625.2 allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via the slave offline status message.
|
| CVE-2015-5282 |
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
|
| CVE-2015-5269 |
Cross-site scripting (XSS) vulnerability in group/overview.php in
Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and
2.9.x before 2.9.2 allows remote authenticated users to inject
arbitrary web script or HTML via a modified grouping description.
|
| CVE-2015-5169 |
Cross-site scripting (XSS) vulnerability in Apache Struts before
2.3.20.
|
| CVE-2015-5151 |
Cross-site scripting (XSS) vulnerability in the Slider Revolution
(revslider) plugin 4.2.2 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the client_action parameter in
a revslider_ajax_action action to wp-admin/admin-ajax.php.
|
| CVE-2015-5150 |
Multiple cross-site scripting (XSS) vulnerabilities in Zoho
ManageEngine SupportCenter Plus 7.90 allow remote authenticated users
to inject arbitrary web script or HTML via the (1) query parameter in
the run_query_editor_query module to CustomReportHandler.do, (2)
compAcct parameter to jsp/ResetADPwd.jsp, or (3) redirectTo parameter
to jsp/CacheScreenWidth.jsp.
|
| CVE-2015-5076 |
Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM
before 5.0.9 allow remote attackers to inject arbitrary web script or
HTML via the (1) version parameter in
protected/views/admin/formEditor.php; the (2) importId parameter in
protected/views/admin/rollbackImport.php; the (3) bc, (4) fg, (5) bgc,
or (6) font parameter in protected/views/site/listener.php; the (7)
Services[*] parameter in protected/components/views/webForm.php; the
(8) file parameter in protected/components/TranslationManager.php; the
(9) x2_key parameter in
protected/tests/webscripts/x2WebTrackingTestPages/customWebLeadCaptureScriptTest.php;
the (10) id parameter in
protected/modules/contacts/controllers/ContactsController.php; or the
(11) lastEventId parameter to index.php/profile/getEvents.
|
| CVE-2015-5066 |
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix
GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script
or HTML via the (1) content or (2) title field in an add action in the
posts page to index.php or the (3) q parameter in the posts page to
index.php.
|
| CVE-2015-5064 |
Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite
Administrator (mysql-lite-administrator) beta-1 allow remote attackers
to inject arbitrary web script or HTML via the table_name parameter to
(1) tabella.php, (2) coloni.php, or (3) insert.php or (4) num_row
parameter to coloni.php.
|
| CVE-2015-5063 |
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe
CMS & Framework 3.1.13 allow remote attackers to inject arbitrary web
script or HTML via the (1) admin_username or (2) admin_password
parameter to install.php.
|
| CVE-2015-5062 |
Open redirect vulnerability in SilverStripe CMS & Framework 3.1.13
allows remote attackers to redirect users to arbitrary web sites and
conduct phishing attacks via a URL in the returnURL parameter to
dev/build.
|
| CVE-2015-5061 |
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine
AssetExplorer 6.1 service pack 6112 and earlier allows remote
authenticated users with permissions to add new vendors to inject
arbitrary web script or HTML via the organizationName parameter to
VendorDef.do.
|
| CVE-2015-5060 |
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
|
| CVE-2015-5057 |
Cross-site scripting (XSS) vulnerability exists in the Wordpress admin
panel when the Broken Link Checker plugin before 1.10.9 is installed.
|
| CVE-2015-5050 |
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris
Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and
10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and
10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to
hijack the authentication of arbitrary users for requests that insert
XSS sequences.
|
| CVE-2015-5037 |
Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x
before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3
allows remote authenticated users to hijack the authentication of
arbitrary users for requests that insert XSS sequences.
|
| CVE-2015-5036 |
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before
3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted URL, a different vulnerability than CVE-2015-5035.
|
| CVE-2015-5035 |
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before
3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted URL, a different vulnerability than CVE-2015-5036.
|
| CVE-2015-5009 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0
through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5
through 8, and 8.0 before 8.0.0.1 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-5008 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0
through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5
through 8, and 8.0 before 8.0.0.1 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-5007 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere
Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature
Pack 8 allows remote authenticated users to hijack the authentication
of arbitrary users for requests that insert XSS sequences.
|
| CVE-2015-5002 |
Cross-site scripting (XSS) vulnerability in IBM Host On-Demand 11.0
through 11.0.14 allows remote attackers to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2015-4998 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0
through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through
7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, a different vulnerability than CVE-2015-4993.
|
| CVE-2015-4993 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0
through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through
7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, a different vulnerability than CVE-2015-4998.
|
| CVE-2015-4973 |
Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise
Integration Gateway 1.x through 1.0.0.1 and B2B Advanced
Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-4971 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Strategic
Supply Management Platform and Emptoris Program Management 10.x before
10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before
10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2015-4959 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated
Identity Manager (TFIM) 6.2.2 before FP16 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-4957 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security
QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-4955 |
Cross-site scripting (XSS) vulnerability in IBM Business Process
Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5
through 8.5.5.0, and 8.5.6 before 8.5.6.0 CF1 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2015-4944 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX003, and
7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before
7.5.0.8 IFIX003 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud
Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2
for Tivoli IT Asset Management for IT and certain other products
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2015-4939 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier
Lifecycle Management and Emptoris Program Management 10.x before
10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before
10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote attackers
to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-4854 |
Unspecified vulnerability in the Oracle Application Object Library
component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and
12.2.4 allows remote attackers to affect integrity via unknown vectors
related to Single Signon. NOTE: the previous information is from the
October 2015 CPU. Oracle has not commented on third-party claims that
this issue is a cross-site scripting (XSS) vulnerability, which allows
remote attackers to inject arbitrary web script or HTML via the Domain
parameter in the CfgOCIReturn servlet.
|
| CVE-2015-4725 |
Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare
2.0.2 allows remote attackers to inject arbitrary web script or HTML
via the email parameter.
|
| CVE-2015-4721 |
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5
5.7.3.1.
|
| CVE-2015-4714 |
Cross-site scripting (XSS) vulnerability in the DreamBox DM500-S
allows remote attackers to inject arbitrary web script or HTML via the
mode parameter to /body.
|
| CVE-2015-4707 |
Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows
remote attackers to inject arbitrary web script or HTML via vectors
involving JSON error messages and the /api/notebooks path.
|
| CVE-2015-4706 |
Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2
allows remote attackers to inject arbitrary web script or HTML via
vectors involving JSON error messages and the /api/contents path.
|
| CVE-2015-4699 |
Cross-site scripting (XSS) vulnerability in the Splash Portal in
Cloud4Wi before 5.9.7 allows remote attackers to inject arbitrary web
script or HTML via the recoveryMessage parameter to the default URI.
|
| CVE-2015-4687 |
Cross-site scripting (XSS) vulnerability in Ellucian (formerly
SunGard) Banner Student 8.5.1.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4679 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface in Airties RT-210 allow remote attackers to inject arbitrary
web script or HTML via the (1) ddns_domainame or (2) ddns_account
parameter to ddns.stm.
|
| CVE-2015-4673 |
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket
2.7.0.5 allow remote authenticated users to inject arbitrary web
script or HTML via (1) the collection_description parameter to
upload/manage_collections.php in an add_new action or the (2)
photo_description, (3) photo_tags, or (4) photo_title parameter to
upload/actions/photo_uploader.php.
|
| CVE-2015-4671 |
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2
allows remote attackers to inject arbitrary web script or HTML via the
zone_id parameter to index.php.
|
| CVE-2015-4665 |
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium
Xsuite 2.3.0 and 2.4.3.0 allows remote attackers to inject arbitrary
web script or HTML via the fileName parameter.
|
| CVE-2015-4661 |
Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows
remote attackers to inject arbitrary web script or HTML via the sort
parameter to system/authors.
|
| CVE-2015-4660 |
Cross-site scripting (XSS) vulnerability in Enhanced SQL Portal
5.0.7961 allows remote attackers to inject arbitrary web script or
HTML via the id parameter to iframe.php.
|
| CVE-2015-4657 |
Cross-site scripting (XSS) vulnerability in Mailbird 2.0.16.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via an e-mail message body with a crafted URL.
|
| CVE-2015-4656 |
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo
Station before 6.3-2945 allow remote attackers to inject arbitrary web
script or HTML via the (1) success parameter to login.php or (2)
crafted URL parameters to index.php, as demonstrated by the t
parameter to photo/.
|
| CVE-2015-4655 |
Cross-site scripting (XSS) vulnerability in Synology DiskStation
Manager (DSM) before 5.2-5565 Update 1 allows remote attackers to
inject arbitrary web script or HTML via the "compound" parameter to
entry.cgi.
|
| CVE-2015-4608 |
Cross-site scripting (XSS) vulnerability in the BE User Log
(beko_beuserlog) extension 1.1.1 and earlier for TYPO3 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-4587 |
Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent
CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote
attackers to inject arbitrary web script or HTML via the "Custom
application" field in the "port triggering" menu.
|
| CVE-2015-4559 |
Cross-site scripting (XSS) vulnerability in the product deployment
feature in the Java core web services in Intel McAfee ePolicy
Orchestrator (ePO) before 5.1.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4552 |
Cross-site scripting (XSS) vulnerability in the quick edit function in
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote
attackers to inject arbitrary web script or HTML via the content of a
post.
|
| CVE-2015-4541 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer
GRC 5.x before 5.5.3 allow remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4540 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA
Identity Management & Governance (IMG) before 6.8.1 P18 and 6.9.x
before 6.9.1 P6 allow remote authenticated users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2015-4539 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA
Identity Management & Governance (IMG) before 7.0.0 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-4528 |
Cross-site scripting (XSS) vulnerability in EMC Documentum CenterStage
1.2SP1 and 1.2SP2 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4518 |
The Reader View implementation in Mozilla Firefox before 42.0 has an
improper whitelist, which makes it easier for remote attackers to
bypass the Content Security Policy (CSP) protection mechanism and
conduct cross-site scripting (XSS) attacks via vectors involving SVG
animations and the about:reader URL.
|
| CVE-2015-4490 |
The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in
Mozilla Firefox before 40.0 does not implement the Content Security
Policy Level 2 exceptions for the blob, data, and filesystem URL
schemes during wildcard source-expression matching, which might make
it easier for remote attackers to conduct cross-site scripting (XSS)
attacks by leveraging unexpected policy-enforcement behavior.
|
| CVE-2015-4483 |
Mozilla Firefox before 40.0 allows man-in-the-middle attackers to
bypass a mixed-content protection mechanism via a feed: URL in a POST
request.
|
| CVE-2015-4465 |
Cross-site scripting (XSS) vulnerability in the zM Ajax Login &
Register plugin before 1.1.0 for WordPress allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4427 |
Multiple cross-site scripting (XSS) vulnerabilities in
Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS)
before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote authenticated
users to inject arbitrary web script or HTML via the (1) page, (2)
action, (3) folder_id, or (4) LangType parameter.
|
| CVE-2015-4420 |
Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2
and earlier allow remote attackers to inject arbitrary web script or
HTML via a (1) crafted check plugin, the (2) description in a host
profile, or the (3) plugin_args parameter to a Test service check
page.
|
| CVE-2015-4413 |
Cross-site scripting (XSS) vulnerability in the new_fb_sign_button
function in nextend-facebook-connect.php in Nextend Facebook Connect
plugin before 1.5.6 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the redirect_to parameter.
|
| CVE-2015-4392 |
Cross-site scripting (XSS) vulnerability in the Display Suite module
7.x-2.7 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors related to field
display settings.
|
| CVE-2015-4388 |
Cross-site scripting (XSS) vulnerability in the Current Search Links
module 7.x-1.x before 7.x-1.1 for Drupal, when the "Append the
keywords passed by the user to the list" option is disabled, allows
remote attackers to inject arbitrary web script or HTML via a crafted
search query.
|
| CVE-2015-4387 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Password Policy module 6.x-1.x before 6.x-1.11 and
7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses
the username constraint, allows remote attackers to inject arbitrary
web script or HTML via a crafted username that is imported from an
external source.
|
| CVE-2015-4386 |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified
administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal
allow remote attackers to inject arbitrary web script or HTML via
unknown vectors involving creating or editing (1) comments, (2)
taxonomy terms, or (3) nodes.
|
| CVE-2015-4385 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Imagefield Info module 7.x-1.x before 7.x-1.2 for Drupal
allows remote authenticated users with the "Administer image styles"
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-4384 |
Cross-site scripting (XSS) vulnerability in the Ubercart Webform
Checkout Pane module 6.x-3.x before 6.x-3.10 and 7.x-3.x before
7.x-3.11 for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-4381 |
Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x
before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote
authenticated users with the "Administer own invoices" permission to
inject arbitrary web script or HTML via unspecified vectors involving
nodes of the "Invoice" content type.
|
| CVE-2015-4380 |
Cross-site scripting (XSS) vulnerability in the Linear Case module
6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-4378 |
Cross-site scripting (XSS) vulnerability in the Crumbs module 7.x-2.x
before 7.x-2.3 for Drupal allows remote authenticated users with the
"Administer Crumbs" permission to inject arbitrary web script or HTML
via a custom breadcrumb separator.
|
| CVE-2015-4377 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows
remote authenticated users with the "create petition" permission to
inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2015-4376 |
Cross-site scripting (XSS) vulnerability in the Profile2 Privacy
module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated
users with the "Administer Profile2 Privacy Levels" permission to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4374 |
Cross-site scripting (XSS) vulnerability in the Webform module before
6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for
Drupal allows remote authenticated users with certain permissions to
inject arbitrary web script or HTML via a component name in the
recipient (To) address of an email.
|
| CVE-2015-4373 |
Cross-site scripting (XSS) vulnerability in the OG tabs module before
7.x-1.1 for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via vectors related
to nodes posted in an Organic Groups group.
|
| CVE-2015-4372 |
Cross-site scripting (XSS) vulnerability in the Image Title module
before 7.x-1.1 for Drupal allows remote authenticated users with
certain permissions to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-4370 |
Cross-site scripting (XSS) vulnerability in the Site Documentation
module before 6.x-1.5 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
vectors related to taxonomy terms.
|
| CVE-2015-4369 |
Cross-site scripting (XSS) vulnerability in the Trick Question module
before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal allows remote
authenticated users with the "Administer Trick Question" permission to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4367 |
Cross-site scripting (XSS) vulnerability in the Simple Subscription
module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows
remote authenticated users with the "administer blocks" permission to
inject arbitrary web script or HTML via vectors related to block
content.
|
| CVE-2015-4366 |
Cross-site scripting (XSS) vulnerability in the Mover module 6.x-1.0
for Drupal allows remote authenticated users with certain permissions
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4365 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Accordion
module for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via vectors related
to taxonomy terms.
|
| CVE-2015-4359 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Registration codes module before 6.x-1.6, 6.x-2.x before 6.x-2.8, and
7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users
with permission to create or edit taxonomy terms or nodes to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4358 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Ubercart Discount Coupons module 6.x-1.x before 6.x-1.8
for Drupal allows remote authenticated users with certain permissions
to inject arbitrary web script or HTML via vectors related to taxonomy
terms.
|
| CVE-2015-4357 |
Cross-site scripting (XSS) vulnerability in the Webform module before
6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for
Drupal allows remote authenticated users with certain permissions to
inject arbitrary web script or HTML via a node title, which is used as
the default title of a webform block.
|
| CVE-2015-4356 |
Cross-site scripting (XSS) vulnerability in the view-based webform
results table in the Webform module 7.x-4.x before 7.x-4.4 for Drupal
allows remote authenticated users with certain permissions to inject
arbitrary web script or HTML via a webform.
|
| CVE-2015-4354 |
Cross-site scripting (XSS) vulnerability in the Ubercart Webform
Integration module before 6.x-1.8 and 7.x before 7.x-2.4 for Drupal
allows remote authenticated users with certain permissions to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4347 |
Cross-site scripting (XSS) vulnerability in the inLinks Integration
module for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified path arguments.
|
| CVE-2015-4346 |
Cross-site scripting (XSS) vulnerability in the SMS Framework module
6.x-1.x before 6.x-1.1 for Drupal, when the "Send to phone" submodule
is enabled, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors related to message previews.
|
| CVE-2015-4337 |
Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2
for WordPress allows remote authenticated users to inject arbitrary
web script or HTML via the excl_manual parameter in the xcloner_show
page to wpadmin/plugins.php.
|
| CVE-2015-4310 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse
10.5(1) allow remote attackers to inject arbitrary web script or HTML
via unspecified parameters in a (1) GET or (2) POST request, aka Bug
IDs CSCuq82322, CSCut95853, and CSCuq73975.
|
| CVE-2015-4294 |
Cross-site scripting (XSS) vulnerability in Cisco IM and Presence
Service before 10.5 MR1 allows remote attackers to inject arbitrary
web script or HTML by constructing a crafted URL that leverages
incomplete filtering of HTML elements, aka Bug ID CSCut41766.
|
| CVE-2015-4292 |
Cross-site scripting (XSS) vulnerability in the management interface
in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS)
10.6(2) allows remote attackers to inject arbitrary web script or HTML
via an unspecified value, aka Bug ID CSCuv45818.
|
| CVE-2015-4272 |
Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page
in Cisco Unified Communications Manager (formerly CallManager)
10.5(2.10000.5) allow remote attackers to inject arbitrary web script
or HTML via a crafted parameter, aka Bug ID CSCut19580.
|
| CVE-2015-4270 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT
System Software 5.3.1.5 and 6.0.0 allow remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka Bug IDs
CSCuv22557, CSCuv22583, CSCuv22632, CSCuv22641, CSCuv22650,
CSCuv22662, CSCuv22697, and CSCuv22702.
|
| CVE-2015-4268 |
Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin
UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876)
allow remote attackers to inject arbitrary web script or HTML via
unspecified parameters in a (1) GET or (2) POST request, aka Bug ID
CSCus16052.
|
| CVE-2015-4260 |
Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration
Solution 10.6(1) allows remote attackers to inject arbitrary web
script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.
|
| CVE-2015-4220 |
Cross-site scripting (XSS) vulnerability in Cisco Unified Presence
Server 9.1(1) allows remote attackers to inject arbitrary web script
or HTML via an unspecified value, aka Bug ID CSCuq03773.
|
| CVE-2015-4210 |
Cross-site scripting (XSS) vulnerability in Cisco WebEx Meeting Center
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL, aka Bug ID CSCur03806.
|
| CVE-2015-4206 |
Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows
remote attackers to bypass an XSS protection mechanism via a crafted
parameter, aka Bug ID CSCuu15266.
|
| CVE-2015-4198 |
Cross-site scripting (XSS) vulnerability in the web framework on Cisco
Web Security Appliance (WSA) devices with software 8.5.0-497 allows
remote attackers to inject arbitrary web script or HTML via an
unspecified HTTP header, aka Bug ID CSCuu24409.
|
| CVE-2015-4174 |
Cross-site scripting (XSS) vulnerability in the integrated web server
on the Siemens Climatix BACnet/IP communication module with firmware
before 10.34 allows remote attackers to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2015-4140 |
Cross-site request forgery (CSRF) vulnerability in the WP Smiley
plugin 1.4.1 for WordPress allows remote attackers to hijack the
authentication of editors for requests that conduct cross-site
scripting (XSS) attacks via the s4w-more parameter to the
smilies4wp.php page to wp-admin/options-general.php.
|
| CVE-2015-4139 |
Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP
Smiley plugin 1.4.1 for WordPress allows remote authenticated users to
inject arbitrary web script or HTML via the s4w-more parameter to
wp-admin/options-general.php.
|
| CVE-2015-4135 |
Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7
allows remote attackers to inject arbitrary web script or HTML via the
url parameter.
|
| CVE-2015-4132 |
Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks
ClearPass Policy Manager (CPPM) before 6.4.5 allow remote
administrators to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-4127 |
Cross-site scripting (XSS) vulnerability in the church_admin plugin
before 0.810 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the address parameter, as demonstrated by a
request to index.php/2015/05/21/church_admin-registration-form/.
|
| CVE-2015-4093 |
Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x
before 4.0.3 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-4084 |
Cross-site scripting (XSS) vulnerability in the Free Counter plugin
1.1 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the value_ parameter in a check_stat action to
wp-admin/admin-ajax.php.
|
| CVE-2015-4072 |
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk
Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject
arbitrary web script or HTML via vectors related to name and message.
|
| CVE-2015-4065 |
Cross-site scripting (XSS) vulnerability in
shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin
before 1.8.5 for WordPress allows remote authenticated users to inject
arbitrary web script or HTML via the post parameter to
wp-admin/post-new.php.
|
| CVE-2015-4063 |
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in
the NewStatPress plugin before 0.9.9 for WordPress allows remote
authenticated users to inject arbitrary web script or HTML via the
where1 parameter in the nsp_search page to wp-admin/admin.php.
|
| CVE-2015-4029 |
Cross-site scripting (XSS) vulnerability in the WebGUI in pfSense
before 2.2.3 allows remote attackers to inject arbitrary web script or
HTML via the zone parameter in a del action to
services_captiveportal_zones.php.
|
| CVE-2015-4010 |
Cross-site request forgery (CSRF) vulnerability in the Encrypted
Contact Form plugin before 1.1 for WordPress allows remote attackers
to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks via the iframe_url
parameter in an Update Page action in the conformconf page to
wp-admin/options-general.php.
|
| CVE-2015-3998 |
Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in
the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows
remote attackers to inject arbitrary web script or HTML via the query
parameter to whois.php.
|
| CVE-2015-3989 |
Multiple cross-site scripting (XSS) vulnerabilities in concrete5
before 5.7.4 allow remote attackers to inject arbitrary web script or
HTML via vectors related to private messages or other unspecified
vectors.
|
| CVE-2015-3988 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack
Dashboard (Horizon) 2015.1.0 allow remote authenticated users to
inject arbitrary web script or HTML via the metadata to a (1) Glance
image, (2) Nova flavor or (3) Host Aggregate.
|
| CVE-2015-3976 |
Cross-site scripting (XSS) vulnerability in GE Multilink
ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink
ML800/1200/1600/2400 4.2.1 and earlier.
|
| CVE-2015-3970 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-3948 |
Cross-site scripting (XSS) vulnerability in Advantech WebAccess before
8.1 allows remote authenticated users to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2015-3942 |
Multiple cross-site scripting (XSS) vulnerabilities in the web-server
component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and
Magnum 10K switches allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-3935 |
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr
ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web
script or HTML via the Business Search (search_nom) field to (1)
htdocs/societe/societe.php or (2) htdocs/societe/admin/societe.php.
|
| CVE-2015-3921 |
Cross-site scripting (XSS) vulnerability in contact.php in Coppermine
Photo Gallery before 1.5.36 allows remote authenticated users to
inject arbitrary web script or HTML via the referer parameter.
|
| CVE-2015-3904 |
Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php
in the Roomcloud plugin before 1.3 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) pin, (2)
start_day, (3) start_month, (4) start_year, (5) end_day, (6)
end_month, (7) end_year, (8) lang, (9) adults, or (10) children
parameter.
|
| CVE-2015-3883 |
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow
remote attackers to inject arbitrary web script or HTML via the (1)
search[keywords] parameter to index.php/users page; the (2) "Name of
application" on index.php/configuration; (3) a new project name on
index.php/projects; (4) the task name on index.php/tasks; (5) ticket
name on index.php/tickets; (6) discussion name on
index.php/discussions; (7) report name on index.php/projectReports; or
(8) event name on index.php/scheduler/personal.
|
| CVE-2015-3781 |
Cross-site scripting (XSS) vulnerability in Quick Look in Apple OS X
before 10.10.5 allows remote attackers to inject arbitrary web script
or HTML via a previously visited web site that is rendered during a
Quick Look search.
|
| CVE-2015-3660 |
Cross-site scripting (XSS) vulnerability in the PDF functionality in
WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before
8.0.7 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL in embedded PDF content.
|
| CVE-2015-3647 |
Multiple cross-site scripting (XSS) vulnerabilities in
wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin
before 6.1.3 for WordPress allow remote attackers to inject arbitrary
web script or HTML via the (1) comemail or (2) comname parameter in a
wppa do-comment action.
|
| CVE-2015-3626 |
Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the
Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate
devices allows remote attackers to inject arbitrary web script or HTML
via a crafted hostname.
|
| CVE-2015-3620 |
Cross-site scripting (XSS) vulnerability in the advanced dataset
reports page in Fortinet FortiAnalyzer 5.0.0 through 5.0.10 and 5.2.0
through 5.2.1 and FortiManager 5.0.3 through 5.0.10 and 5.2.0 through
5.2.1 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2015-3615 |
Cross-site scripting (XSS) vulnerability in Fortinet FortiManager
5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated
users to inject arbitrary web script or HTML via vectors involving
unspecified parameters and a privilege escalation attack.
|
| CVE-2015-3447 |
Multiple cross-site scripting (XSS) vulnerabilities in
macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow
remote attackers to inject arbitrary web script or HTML via the (1)
searchSpoof or (2) searchSpoofIpDet parameter.
|
| CVE-2015-3443 |
Cross-site scripting (XSS) vulnerability in the basic dashboard in
Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005
allows remote authenticated users to inject arbitrary web script or
HTML via a password entry, which is not properly handled when toggling
the password mask.
|
| CVE-2015-3440 |
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in
WordPress before 4.2.1 allows remote attackers to inject arbitrary web
script or HTML via a long comment that is improperly stored because of
limitations on the MySQL TEXT data type.
|
| CVE-2015-3439 |
Cross-site scripting (XSS) vulnerability in the Ephox (formerly
Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in
WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products,
allows remote attackers to execute same-origin JavaScript functions
via the target parameter, as demonstrated by executing a certain click
function, related to _init.as and _fireEvent.as.
|
| CVE-2015-3438 |
Multiple cross-site scripting (XSS) vulnerabilities in WordPress
before 4.1.2, when MySQL is used without strict mode, allow remote
attackers to inject arbitrary web script or HTML via a (1) four-byte
UTF-8 character or (2) invalid character that reaches the database
layer, as demonstrated by a crafted character in a comment.
|
| CVE-2015-3432 |
Multiple cross-site scripting (XSS) vulnerabilities in Pydio (formerly
AjaXplorer) before 6.0.7 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors, aka "Pydio XSS
Vulnerabilities."
|
| CVE-2015-3429 |
Cross-site scripting (XSS) vulnerability in example.html in Genericons
before 3.3.1, as used in WordPress before 4.2.2, allows remote
attackers to inject arbitrary web script or HTML via a fragment
identifier.
|
| CVE-2015-3422 |
Cross-site scripting (XSS) vulnerability in SearchBlox before 8.2.1
allows remote attackers to inject arbitrary web script or HTML via the
menu2 parameter to admin/main.jsp.
|
| CVE-2015-3421 |
The eshop_checkout function in checkout.php in the Wordpress Eshop
plugin 6.3.11 and earlier does not validate variables in the
"eshopcart" HTTP cookie, which allows remote attackers to perform
cross-site scripting (XSS) attacks, or a path disclosure attack via
crafted variables named after target PHP variables.
|
| CVE-2015-3397 |
Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4
allows remote attackers to inject arbitrary web script or HTML via
vectors related to JSON, arrays, and Internet Explorer 6 or 7.
|
| CVE-2015-3392 |
Cross-site scripting (XSS) vulnerability in the Ajax Timeline module
before 7.x-1.1 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3390 |
Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher
module for Drupal allows remote authenticated users with the "access
administration pages" permission to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-3389 |
Cross-site scripting (XSS) vulnerability in the Download counts report
page in the Public Download Count module (pubdlcnt) 7.x-1.x-dev and
earlier for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-3387 |
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy
Tools module before 7.x-1.4 for Drupal allow remote authenticated
users to inject arbitrary web script or HTML via a (1) node or (2)
taxonomy term title.
|
| CVE-2015-3386 |
Cross-site scripting (XSS) vulnerability in the Node Access Product
module for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3385 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Path module
before 7.x-1.2 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via the "Link to path" field formatter.
|
| CVE-2015-3384 |
Cross-site scripting (XSS) vulnerability in the Bank Account Listing
Page in the Commerce Balanced Payments module for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-3381 |
Cross-site scripting (XSS) vulnerability in the Node basket module for
Drupal allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-3376 |
Cross-site scripting (XSS) vulnerability in the Quizzler module before
7-x.1.16 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3372 |
Cross-site scripting (XSS) vulnerability in the Node Invite module
before 6.x-2.5 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3369 |
Cross-site scripting (XSS) vulnerability in the Taxonews module before
6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote
authenticated users with the "administer taxonomy" permission to
inject arbitrary web script or HTML via a term name in a block.
|
| CVE-2015-3368 |
Cross-site scripting (XSS) vulnerability in the administration user
interface in the Classified Ads module before 6.x-3.1 and 7.x-3.x
before 7.x-3.1 for Drupal allows remote authenticated users with the
"administer taxonomy" permission to inject arbitrary web script or
HTML via a category name.
|
| CVE-2015-3365 |
Cross-site scripting (XSS) vulnerability in the nodeauthor module for
Drupal allows remote authenticated users to inject arbitrary web
script or HTML via a Profile2 field in a provided block.
|
| CVE-2015-3364 |
Cross-site scripting (XSS) vulnerability in the Content Analysis
module before 6.x-1.7 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, which are not
properly handled in a log message.
|
| CVE-2015-3362 |
Cross-site scripting (XSS) vulnerability in the Video module before
7.x-2.11 for Drupal, when using the video WYSIWYG plugin, allows
remote authenticated users to inject arbitrary web script or HTML via
a node title.
|
| CVE-2015-3361 |
Cross-site scripting (XSS) vulnerability in the Linkit module before
7.x-2.7 and 7.x-3.x before 7.x-3.3 for Drupal, when the node search
plugin is enabled, allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3360 |
Cross-site scripting (XSS) vulnerability in the Term Merge module
before 7.x-1.2 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-3359 |
Multiple cross-site scripting (XSS) vulnerabilities in the Room
Reservations module before 7.x-1.1 for Drupal allow remote
authenticated users with the "Administer the room reservations system"
permission to inject arbitrary web script or HTML via the (1) node
title of a "Room Reservations Category" or (2) body of a "Room
Reservations Room" node.
|
| CVE-2015-3357 |
Cross-site scripting (XSS) vulnerability in the Wishlist module before
6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote
authenticated users with the "access wishlists" permission to inject
arbitrary web script or HTML via unspecified vectors, which are not
properly handled in a log message.
|
| CVE-2015-3353 |
Cross-site scripting (XSS) vulnerability in the Field Display Label
module before 7.x-1.3 for Drupal allows remote authenticated users to
inject arbitrary web script or HTML via the alternate field label in
content types settings.
|
| CVE-2015-3348 |
Cross-site scripting (XSS) vulnerability in the Cloudwords for
Multilingual Drupal module before 7.x-2.3 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via a node
title.
|
| CVE-2015-3344 |
Cross-site scripting (XSS) vulnerability in the Course module 6.x-1.x
before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via a node
title.
|
| CVE-2015-3319 |
Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly
flag in a Set-Cookie header, which makes it easier for remote
attackers to obtain potentially sensitive information via script
access to this cookie.
|
| CVE-2015-3300 |
Multiple cross-site scripting (XSS) vulnerabilities in the
TheCartPress eCommerce Shopping Cart (aka The Professional WordPress
eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote
attackers to inject arbitrary web script or HTML via the (1)
billing_firstname, (2) billing_lastname, (3) billing_company, (4)
billing_tax_id_number, (5) billing_city, (6) billing_street, (7)
billing_street_2, (8) billing_postcode, (9) billing_telephone_1, (10)
billing_telephone_2, (11) billing_fax, (12) shipping_firstname, (13)
shipping_lastname, (14) shipping_company, (15) shipping_tax_id_number,
(16) shipping_city, (17) shipping_street, (18) shipping_street_2, (19)
shipping_postcode, (20) shipping_telephone_1, (21)
shipping_telephone_2, or (22) shipping_fax parameter to
shopping-cart/checkout/; the (23) search_by parameter in the
admin/AddressesList.php page to wp-admin/admin.php; the (24)
address_id, (25) address_name, (26) firstname, (27) lastname, (28)
street, (29) city, (30) postcode, or (31) email parameter in the
admin/AddressEdit.php page to wp-admin/admin.php; the (32) post_id or
(33) rel_type parameter in the admin/AssignedCategoriesList.php page
to wp-admin/admin.php; or the (34) post_type parameter in the
admin/CustomFieldsList.php page to wp-admin/admin.php.
|
| CVE-2015-3299 |
Cross-site scripting (XSS) vulnerability in the Floating Social Bar
plugin before 1.1.7 for WordPress allows remote attackers to inject
arbitrary web script or HTML via vectors related to original service
order.
|
| CVE-2015-3296 |
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before
0.7 allow remote attackers to inject arbitrary web script or HTML via
vectors related to (1) javascript: or (2) data: URLs.
|
| CVE-2015-3295 |
markdown-it before 4.1.0 does not block data: URLs.
|
| CVE-2015-3275 |
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM
module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before
2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject
arbitrary web script or HTML via a crafted organization name to (1)
mod/scorm/player.php or (2) mod/scorm/prereqs.php.
|
| CVE-2015-3274 |
Cross-site scripting (XSS) vulnerability in the user_get_user_details
function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9,
2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to
inject arbitrary web script or HTML by leveraging absence of an
external_format_text call in a web service.
|
| CVE-2015-3268 |
Cross-site scripting (XSS) vulnerability in the
DisplayEntityField.getDescription method in ModelFormField.java in
Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote
attackers to inject arbitrary web script or HTML via the description
attribute of a display-entity element.
|
| CVE-2015-3267 |
Cross-site scripting (XSS) vulnerability in the 404 error page in Red
Hat JBoss Operations Network before 3.3.3 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-3257 |
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not
properly sanitize path input, which allows remote attackers to perform
cross-site scripting (XSS) or open redirect attacks.
|
| CVE-2015-3226 |
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active
Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before
4.2.2 allows remote attackers to inject arbitrary web script or HTML
via a crafted Hash that is mishandled during JSON encoding.
|
| CVE-2015-3219 |
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack
section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and
2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary
web script or HTML via the description parameter in a heat template,
which is not properly handled in the help_text attribute in the Field
class.
|
| CVE-2015-3186 |
Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0
allows remote authenticated cluster operator users to inject arbitrary
web script or HTML via the note field in a configuration change.
|
| CVE-2015-3178 |
Cross-site scripting (XSS) vulnerability in the external_format_text
function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before
2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote
authenticated users to inject arbitrary web script or HTML into an
external application via a crafted string that is visible to web
services.
|
| CVE-2015-3174 |
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11,
2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS
bit for graders, which allows remote authenticated users to conduct
cross-site scripting (XSS) attacks via crafted gradebook feedback
during manual quiz grading.
|
| CVE-2015-3169 |
Cross-site scripting (XSS) vulnerability in askbot
0.7.51-4.el6.noarch.
|
| CVE-2015-3162 |
Cross-site scripting (XSS) vulnerability in the edit comment dialog in
bkr/server/widgets.py in Beaker 20.1 allows remote authenticated users
to inject arbitrary web script or HTML via writing a crafted comment
on an acked or nacked canceled job.
|
| CVE-2015-3141 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
Synametrics Technologies Xeams 4.5 Build 5755 and earlier allow remote
attackers to hijack the authentication of administrators for requests
that create an (1) SMTP domain or a (2) user via a request to
/FrontController; or conduct cross-site scripting (XSS) attacks via
the (3) domainname parameter to /FrontController, when creating a new
SMTP domain configuration; the (4) txtRecipient parameter to
/FrontController, when creating a new forwarder; the (5)
popFetchServer, (6) popFetchUser, or (7) popFetchRecipient parameter
to /FrontController, when creating a new POP3 Fetcher account; or the
(8) Smtp HELO domain in the Advanced Server Configuration.
|
| CVE-2015-3012 |
Multiple cross-site scripting (XSS) vulnerabilities in WebODF before
0.5.5, as used in ownCloud, allow remote attackers to inject arbitrary
web script or HTML via a (1) style or (2) font name or (3) javascript
or (4) data URI.
|
| CVE-2015-3011 |
Multiple cross-site scripting (XSS) vulnerabilities in the contacts
application in ownCloud Server Community Edition before 5.0.19, 6.x
before 6.0.7, and 7.x before 7.0.5 allow remote authenticated users to
inject arbitrary web script or HTML via a crafted contact.
|
| CVE-2015-3005 |
Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper
Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47
before 12.1X47-D20, and 12.3X48 before 12.3X48-D10 on SRX series
devices allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2015-2989 |
Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP
Twit BBS allows remote attackers to inject arbitrary web script or
HTML via the imagetitle parameter.
|
| CVE-2015-2986 |
Cross-site scripting (XSS) vulnerability in rakuto.net hitSuji
(rktSNS2) 0.2.2b allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-2985 |
Cross-site scripting (XSS) vulnerability in guide-park.com BBS X102
1.03 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2015-2982 |
Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js
in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone
1.0.1 Free and earlier allows remote authenticated users to inject
arbitrary web script or HTML via unspecified input to admin.php.
|
| CVE-2015-2976 |
Multiple cross-site scripting (XSS) vulnerabilities in Research
Artisan Lite before 1.18 allow remote attackers to inject arbitrary
web script or HTML via (1) a crafted HTML document or (2) a crafted
URL that is mishandled during access-log analysis.
|
| CVE-2015-2973 |
Multiple cross-site scripting (XSS) vulnerabilities in the Welcart
plugin before 1.4.18 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the usces_referer parameter to (1)
classes/usceshop.class.php, (2) includes/edit-form-advanced.php, (3)
includes/edit-form-advanced30.php, (4)
includes/edit-form-advanced34.php, (5) includes/member_edit_form.php,
(6) includes/order_edit_form.php, (7) includes/order_list.php, or (8)
includes/usces_item_master_list.php, related to admin.php.
|
| CVE-2015-2969 |
Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP
Simple Oekaki BBS before 1.21 allows remote attackers to inject
arbitrary web script or HTML via the oekakis parameter.
|
| CVE-2015-2967 |
Cross-site scripting (XSS) vulnerability in settings.php in Cacti
before 0.8.8d allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2015-2963 |
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider
the content-type value during media-type validation, which allows
remote attackers to upload HTML documents and conduct cross-site
scripting (XSS) attacks via a spoofed value, as demonstrated by
image/jpeg.
|
| CVE-2015-2960 |
Cross-site scripting (XSS) vulnerability in Zoho NetFlow Analyzer
build 10250 and earlier allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2015-2957 |
Cross-site scripting (XSS) vulnerability in Igreks MilkyStep Light
0.94 and earlier and Professional 1.82 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-2949 |
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2015-2948 |
Cross-site scripting (XSS) vulnerability in the image processor in
Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-2944 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling
API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow
remote attackers to inject arbitrary web script or HTML via the URI,
related to (1) org/apache/sling/api/servlets/HtmlResponse and (2)
org/apache/sling/servlets/post/HtmlResponse.
|
| CVE-2015-2941 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24,
1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows
remote attackers to inject arbitrary web script or HTML via an invalid
parameter in a wddx format request to api.php, which is not properly
handled in an error message, related to unsafe calls to
wddx_serialize_value.
|
| CVE-2015-2939 |
Cross-site scripting (XSS) vulnerability in the Scribunto extension
for MediaWiki allows remote attackers to inject arbitrary web script
or HTML via a function name, which is not properly handled in a Lua
error backtrace.
|
| CVE-2015-2938 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24,
1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers
to inject arbitrary web script or HTML via a custom JavaScript file,
which is not properly handled when previewing the file.
|
| CVE-2015-2933 |
Cross-site scripting (XSS) vulnerability in the Html class in
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2
allows remote attackers to inject arbitrary web script or HTML via a
LanguageConverter substitution string when using a language variant.
|
| CVE-2015-2926 |
Cross-site scripting (XSS) vulnerability in
Php/stats/statsRecent.inc.php in phpTrafficA 2.3 and earlier allows
remote attackers to inject arbitrary web script or HTML via the HTTP
User-Agent header to index.php.
|
| CVE-2015-2883 |
Philips In.Sight B120/37 has XSS, related to the Weaved cloud web
service, as demonstrated by the name parameter to deviceSettings.php or
shareDevice.php.
|
| CVE-2015-2872 |
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro
Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances
with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before
3.7.1248, 3.8.x before 3.8.1263, and other versions allow remote
attackers to inject arbitrary web script or HTML via (1) crafted input
to index.php that is processed by certain Internet Explorer 7
configurations or (2) crafted input to the widget feature.
|
| CVE-2015-2870 |
Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and
BF-660C fingerprint access-control devices allows remote attackers to
inject arbitrary web script or HTML via a SCRIPT element.
|
| CVE-2015-2850 |
Cross-site scripting (XSS) vulnerability in index-login.ant in the
ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E,
InnGate 3.10 M, SG 4, and SSG 4 devices allows remote attackers to
inject arbitrary web script or HTML via the msg parameter.
|
| CVE-2015-2840 |
Cross-site scripting (XSS) vulnerability in help/rt/large_search.html
in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers
to inject arbitrary web script or HTML via the searchQuery parameter.
|
| CVE-2015-2839 |
The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an
incorrect Content-Type when returning an error message, which allows
remote attackers to conduct cross-site scripting (XSS) attacks via the
file_name JSON member in params/xen_hotfix/0 to
nitro/v1/config/xen_hotfix.
|
| CVE-2015-2827 |
Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and
9.3.x before 9.3 H02 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-2807 |
Cross-site scripting (XSS) vulnerability in js/window.php in the Navis
DocumentCloud plugin before 0.1.1 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the wpbase
parameter.
|
| CVE-2015-2781 |
Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi
in Hotspot Express hotEx Billing Manager 73 allows remote attackers to
inject arbitrary web script or HTML via the reply parameter.
|
| CVE-2015-2768 |
Cross-site scripting (XSS) vulnerability in Websense TRITON AP-EMAIL
before 8.0.0 and V-Series 7.7 appliances allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-2764 |
Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON
AP-DATA before 8.0.0 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors to the DSS (1) Mobile or (2)
DLP report catalog.
|
| CVE-2015-2761 |
Cross-site scripting (XSS) vulnerability in the Exceptions and
Scanning Exceptions Pages in Websense TRITON AP-WEB before 8.0.0
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-2760 |
Cross-site scripting (XSS) vulnerability in the ePO extension in
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix
16 (9.3.416.4) allows remote authenticated users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2015-2755 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the AB
Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow
remote attackers to hijack the authentication of administrators for
requests that conduct cross-site scripting (XSS) attacks via the (1)
lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height,
or (5) zoom (Map Zoom) parameter in the ab_map_options page to
wp-admin/admin.php.
|
| CVE-2015-2747 |
Multiple cross-site scripting (XSS) vulnerabilities in the data loss
prevention (DLP) incident Forensics Preview in Websense Triton 7.8.3
and V-Series 7.7 appliances allow remote attackers to inject arbitrary
web script or HTML via a crafted (1) email or (2) HTTP request, which
triggers a DLP Policy.
|
| CVE-2015-2745 |
Multiple cross-site scripting (XSS) vulnerabilities in the Search app
in Gaia in Mozilla Firefox OS before 2.2 allow remote attackers to
inject arbitrary HTML via the (1) name or (2) title field in card
content associated with a search link that is mishandled after a HOME
button press or a Show Windows action, as demonstrated by embedding an
arbitrary application or spoofing the account-creation page.
|
| CVE-2015-2744 |
Cross-site scripting (XSS) vulnerability in the Search app in Gaia in
Mozilla Firefox OS before 2.2 allows remote attackers to inject
arbitrary HTML via a crafted search link that is mishandled after
re-opening the browser or opening the tab view.
|
| CVE-2015-2703 |
Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON
AP-WEB before 8.0.0 and V-Series 7.7 appliances allow remote attackers
to inject arbitrary web script or HTML via the (1) ws-userip in the
ws-encdata parameter to cve-bin/moreBlockInfo.cgi in the Data Security
block page or (2) admin_msg parameter to
configure/ssl_ui/eva-config/client-cert-import_wsoem.html in the
Content Gateway, which is not properly handled in an error message.
|
| CVE-2015-2702 |
Cross-site scripting (XSS) vulnerability in the Message Log in the
Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 and
V-Series 7.7 appliances allows remote attackers to inject arbitrary
web script or HTML via the sender address in an email.
|
| CVE-2015-2690 |
Multiple cross-site scripting (XSS) vulnerabilities in
views/add-license-form.php in the Digium Addons module
(digiumaddoninstaller) before 2.11.0.7 for FreePBX allow remote
attackers to inject arbitrary web script or HTML via the (1)
add_license_key, (2) add_license_first_name, (3)
add_license_last_name, (4) add_license_company, (5)
add_license_address1, (6) add_license_address2, (7) add_license_city,
(8) add_license_state, (9) add_license_post_code, (10)
add_license_country, (11) add_license_phone, or (12) add_license_email
parameter in an add-license-form page to admin/config.php.
|
| CVE-2015-2681 |
Multiple cross-site scripting (XSS) vulnerabilities in the ASUS RT-G32
routers with firmware 2.0.2.6 and 2.0.3.2 allow remote attackers to
inject arbitrary web script or HTML via the (1) next_page, (2)
group_id, (3) action_script, or (4) flag parameter to start_apply.htm.
|
| CVE-2015-2678 |
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix
GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) cat parameter in the categories page to
gxadmin/index.php or (2) page parameter to index.php.
|
| CVE-2015-2677 |
Multiple cross-site scripting (XSS) vulnerabilities in ocPortal before
9.0.17 allow remote authenticated users to inject arbitrary web script
or HTML via the (1) title or (2) text field in the cms_calendar page
to cms/index.php; unspecified fields in (3) the cms_polls page to
cms/index.php or (4) a new topic in the topics page to
forum/index.php; or (5) a new PT (private topic/private message) in
the topics page to forum/index.php.
|
| CVE-2015-2665 |
Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-2544 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1
allows remote attackers to inject arbitrary web script or HTML via a
crafted e-mail message, aka "Exchange Spoofing Vulnerability."
|
| CVE-2015-2543 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 allows
remote attackers to inject arbitrary web script or HTML via a crafted
e-mail message, aka "Exchange Spoofing Vulnerability."
|
| CVE-2015-2536 |
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013
and Skype for Business Server 2015 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka "Skype for
Business Server and Lync Server XSS Elevation of Privilege
Vulnerability."
|
| CVE-2015-2532 |
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL, aka "Lync Server XSS Information Disclosure
Vulnerability."
|
| CVE-2015-2531 |
Cross-site scripting (XSS) vulnerability in the jQuery engine in
Microsoft Lync Server 2013 and Skype for Business Server 2015 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka "Skype for Business Server and Lync Server XSS Information
Disclosure Vulnerability."
|
| CVE-2015-2522 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Foundation 2013 SP1 allows remote authenticated users to inject
arbitrary web script or HTML via crafted content, aka "Microsoft
SharePoint XSS Spoofing Vulnerability."
|
| CVE-2015-2475 |
Cross-site scripting (XSS) vulnerability in uddi/search/frames.aspx in
the UDDI Services component in Microsoft Windows Server 2008 SP2 and
BizTalk Server 2010, 2013 Gold, and 2013 R2 allows remote attackers to
inject arbitrary web script or HTML via the search parameter, aka
"UDDI Services Elevation of Privilege Vulnerability."
|
| CVE-2015-2420 |
Cross-site scripting (XSS) vulnerability in Microsoft System Center
2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10,
and R2 before Rollup 7 allows remote attackers to inject arbitrary web
script or HTML via a crafted URL, aka "System Center Operations
Manager Web Console XSS Vulnerability."
|
| CVE-2015-2398 |
Microsoft Internet Explorer 8 through 11 allows remote attackers to
bypass the XSS filter via a crafted attribute of an element in an HTML
document, aka "Internet Explorer XSS Filter Bypass Vulnerability."
|
| CVE-2015-2359 |
Cross-site scripting (XSS) vulnerability in the web applications in
Microsoft Exchange Server 2013 Cumulative Update 8 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka "Exchange HTML Injection Vulnerability."
|
| CVE-2015-2351 |
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms
9.5.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) homelink parameter to
system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp,
(2) workplaceresource parameter to
system/workplace/locales/en/help/index.html, (3) path parameter to
system/workplace/views/admin/admin-main.jsp, (4) mode parameter to
system/workplace/views/explorer/explorer_files.jsp, or (5) query
parameter in a search action to
system/modules/org.opencms.workplace.help/elements/search.jsp.
|
| CVE-2015-2349 |
Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in
SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to
inject arbitrary web script or HTML via the HTMLForm parameter.
|
| CVE-2015-2347 |
Cross-site scripting (XSS) vulnerability in Huawei SEQ Analyst before
V200R002C03LG0001CP0022 allows remote attackers to inject arbitrary
web script or HTML via the command XML element in the req parameter to
flexdata.action in (1) common/, (2) monitor/, or (3) psnpm/ or the (4)
module XML element in the req parameter to flexdata.action in
monitor/.
|
| CVE-2015-2344 |
Cross-site scripting (XSS) vulnerability in VMware vRealize Automation
6.x before 6.2.4 on Linux allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-2333 |
Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB
(aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-2332 |
Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka
MyBulletinBoard) before 1.8.4 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-2321 |
Cross-site scripting (XSS) vulnerability in the Job Manager plugin
0.7.22 and earlier for WordPress allows remote attackers to inject
arbitrary web script or HTML via the email field.
|
| CVE-2015-2317 |
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x,
1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does
not properly validate URLs, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via a control character in a URL,
as demonstrated by a \x08javascript: URL.
|
| CVE-2015-2315 |
Cross-site scripting (XSS) vulnerability in the WPML plugin before
3.1.9 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the target parameter in a reminder_popup action to
the default URI.
|
| CVE-2015-2295 |
Cross-site request forgery (CSRF) vulnerability in
system_firmware_restorefullbackup.php in the WebGUI in pfSense before
2.2.1 allows remote attackers to hijack the authentication of
administrators for requests that delete arbitrary files via the
deletefile parameter.
|
| CVE-2015-2294 |
Multiple cross-site scripting (XSS) vulnerabilities in the WebGUI in
pfSense before 2.2.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) zone parameter to status_captiveportal.php;
(2) if or (3) dragtable parameter to firewall_rules.php; (4) queue
parameter in an add action to firewall_shaper.php; (5) id parameter in
an edit action to services_unbound_acls.php; or (6)
filterlogentries_time, (7) filterlogentries_sourceipaddress, (8)
filterlogentries_sourceport, (9)
filterlogentries_destinationipaddress, (10)
filterlogentries_interfaces, (11) filterlogentries_destinationport,
(12) filterlogentries_protocolflags, or (13) filterlogentries_qty
parameter to diag_logs_filter.php.
|
| CVE-2015-2289 |
Cross-site scripting (XSS) vulnerability in
templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows
remote authenticated editors to inject arbitrary web script or HTML
via the serendipity[cat][name] parameter to serendipity_admin.php,
when creating a new category.
|
| CVE-2015-2275 |
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery
2.0 before 2014-12-26 allows remote attackers to inject arbitrary web
script or HTML via the parameters[data][7][title] parameter in a
saveImageData action to index.php/AJAXProxy.
|
| CVE-2015-2273 |
Cross-site scripting (XSS) vulnerability in
mod/quiz/report/statistics/statistics_question_table.php in Moodle
through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x
before 2.8.4 allows remote authenticated users to inject arbitrary web
script or HTML by leveraging the student role for a crafted quiz
response.
|
| CVE-2015-2269 |
Multiple cross-site scripting (XSS) vulnerabilities in
lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9,
2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated
users to inject arbitrary web script or HTML via a (1) alt or (2)
title attribute in an IMG element.
|
| CVE-2015-2250 |
Multiple cross-site scripting (XSS) vulnerabilities in concrete5
before 5.7.4 allow remote attackers to inject arbitrary web script or
HTML via the (1) banned_word[] parameter to
index.php/dashboard/system/conversations/bannedwords/success, (2)
channel parameter to index.php/dashboard/reports/logs/view, (3)
accessType parameter to
index.php/tools/required/permissions/access_entity, (4) msCountry
parameter to index.php/dashboard/system/multilingual/setup/load_icon,
arHandle parameter to (5) design/submit or (6) design in
index.php/ccm/system/dialogs/area/design/submit, (7) pageURL to
index.php/dashboard/pages/single, (8) SEARCH_INDEX_AREA_METHOD
parameter to index.php/dashboard/system/seo/searchindex/updated, (9)
unit parameter to
index.php/dashboard/system/optimization/jobs/job_scheduled, (10)
register_notification_email parameter to
index.php/dashboard/system/registration/open/1, or (11) PATH_INFO to
index.php/dashboard/extend/connect/.
|
| CVE-2015-2244 |
Multiple cross-site scripting (XSS) vulnerabilities in Webshop hun
1.062S allow remote attackers to inject arbitrary web script or HTML
via the (1) param, (2) center, (3) lap, (4) termid, or (5) nyelv_id
parameter to index.php.
|
| CVE-2015-2241 |
Cross-site scripting (XSS) vulnerability in the contents function in
admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows
remote attackers to inject arbitrary web script or HTML via a model
attribute in ModelAdmin.readonly_fields, as demonstrated by a
@property.
|
| CVE-2015-2239 |
Google Chrome before 41.0.2272.76, when Instant Extended mode is used,
does not properly consider the interaction between the "1993 search"
features and restore-from-disk RELOAD transitions, which makes it
easier for remote attackers to spoof the address bar for a
search-results page by leveraging (1) a compromised search engine or
(2) an XSS vulnerability in a search engine, a different vulnerability
than CVE-2015-1231.
|
| CVE-2015-2223 |
Multiple cross-site scripting (XSS) vulnerabilities in the web-based
console management interface in Palo Alto Networks Traps (formerly
Cyvera Endpoint Protection) 3.1.2.1546 allow remote attackers to
inject arbitrary web script or HTML via the (1) Arguments, (2)
FileName, or (3) URL parameter in a SOAP request.
|
| CVE-2015-2220 |
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms
plugin before 2.8.9 for WordPress allow (1) remote attackers to inject
arbitrary web script or HTML via the ninja_forms_field_1 parameter in
a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2)
remote administrators to inject arbitrary web script or HTML via the
fields[1] parameter to wp-admin/post.php.
|
| CVE-2015-2218 |
Multiple cross-site scripting (XSS) vulnerabilities in the
wp_ajax_save_item function in wonderpluginaudio.php in the
WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1)
item[name] or (2) item[customcss] parameter in a
wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or the
itemid parameter in the (3) wonderplugin_audio_show_item or (4)
wonderplugin_audio_edit_item page to wp-admin/admin.php.
|
| CVE-2015-2217 |
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate PHP
Board (aka myUPB) before 2.2.8 allow remote attackers to inject
arbitrary web script or HTML via the (1) q parameter to search.php or
(2) avatar parameter to profile.php.
|
| CVE-2015-2198 |
Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php
in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web
script or HTML via the (1) homepage_url, (2) pic_url, or (3)
avatar_url parameter, which are not properly handled in an error
message.
|
| CVE-2015-2197 |
Cross-site scripting (XSS) vulnerability in the Entity API module
before 7.x-1.6 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a field label in the Token API.
|
| CVE-2015-2195 |
Multiple cross-site scripting (XSS) vulnerabilities in the WP Media
Cleaner plugin 2.2.6 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) view, (2) paged, or (3) s
parameter in the wp-media-cleaner page to wp-admin/upload.php.
|
| CVE-2015-2182 |
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4
allow remote attackers to inject arbitrary web script or HTML via the
(1) schltr parameter in a brands action or (2) brand parameter in a
viewbrands action to index.php. NOTE: The search parameter vector is
already covered by CVE-2010-5322.
|
| CVE-2015-2169 |
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine
AssetExplorer 6.1 service pack 6112 allows remote attackers to inject
arbitrary web script or HTML via a Publisher registry entry, which is
not properly handled when the machine is scanned.
|
| CVE-2015-2165 |
Multiple cross-site scripting (XSS) vulnerabilities in the Report
Viewer in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4.x,
5.x, and 6.x allow remote attackers to inject arbitrary web script or
HTML via the (1) portal, (2) fromDate, (3) toDate, (4) fromTime, (5)
toTime, (6) kword, (7) uname, (8) pname, (9) sname, (10) atype, or
(11) atitle parameter to top-links.jsp; (12) portal or (13) uid
parameter to (a) page-summary.jsp or (b) service-summary.jsp; (14)
portal, (15) fromDate, (16) toDate, (17) fromTime, (18) toTime, (19)
sortDirection, (20) kword, (21) uname, (22) pname, (23) sname, (24)
file, (25) atype, or (26) atitle parameter to (c)
top-useragent-devices.jsp or (d) top-interest-areas.jsp; (27)
fromDate, (28) toDate, (29) fromTime, (30) toTime, (31) sortDirection,
(32) kword, (33) uname, (34) pname, (35) sname, (36) file, (37) atype,
or (38) atitle parameter to top-message-services.jsp; (39) portal,
(40) fromDate, (41) toDate, (42) fromTime, (43) toTime, (44) orderBy,
(45) sortDirection, (46) kword, (47) uname, (48) pname, (49) sname,
(50) file, (51) atype, or (52) atitle parameter to (e)
user-statistics.jsp, (f) top-web-pages.jsp, (g) top-devices.jsp, (h)
top-pages.jsp, (i) session-summary.jsp, (j) top-providers.jsp, (k)
top-modules.jsp, or (l) top-services.jsp; (53) fromDate, (54) toDate,
(55) fromTime, (56) toTime, (57) orderBy, (58) sortDirection, (59)
uid, (60) uid2, (61) kword, (62) uname, (63) pname, (64) sname, (65)
file, (66) atype, or (67) atitle parameter to
message-shortcode-summary.jsp; (68) fromDate, (69) toDate, (70)
fromTime, (71) toTime, (72) orderBy, (73) sortDirection, (74) uid,
(75) kword, (76) uname, (77) pname, (78) sname, (79) file, (80) atype,
or (81) atitle parameter to (m) message-providers-summary.jsp or (n)
message-services-summary.jsp; (82) kword, (83) uname, (84) pname, (85)
sname, (86) file, (87) atype, or (88) atitle parameter to
license-summary.jsp; (89) portal, (90) fromDate, (91) toDate, (92)
fromTime, (93) toTime, (94) orderBy, (95) sortDirection, (96) uid,
(97) uid2, (98) kword, (99) uname, (100) pname, (101) sname, (102)
file, (103) atype, or (104) atitle parameter to
useragent-device-summary.jsp; (105) fromDate, (106) toDate, (107)
fromTime, (108) toTime, (109) orderBy, (110) sortDirection, (111)
kword, (112) uname, (113) pname, (114) sname, (115) file, (116) atype,
or (117) atitle parameter to (o) top-message-providers.jsp, (p)
top-message-devices.jsp, (q) top-message-assets.jsp, (r)
top-message-downloads.jsp, or (s) top-message-shortcode.jsp; (118)
fromDate, (119) toDate, (120) fromTime, (121) toTime, (122) kword,
(123) uname, (124) pname, (125) sname, (126) file, (127) atype, or
(128) atitle parameter to request-summary.jsp; (129) portal parameter
to link-summary-select.jsp, (130) provider-summary-select.jsp, or
(131) module-summary-select.jsp; (132) portal, (133) uid, (134) kword,
(135) uname, (136) pname, (137) sname, (138) file, (139) atype, or
(140) atitle parameter to link-summary.jsp; (141) portal, (142)
fromDate, (143) toDate, (144) fromTime, (145) toTime, (146) orderBy,
(147) sortDirection, (148) uid, (149) kword, (150) uname, (151) pname,
(152) sname, (153) file, (154) atype, or (155) atitle parameter to (t)
provider-summary.jsp or (u) module-summary.jsp in reports/pages/.
|
| CVE-2015-2149 |
Multiple cross-site scripting (XSS) vulnerabilities in the administrative
backend in MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated
users to inject arbitrary web script or HTML via the (1) MIME-type field in
an add action in the config-attachment_types module to admin/index.php; (2)
title or (3) short description field in an add action in the (a)
config-mycode or (b) user-groups module to admin/index.php; (4) title field
in an add action in the (c) forum-management or (d) tool-tasks module to
admin/index.php; (5) name field in an add_set action in the style-templates
module to admin/index.php; (6) title field in an add_template_group action in
the style-templates module to admin/index.php; (7) name field in an add
action in the config-post_icons module to admin/index.php; (8) "title to
assign" field in an add action in the user-titles module to admin/index.php;
or (9) username field in the config-banning module to admin/index.php.
|
| CVE-2015-2148 |
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker
phpBugTracker before 1.7.2 allow remote attackers to inject arbitrary
web script or HTML via unspecified parameters.
|
| CVE-2015-2145 |
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker
phpBugTracker before 1.7.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified parameters.
|
| CVE-2015-2144 |
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker
phpBugTracker before 1.7.0 allow remote authenticated users to inject
arbitrary web script or HTML via the (1) project name parameter to
project.php; the (2) use_js parameter to user.php; the (3) use_js
parameter to group.php; the (4) Description parameter to status.php;
the (5) Description parameter to severity.php; the (6) Regex parameter
to os.php; or the (7) Name parameter to database.php.
|
| CVE-2015-2103 |
Cross-site scripting (XSS) vulnerability in the admin-login panel
(admin/index.cgi) in Cosmoshop allows remote attackers to inject
arbitrary web script or HTML via the username field (u_name
parameter).
|
| CVE-2015-2101 |
Cross-site scripting (XSS) vulnerability in the Navigate bar in the
Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-2089 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
CrossSlide jQuery (crossslide-jquery-plugin-for-wordpress) plugin
2.0.5 for WordPress allow remote attackers to hijack the
authentication of administrators for requests that (1) change plugin
settings or conduct cross-site scripting (XSS) attacks via the (2)
csj_width, (3) csj_height, (4) csj_sleep, (5) csj_fade, or (6)
upload_image parameter in the thisismyurl_csj.php page to
wp-admin/options-general.php.
|
| CVE-2015-2088 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Term Queue module before 6.x-1.1 for Drupal allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2015-2086 |
Cross-site scripting (XSS) vulnerability in the live preview in the
Panopoly Magic module before 7.x-1.17 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via a pane
title.
|
| CVE-2015-2084 |
Cross-site request forgery (CSRF) vulnerability in the Easy Social
Icons plugin before 1.2.3 for WordPress allows remote attackers to
hijack the authentication of administrators for requests that conduct
cross-site scripting (XSS) attacks via the image_file parameter in an
edit action in the cnss_social_icon_add page to wp-admin/admin.php.
|
| CVE-2015-2082 |
Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4
Prosoft HRMS before 8.14.330.43 allows remote attackers to inject
arbitrary web script or HTML via the txtUserID parameter.
|
| CVE-2015-2072 |
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73
(1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861)
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors to (1)
ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or
(2) xs/ide/editor/templates/trace/hanaTraceDetailService.xsjs, aka SAP
Note 2069676.
|
| CVE-2015-2069 |
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin
before 2.2.11 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the QUERY_STRING in the wc-reports
page to wp-admin/admin.php.
|
| CVE-2015-2068 |
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka
Magento Mass Importer) plugin for Magento Server allow remote
attackers to inject arbitrary web script or HTML via the (1) profile
parameter to web/magmi.php or (2) QUERY_STRING to
web/magmi_import_run.php.
|
| CVE-2015-2064 |
Multiple cross-site scripting (XSS) vulnerabilities in DLGuard 5, 4.6,
and 4.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) page, (2) c, or (3) redirect parameter to index.php or (4)
search field (searchTerm parameter) in the main page.
|
| CVE-2015-2046 |
Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later
before 1.2.20.
|
| CVE-2015-2043 |
Multiple cross-site scripting (XSS) vulnerabilities in Visualware
MyConnection Server 8.2b allow remote attackers to inject arbitrary
web script or HTML via the (1) bt, (2) variable, or (3) et parameter
to myspeed/db/historyitem.
|
| CVE-2015-2040 |
Cross-site scripting (XSS) vulnerability in the Contact Form DB (aka
CFDB and contact-form-7-to-database-extension) plugin 2.8.26 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the submit_time parameter in the CF7DBPluginSubmissions page
to wp-admin/admin.php.
|
| CVE-2015-2039 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Acobot Live Chat & Contact Form plugin 2.0 for WordPress allow remote
attackers to hijack the authentication of administrators for requests
that (1) change plugin settings or (2) conduct cross-site scripting
(XSS) attacks via the acobot_token parameter in the acobot page to
wp-admin/options-general.php.
|
| CVE-2015-2034 |
Cross-site scripting (XSS) vulnerability in the administrative backend
in Piwigo before 2.7.4 allows remote attackers to inject arbitrary web
script or HTML via the page parameter to admin.php.
|
| CVE-2015-2031 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme
Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2015-2026 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere
eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows
remote authenticated users to hijack the authentication of arbitrary
users for requests that insert XSS sequences.
|
| CVE-2015-2015 |
Cross-site scripting (XSS) vulnerability in pubnames.ntf (aka the
Directory template) in the web server in IBM Domino before 9.0.0
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL, aka SPR KLYH8WBPRN.
|
| CVE-2015-2014 |
Open redirect vulnerability in the web server in IBM Domino 8.5 before
8.5.3 FP6 IF9 and 9.0 before 9.0.1 FP4 allows remote attackers to
redirect users to arbitrary web sites and conduct phishing attacks or
cross-site scripting (XSS) attacks via a crafted URL, aka SPR
SJAR9DNGDA.
|
| CVE-2015-1997 |
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar
Vulnerability Manager 7.2.x before 7.2.5 Patch 5 allows remote
attackers to hijack the authentication of arbitrary users for requests
that insert XSS sequences.
|
| CVE-2015-1995 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Security
QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allow remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-1988 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage Manger
for Virtual Environments: Data Protection for VMware 6.3 before
6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 and Tivoli Storage
FlashCopy Manager for VMware 3.1 before 3.1.1.3, 3.2 before 3.2.0.6,
and 4.1 before 4.1.3.0 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-1983 |
Cross-site scripting (XSS) vulnerability in the Projects page in IBM
UrbanCode Build 6.1.x before 6.1.1 allows remote authenticated users
to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-1981 |
Cross-site scripting (XSS) vulnerability in the web server in IBM
Domino 8.5.x before 8.5.3 FP6 IF8 and 9.x before 9.0.1 FP4, when
Webmail is enabled, allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL, aka SPR KLYH9WYPR5.
|
| CVE-2015-1979 |
Multiple cross-site scripting (XSS) vulnerabilities in the Error
dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote
authenticated users to inject arbitrary web script or HTML via crafted
input to the (1) addressability or (2) comments component.
|
| CVE-2015-1978 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Security
Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before
iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix
2 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-1969 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Common
Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x
as used in Cognos Business Intelligence before 10.2 IF0015 and other
products, allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2015-1968 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data
Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4
before FP03 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2015-1966 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli
Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9,
and 6.2.2 before FP15, as used in Security Access Manager for Mobile
and other products, allow remote attackers to inject arbitrary web
script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION
and (2) TOKEN:RelayState macros.
|
| CVE-2015-1944 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0
before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-1919 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar
Incident Forensics before 7.2.5 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-1917 |
Cross-site scripting (XSS) vulnerability in the Active Content
Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6
CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0
before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-1911 |
Cross-site scripting (XSS) vulnerability in Sterling Order Management
8.5 before HF113, Sterling Selling and Fulfillment Foundation 9.0.0
before FP92, and Sterling Field Sales (SFS) 9.0 before HF7 in IBM
Sterling Selling and Fulfillment Suite allows remote attackers to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-1910 |
Cross-site scripting (XSS) vulnerability in the Reference Data
Management component in the server in IBM InfoSphere Master Data
Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted URL.
|
| CVE-2015-1908 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0
through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through
7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as
used in Web Content Manager and other products, allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-1906 |
Cross-site scripting (XSS) vulnerability in the REST API in IBM
Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through
8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6
through 8.5.6.0 allows remote authenticated users to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2015-1894 |
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere
Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to
hijack the authentication of arbitrary users for requests that insert
XSS sequences.
|
| CVE-2015-1888 |
Cross-site scripting (XSS) vulnerability in IBM Content Navigator
2.0.2 before 2.0.2-ICN-FP007 and 2.0.3 before 2.0.3-ICN-FP003, as used
in Content Manager, FileNet Content Manager, Content Foundation,
Content Manager OnDemand, and other products, allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2015-1880 |
Cross-site scripting (XSS) vulnerability in the sslvpn login page in
Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-1879 |
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder
plugin before 2.5.19 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the profile parameter in an edit
action in the gde-settings page to wp-admin/options-general.php.
|
| CVE-2015-1866 |
Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before
1.10.1 and 1.11.x before 1.11.2.
|
| CVE-2015-1864 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administration pages in Kallithea before 0.2.1 allow remote attackers
to inject arbitrary web script or HTML via the (1) first name or (2)
last name user details, or the (3) repository, (4) repository group,
or (5) user group description.
|
| CVE-2015-1813 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and
LTS before 1.596.2 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2015-1812.
|
| CVE-2015-1812 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and
LTS before 1.596.2 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2015-1813.
|
| CVE-2015-1773 |
Cross-site scripting (XSS) vulnerability in asdoc/templates/index.html
in Apache Flex before 4.14.1 allows remote attackers to inject
arbitrary web script or HTML by providing a crafted URI to JavaScript
code generated by the asdoc component.
|
| CVE-2015-1757 |
Cross-site scripting (XSS) vulnerability in adfs/ls in Active
Directory Federation Services (AD FS) in Microsoft Windows Server 2008
SP2 and R2 SP1 and Server 2012 allows remote attackers to inject
arbitrary web script or HTML via the wct parameter, aka "ADFS XSS
Elevation of Privilege Vulnerability."
|
| CVE-2015-1653 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote
attackers to inject arbitrary web script or HTML via a crafted
request, aka "Microsoft SharePoint XSS Vulnerability."
|
| CVE-2015-1640 |
Cross-site scripting (XSS) vulnerability in Microsoft Project Server
2010 SP2 and 2013 SP1 allows remote attackers to inject arbitrary web
script or HTML via a crafted request, aka "Microsoft SharePoint XSS
Vulnerability."
|
| CVE-2015-1639 |
Cross-site scripting (XSS) vulnerability in Microsoft Office for Mac
2011 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, aka "Microsoft Outlook App for Mac XSS
Vulnerability."
|
| CVE-2015-1636 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted request, aka "Microsoft SharePoint XSS
Vulnerability."
|
| CVE-2015-1633 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation
2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
|
| CVE-2015-1632 |
Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook
Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative
Update 7 allows remote attackers to inject arbitrary web script or
HTML via the msgParam parameter in an authError action, aka "Exchange
Error Message Cross Site Scripting Vulnerability."
|
| CVE-2015-1630 |
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in
Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka "Audit Report Cross Site Scripting Vulnerability."
|
| CVE-2015-1629 |
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in
Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka "ExchangeDLP Cross Site Scripting Vulnerability."
|
| CVE-2015-1628 |
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in
Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows
remote attackers to inject arbitrary web script or HTML via a crafted
X-OWA-Canary cookie in an AD.RecipientType.User action, aka "OWA
Modified Canary Parameter Cross Site Scripting Vulnerability."
|
| CVE-2015-1621 |
Cross-site scripting (XSS) vulnerability in the Webform prepopulate
block module before 7.x-3.1 for Drupal allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-1619 |
Cross-site scripting (XSS) vulnerability in the Secure Web Mail Client
user interface in McAfee Email Gateway (MEG) 7.6.x before 7.6.3.2,
7.5.x before 75.6, 7.0.x through 7.0.5, 5.6, and earlier allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified tokens in Digest messages.
|
| CVE-2015-1617 |
Cross-site scripting (XSS) vulnerability in the ePO extension in
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-1614 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Image Metadata Cruncher plugin for WordPress allow remote attackers to
hijack the authentication of administrators for requests that conduct
cross-site scripting (XSS) attacks via the (1)
image_metadata_cruncher[alt] or (2) image_metadata_cruncher[caption]
parameter in an update action in the image_metadata_cruncher_title
page to wp-admin/options.php or (3) custom image meta tag to the image
metadata cruncher page.
|
| CVE-2015-1604 |
Unrestricted file upload vulnerability in asys/site/files.php in
Adminsystems CMS before 4.0.2 allows remote authenticated users to
execute arbitrary code by uploading a file with an executable
extension, then accessing it via a direct request to the file in
upload/files/.
|
| CVE-2015-1603 |
Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems
CMS before 4.0.2 allow remote attackers to inject arbitrary web script
or HTML via the (1) page parameter to index.php or (2) id parameter in
a users_users action to asys/site/system.php.
|
| CVE-2015-1588 |
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange
Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and
7.6.1-rev21.
|
| CVE-2015-1582 |
Multiple cross-site scripting (XSS) vulnerabilities in the Spider
Facebook plugin before 1.0.11 for WordPress allow (1) remote attackers
to inject arbitrary web script or HTML via the appid parameter in a
registration task to the default URI or remote administrators to
inject arbitrary web script or HTML via the (2) asc_or_desc, (3)
order_by, (4) page_number, (5) serch_or_not, or (6)
search_events_by_title parameter in (a) the Spider_Facebook_manage
page to wp-admin/admin.php or a (b) selectpagesforfacebook or (c)
selectpostsforfacebook action to wp-admin/admin-ajax.php.
|
| CVE-2015-1581 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Mobile Domain plugin 1.5.2 for WordPress allow remote attackers to
hijack the authentication of administrators for requests that (1)
change plugin settings or conduct cross-site scripting (XSS) attacks
via the (2) domain, (3) text, (4) font, (5) fontcolor, (6) color, or
(7) padding parameter in an add-domain action in the mobile-domain
page to wp-admin/options-general.php.
|
| CVE-2015-1580 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Redirection Page plugin 1.2 for WordPress allow remote attackers to
hijack the authentication of administrators for requests that (1)
change plugin settings or conduct cross-site scripting (XSS) attacks
via the (2) source or (3) redir parameter in an add action in the
redirection-page to wp-admin/options-general.php.
|
| CVE-2015-1575 |
Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before
3.9.4 allow remote attackers to inject arbitrary web script or HTML
via the (1) c, (2) i, (3) l, or (4) p parameter to index.php; the (5)
a or (6) b parameter to u5admin/cookie.php; the name parameter to (7)
copy.php or (8) delete.php in u5admin/; the (9) f or (10) typ
parameter to u5admin/deletefile.php; the (11) n parameter to
u5admin/done.php; the (12) c parameter to u5admin/editor.php; the (13)
uri parameter to u5admin/meta2.php; the (14) n parameter to
u5admin/notdone.php; the (15) newname parameter to
u5admin/rename2.php; the (16) l parameter to u5admin/sendfile.php; the
(17) s parameter to u5admin/characters.php; the (18) page parameter to
u5admin/savepage.php; or the (19) name parameter to u5admin/new2.php.
|
| CVE-2015-1567 |
Cross-site scripting (XSS) vulnerability in the admin page in the GD
Infinite Scroll module before 7.x-1.4 for Drupal allows remote
authenticated users with the "edit gd infinite scroll settings"
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-1566 |
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before
7.4.0 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2015-1565 |
Cross-site scripting (XSS) vulnerability in the online help in Hitachi
Device Manager, Tiered Storage Manager, Replication Manager, and
Global Link Manager before 8.1.2-00, and Compute Systems Manager
before 7.6.1-08 and 8.x before 8.1.2-00, as used in Hitachi Command
Suite, allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2015-1564 |
Cross-site scripting (XSS) vulnerability in style-underground/search
in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to
inject arbitrary web script or HTML via the Search field.
|
| CVE-2015-1562 |
Multiple cross-site scripting (XSS) vulnerabilities in Saurus CMS
4.7.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) search parameter to admin/user_management.php, (2)
data_search parameter to /admin/profile_data.php, or (3) filter
parameter to error_log.php.
|
| CVE-2015-1516 |
Cross-site scripting (XSS) vulnerability in Polycom RealPresence
CloudAXIS Suite before 1.7.0 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-1512 |
Multiple cross-site scripting (XSS) vulnerabilities in FancyFon FAMOC
before 3.17.4 allow remote attackers to inject arbitrary web script or
HTML via the (1) LoginForm[username] to ui/system/login or the (2)
order or (3) myorgs to index.php.
|
| CVE-2015-1494 |
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not
properly restrict access, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an
update action to wp-admin/admin-post.php, as demonstrated by the
mfbfw[padding] parameter and exploited in the wild in February 2015.
|
| CVE-2015-1483 |
Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX
allows remote attackers to execute arbitrary JavaScript code via
unspecified vectors.
|
| CVE-2015-1482 |
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to
bypass authentication and obtain sensitive information via a websocket
connection to socket.io/1/.
|
| CVE-2015-1481 |
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization
administrators to gain privileges by creating a superuser account.
|
| CVE-2015-1478 |
Cross-site scripting (XSS) vulnerability in the CMSJunkie
J-ClassifiedsManager component for Joomla! allows remote attackers to
inject arbitrary web script or HTML via the view parameter to
/classifieds.
|
| CVE-2015-1475 |
Multiple cross-site scripting (XSS) vulnerabilities in my little forum
2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web
script or HTML via the (1) page or (2) category parameter to forum.php
or the (3) page or (4) order parameter to (a) board_entry.php or (b)
forum_entry.php.
|
| CVE-2015-1459 |
Cross-site scripting (XSS) vulnerability in Fortinet
FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary
web script or HTML via the operation parameter to cert/scep/.
|
| CVE-2015-1451 |
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet
FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to
inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP
Active Software Version field in a CAPWAP Join request.
|
| CVE-2015-1445 |
HTTP header injection in the httpd package in fli4l before 3.10.1 and
4.0 before 2015-01-30.
|
| CVE-2015-1444 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
administration frontend in the httpd package in fli4l before 3.10.1
and 4.0 before 2015-01-30 allow remote attackers to inject arbitrary
web script or HTML via the (1) conntrack.cgi, (2) index.cgi, (3)
log_syslog.cgi, (4) problems.cgi, (5) status.cgi, (6)
status_network.cgi, or (7) status_system.cgi script in admin/.
|
| CVE-2015-1443 |
The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30
allows remote attackers to execute arbitrary code.
|
| CVE-2015-1437 |
Multiple cross-site scripting (XSS) vulnerabilities in Asus RT-N10+ D1
router with firmware 2.1.1.1.70 allow remote attackers to inject
arbitrary web script or HTML via the flag parameter to (1)
result_of_get_changed_status.asp or (2) error_page.htm.
|
| CVE-2015-1436 |
Cross-site scripting (XSS) vulnerability in the Easing Slider plugin
before 2.2.0.7 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the edit parameter in the (1)
easingslider_manage_customizations or (2) easingslider_edit_sliders
page to wp-admin/admin.php.
|
| CVE-2015-1435 |
Cross-site scripting (XSS) vulnerability in my little forum before
2.3.4 allows remote attackers to inject arbitrary web script or HTML
via the back parameter to index.php.
|
| CVE-2015-1433 |
program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does
not properly quote strings, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via the style attribute in an
email.
|
| CVE-2015-1431 |
Cross-site scripting (XSS) vulnerability in includes/startup.php in
phpBB before 3.0.13 allows remote attackers to inject arbitrary web
script or HTML via vectors related to "Relative Path Overwrite."
|
| CVE-2015-1422 |
Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2
and 2.3 allow remote attackers to inject arbitrary web script or HTML
via the (1) horder[], (2) jak_catid, (3) jak_content, (4) jak_css, (5)
jak_delete_log[], (6) jak_email, (7) jak_extfile, (8) jak_file, (9)
jak_hookshow[], (10) jak_img, (11) jak_javascript, (12) jak_lcontent,
(13) jak_name, (14) jak_password, (15) jak_showcontact, (16) jak_tags,
(17) jak_title, (18) jak_url, (19) jak_username, (20) real_hook_id[],
(21) sp, (22) sreal_plugin_id[], (23) ssp, or (24) sssp parameter to
admin/index.php or the (25) editor, (26) field_id, (27) fldr, (28)
lang, (29) popup, (30) subfolder, or (31) type parameter to
js/editor/plugins/filemanager/dialog.php.
|
| CVE-2015-1404 |
Cross-site scripting (XSS) vulnerability in the Content Rating Extbase
extension 2.0.3 and earlier for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-1402 |
Cross-site scripting (XSS) vulnerability in the Content Rating
extension 1.0.3 and earlier for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-1389 |
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass
Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject
arbitrary web script or HTML via the username parameter to
tips/tipsLoginSubmit.action.
|
| CVE-2015-1385 |
Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress
Podcasting plugin before 6.0.1 for WordPress allows remote attackers
to inject arbitrary web script or HTML via the cat parameter in a
powerpress-editcategoryfeed action in the
powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.
|
| CVE-2015-1384 |
Cross-site scripting (XSS) vulnerability in the Banner Effect Header
plugin before 1.2.8 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the banner_effect_divid parameter in
the BannerEffectOptions page to wp-admin/options-general.php.
|
| CVE-2015-1383 |
Cross-site scripting (XSS) vulnerability in the geo search widget in
the Geo Mashup plugin before 1.8.3 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the search key.
|
| CVE-2015-1374 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack
the authentication of administrators for requests that conduct (1)
cross-site scripting (XSS), (2) SQL injection, or (3) unrestricted
file upload attacks.
|
| CVE-2015-1373 |
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in
ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web
script or HTML via the (1) action parameter in a search request, (2)
username in a login request, which is not properly handled when
logging the event, or (3) page title in an insert action.
|
| CVE-2015-1370 |
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for
Node.js allows remote attackers to conduct cross-site scripting (XSS)
attacks via a vbscript tag in a link.
|
| CVE-2015-1368 |
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower
(aka Ansible UI) before 2.0.5 allow remote attackers to inject
arbitrary web script or HTML via the (1) order_by parameter to
credentials/, (2) inventories/, (3) projects/, or (4)
users/3/permissions/ in api/v1/ or the (5) next_run parameter to
api/v1/schedules/.
|
| CVE-2015-1366 |
Cross-site scripting (XSS) vulnerability in pixabay-images.php in the
Pixabay Images plugin before 2.4 for WordPress allows remote attackers
to inject arbitrary web script or HTML via the image_user parameter.
|
| CVE-2015-1363 |
Cross-site scripting (XSS) vulnerability in Free Reprintables
ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script
or HTML via the q parameter to search/v/.
|
| CVE-2015-1347 |
Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket
before 1.9.5.1 allows remote attackers to inject arbitrary web script
or HTML via the lang parameter.
|
| CVE-2015-1286 |
Cross-site scripting (XSS) vulnerability in the
V8ContextNativeHandler::GetModuleSystem function in
extensions/renderer/v8_context_native_handler.cc in Google Chrome
before 44.0.2403.89 allows remote attackers to inject arbitrary web
script or HTML by leveraging the lack of a certain V8 context
restriction, aka a Blink "Universal XSS (UXSS)."
|
| CVE-2015-1285 |
The XSSAuditor::canonicalize function in
core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used
in Google Chrome before 44.0.2403.89, does not properly choose a
truncation point, which makes it easier for remote attackers to obtain
sensitive information via an unspecified linear-time attack.
|
| CVE-2015-1275 |
Cross-site scripting (XSS) vulnerability in
org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before
44.0.2403.89 on Android allows remote attackers to inject arbitrary
web script or HTML via a crafted intent: URL, as demonstrated by a
trailing alert(document.cookie);// substring, aka "Universal XSS
(UXSS)."
|
| CVE-2015-1264 |
Cross-site scripting (XSS) vulnerability in Google Chrome before
43.0.2357.65 allows user-assisted remote attackers to inject arbitrary
web script or HTML via crafted data that is improperly handled by the
Bookmarks feature.
|
| CVE-2015-1204 |
Cross-site scripting (XSS) vulnerability in the Save Filters
functionality in the WP Slimstat plugin before 3.9.2 for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
fs[resource] parameter in the wp-slim-view-2 page to
wp-admin/admin.php.
|
| CVE-2015-1180 |
Cross-site scripting (XSS) vulnerability in the Web Reports in
EventSentry 3.1.0 allows remote attackers to inject arbitrary web
script or HTML via the pageId parameter to networktile/bullet.
|
| CVE-2015-1179 |
Multiple cross-site scripting (XSS) vulnerabilities in
data_point_details.shtm in Mango Automation 2.4.0 and earlier allow
remote attackers to inject arbitrary web script or HTML via the (1)
dpid, (2) dpxid, or (3) pid parameter.
|
| CVE-2015-1178 |
Multiple cross-site scripting (XSS) vulnerabilities in cart.php in
X-Cart 5.1.8 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) product_id or (2) category_id
parameter.
|
| CVE-2015-1177 |
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.
|
| CVE-2015-1176 |
Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in
osTicket before 1.9.5 allows remote attackers to inject arbitrary web
script or HTML via the status parameter in a search action.
|
| CVE-2015-1175 |
Cross-site scripting (XSS) vulnerability in blocklayered-ajax.php in
the blocklayered module in PrestaShop 1.6.0.9 and earlier allows
remote attackers to inject arbitrary web script or HTML via the
layered_price_slider parameter.
|
| CVE-2015-1159 |
Cross-site scripting (XSS) vulnerability in the cgi_puts function in
cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows
remote attackers to inject arbitrary web script or HTML via the QUERY
parameter to help/.
|
| CVE-2015-1058 |
Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3
allow remote attackers to inject arbitrary web script or HTML via the
(1) data[Category][title] parameter to admin/categories/add, (2)
data[Field][title] parameter to admin/fields/ajax_fields/, (3) name
property in a basicInfo JSON object to admin/tools/create_theme, (4)
data[Link][link_title] parameter to admin/links/links/add, or (5)
data[ForumTopic][subject] parameter to forums/off-topic/new.
|
| CVE-2015-1057 |
Cross-site scripting (XSS) vulnerability in usersettings.php in e107
2.0.0 allows remote attackers to inject arbitrary web script or HTML
via the "Real Name" value.
|
| CVE-2015-1056 |
Cross-site scripting (XSS) vulnerability in Brother MFC-J4410DW
printer with firmware before L allows remote attackers to inject
arbitrary web script or HTML via the url parameter to
general/status.html and possibly other pages.
|
| CVE-2015-1054 |
Cross-site scripting (XSS) vulnerability in the Games feature in
Crea8Social 2.0 allows remote authenticated users to inject arbitrary
web script or HTML via the Game Content field in Add Game.
|
| CVE-2015-1053 |
Cross-site scripting (XSS) vulnerability in the administrative backend
in Croogo before 2.2.1 allows remote attackers to inject arbitrary web
script or HTML via the path parameter to
admin/file_manager/file_manager/editfile.
|
| CVE-2015-1052 |
Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT
1.6.6 (Build 160014) allows remote attackers to inject arbitrary web
script or HTML via the result parameter to
upload_files/pk/include.php.
|
| CVE-2015-1050 |
Cross-site scripting (XSS) vulnerability in F5 BIG-IP Application
Security Manager (ASM) before 11.6 allows remote attackers to inject
arbitrary web script or HTML via the Response Body field when creating
a new user account.
|
| CVE-2015-1041 |
Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php
in e107 1.0.4 allows remote attackers to inject arbitrary web script
or HTML via the e107_files/ file path in the QUERY_STRING.
|
| CVE-2015-1040 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative backend in BEdita 3.4.0 allow remote authenticated
users to inject arbitrary web script or HTML via the (1) lrealname
field in the editProfile form to index.php/home/profile; the (2)
data[title] or (3) data[description] field in the addQuickItem form to
index.php; the (4) "note text" field in the saveNote form to
index.php/areas; or the (5) titleBEObject or (6) tagsArea field in the
updateForm form to index.php/documents/view.
|
| CVE-2015-1039 |
Cross-site scripting (XSS) vulnerability in user/login.phtml in
ZF-Commons ZfcUser before 1.2.2 allows remote attackers to inject
arbitrary web script or HTML via the redirect parameter.
|
| CVE-2015-1032 |
Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when
using kiwix-serve, allows remote attackers to inject arbitrary web
script or HTML via the pattern parameter to /search.
|
| CVE-2015-1028 |
Multiple cross-site scripting (XSS) vulnerabilities in D-Link
DSL-2730B router (rev C1) with firmware GE_1.01 allow remote
authenticated users to inject arbitrary web script or HTML via the (1)
domainname parameter to dnsProxy.cmd (DNS Proxy Configuration Panel);
the (2) brName parameter to lancfg2get.cgi (Lan Configuration Panel);
the (3) wlAuthMode, (4) wl_wsc_reg, or (5) wl_wsc_mode parameter to
wlsecrefresh.wl (Wireless Security Panel); or the (6) wlWpaPsk
parameter to wlsecurity.wl (Wireless Password Viewer).
|
| CVE-2015-1026 |
Multiple cross-site scripting (XSS) vulnerabilities in ZOHO
ManageEngine ADManager Plus before 6.2 Build 6270 allow remote
attackers to inject arbitrary web script or HTML via the (1)
technicianSearchText parameter to the Help Desk Technician page or (2)
rolesSearchText parameter to the Help Desk Roles.
|
| CVE-2015-1000004 |
XSS in filedownload v1.4 wordpress plugin
|
| CVE-2015-0976 |
Cross-site scripting (XSS) vulnerability in Inductive Automation
Ignition 7.7.2 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2015-0967 |
Multiple cross-site scripting (XSS) vulnerabilities in SearchBlox
before 8.2 allow remote attackers to inject arbitrary web script or
HTML via (1) the search field in plugin/index.html or (2) the title
field in the Create Featured Result form in admin/main.jsp.
|
| CVE-2015-0950 |
Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6
through 5.1.10 allows remote attackers to inject arbitrary web script
or HTML via the substring parameter.
|
| CVE-2015-0937 |
Cross-site scripting (XSS) vulnerability in search.php on the Blue
Coat Malware Analysis appliance with software before
4.2.4.20150312-RELEASE allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-0920 |
Cross-site request forgery (CSRF) vulnerability in the Banner Effect
Header plugin 1.2.6 for WordPress allows remote attackers to hijack
the authentication of administrators for requests that conduct
cross-site scripting (XSS) attacks via the banner_effect_email
parameter in the BannerEffectOptions page to
wp-admin/options-general.php.
|
| CVE-2015-0918 |
Cross-site scripting (XSS) vulnerability in the administrative backend
in Sefrengo before 1.6.1 allows remote attackers to inject arbitrary
web script or HTML via the searchterm parameter to backend/main.php.
|
| CVE-2015-0917 |
Cross-site scripting (XSS) vulnerability in the backend in Kajona
before 4.6.3 allows remote attackers to inject arbitrary web script or
HTML via the action parameter to index.php.
|
| CVE-2015-0915 |
Cross-site scripting (XSS) vulnerability in RAKUS MailDealer 11.2.1
and earlier allows remote attackers to inject arbitrary web script or
HTML via a crafted attachment filename.
|
| CVE-2015-0913 |
Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-0910 |
Cross-site scripting (XSS) vulnerability in TAGAWA Takao TransmitMail
1.0.11 through 1.5.8 allows remote attackers to inject arbitrary web
script or HTML via a crafted filename.
|
| CVE-2015-0901 |
Cross-site scripting (XSS) vulnerability in the duwasai flashy theme
1.3 and earlier for WordPress allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-0900 |
Cross-site scripting (XSS) vulnerability in schedule.cgi in Nishishi
Factory Fumy Teacher's Schedule Board 1.10 through 2.21 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-0896 |
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer
before 2.1.7 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-0893 |
Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka
Relay Novel allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-0892 |
Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka
Image Album allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-0891 |
Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka
Simple Board allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-0882 |
Multiple cross-site scripting (XSS) vulnerabilities in zencart-ja (aka
Zen Cart Japanese edition) 1.3 jp through 1.3.0.2 jp8 and 1.5 ja
through 1.5.1 ja allow remote attackers to inject arbitrary web script
or HTML via a crafted parameter, related to
admin/includes/init_includes/init_sanitize.php and
includes/init_includes/init_sanitize.php.
|
| CVE-2015-0876 |
Multiple cross-site scripting (XSS) vulnerabilities in the
print_language_selectbox function in classes/adminpage.inc.php in
Saurus CMS Community Edition before 4.7 2015-02-04 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-0873 |
Cross-site scripting (XSS) vulnerability in Homepage Decorator
PerlTreeBBS 2.30 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-0871 |
Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI
shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-0870 |
Cross-site scripting (XSS) vulnerability in hb.cgi in Nishishi Factory
Fumy News Clipper 2.x before 2.5.0 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-0866 |
Multiple cross-site scripting (XSS) vulnerabilities in Zoho
ManageEngine SupportCenter Plus 7.9 before hotfix 7941 allow remote
attackers to inject arbitrary web script or HTML via the (1)
fromCustomer, (2) username, or (3) password parameter to HomePage.do.
|
| CVE-2015-0862 |
Multiple cross-site scripting (XSS) vulnerabilities in the management
web UI in the RabbitMQ management plugin before 3.4.3 allow remote
authenticated users to inject arbitrary web script or HTML via (1)
message details when a message is unqueued, such as headers or
arguments; (2) policy names, which are not properly handled when
viewing policies; (3) details for AMQP network clients, such as the
version; allow remote authenticated administrators to inject arbitrary
web script or HTML via (4) user names, (5) the cluster name; or allow
RabbitMQ cluster administrators to (6) modify unspecified content.
|
| CVE-2015-0787 |
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote
attackers to inject arbitrary HTML code via the accessMgrDN value of
the forgotUser.do CGI.
|
| CVE-2015-0774 |
Cross-site scripting (XSS) vulnerability in Cisco Application and
Content Networking System (ACNS) 5.5(9) allows remote attackers to
inject arbitrary web script or HTML via a crafted URL, aka Bug ID
CSCuu70650.
|
| CVE-2015-0766 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative web interface in the Management Center component in
Cisco FireSIGHT System Software 6.0.0 allow remote attackers to inject
arbitrary web script or HTML via unspecified fields, aka Bug IDs
CSCus93566, CSCut31557, and CSCut47196.
|
| CVE-2015-0762 |
Cross-site scripting (XSS) vulnerability in the management interface
in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) for Microsoft
Outlook allows remote attackers to inject arbitrary web script or HTML
via a crafted value in a URL, aka Bug ID CSCuu51400.
|
| CVE-2015-0752 |
Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video
Communication Server (VCS) X8.5.1 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635.
|
| CVE-2015-0738 |
Cross-site scripting (XSS) vulnerability in the Web Tracking Report
page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows
remote attackers to inject arbitrary web script or HTML via an
unspecified field, aka Bug ID CSCuu16008.
|
| CVE-2015-0737 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT
System Software 5.3.1.1 allow remote attackers to inject arbitrary web
script or HTML via a crafted (1) GET or (2) POST parameter, aka Bug ID
CSCuu11099.
|
| CVE-2015-0734 |
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Email
Security Appliance (ESA) 8.5.6-106 allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters in a (1) GET
or (2) POST request, aka Bug ID CSCut87743.
|
| CVE-2015-0733 |
CRLF injection vulnerability in the HTTP Header Handler in Digital
Broadband Delivery System in Cisco Headend System Release allows
remote attackers to inject arbitrary HTTP headers, and conduct HTTP
response splitting attacks or cross-site scripting (XSS) attacks, via
a crafted request, aka Bug ID CSCur25580.
|
| CVE-2015-0732 |
Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web
Security Appliance (WSA) 9.0.0-193; Email Security Appliance (ESA)
8.5.6-113, 9.1.0-032, 9.1.1-000, and 9.6.0-000; and Content Security
Management Appliance (SMA) 9.1.0-033 allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug IDs
CSCuu37430, CSCuu37420, CSCut71981, and CSCuv50167.
|
| CVE-2015-0729 |
Cross-site scripting (XSS) vulnerability in Cisco Secure Access
Control Server Solution Engine (ACSE) 5.5(0.1) allows remote attackers
to inject arbitrary web script or HTML via a file-inclusion attack,
aka Bug ID CSCuu11005.
|
| CVE-2015-0728 |
Cross-site scripting (XSS) vulnerability in Cisco Access Control
Server (ACS) 5.5(0.1) allows remote attackers to inject arbitrary web
script or HTML via a crafted URL, aka Bug ID CSCuu11002.
|
| CVE-2015-0727 |
Cross-site scripting (XSS) vulnerability in the HTTP module in Cisco
Security Manager (CSM) 4.7(0)SP1(1) allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27789.
|
| CVE-2015-0724 |
Multiple cross-site scripting (XSS) vulnerabilities in dncs 7.0.0.12
in Cisco Headend Digital Broadband Delivery System allow remote
attackers to inject arbitrary web script or HTML via unspecified
parameters in a (1) GET or (2) POST request, aka Bug ID CSCur25604.
|
| CVE-2015-0714 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse
Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers
to inject arbitrary web script or HTML via unspecified parameters, aka
Bug ID CSCut53595.
|
| CVE-2015-0707 |
Cross-site scripting (XSS) vulnerability in Cisco FireSIGHT System
Software 5.3.1.1 and 6.0.0 in FireSIGHT Management Center allows
remote authenticated users to inject arbitrary web script or HTML via
an unspecified parameter, aka Bug ID CSCus85425.
|
| CVE-2015-0703 |
Cross-site scripting (XSS) vulnerability in the administrative web
interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka Bug ID CSCus95857.
|
| CVE-2015-0698 |
Multiple cross-site scripting (XSS) vulnerabilities in filter search
forms in admin web pages on Cisco Web Security Appliance (WSA) devices
with software 8.5.0-497 allow remote attackers to inject arbitrary web
script or HTML via a crafted URL, aka Bug ID CSCut39213.
|
| CVE-2015-0696 |
Cross-site scripting (XSS) vulnerability in the login page in Cisco TC
Software before 7.1.0 on Cisco TelePresence Collaboration Desk and
Room Endpoints devices allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, aka Bug ID CSCuq94977.
|
| CVE-2015-0690 |
Cross-site scripting (XSS) vulnerability in the HTML help system on
Cisco Wireless LAN Controller (WLC) devices before 8.0 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL,
aka Bug ID CSCun95178.
|
| CVE-2015-0674 |
Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco
Cloud Web Security base revision allows remote attackers to inject
arbitrary web script or HTML via unspecified parameters.
|
| CVE-2015-0668 |
Cross-site scripting (XSS) vulnerability in the administration portal
in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka Bug ID CSCuq66737.
|
| CVE-2015-0656 |
Cross-site scripting (XSS) vulnerability in the login page in Cisco
Network Analysis Module (NAM) allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, aka Bug ID
CSCum81269.
|
| CVE-2015-0655 |
Cross-site scripting (XSS) vulnerability in Unified Web Interaction
Manager in Cisco Unified Web and E-Mail Interaction Manager allows
remote attackers to inject arbitrary web script or HTML via vectors
related to a POST request, aka Bug ID CSCus74184.
|
| CVE-2015-0634 |
Cross-site scripting (XSS) vulnerability in the administrative
interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka Bug ID CSCuq86310.
|
| CVE-2015-0623 |
Cross-site scripting (XSS) vulnerability in the Administrator report
page on Cisco Web Security Appliance (WSA) devices allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka Bug ID CSCus40627.
|
| CVE-2015-0594 |
Multiple cross-site scripting (XSS) vulnerabilities in the help pages
in Cisco Common Services, as used in Cisco Prime LAN Management
Solution (LMS) and Cisco Security Manager, allow remote attackers to
inject arbitrary web script or HTML via unspecified parameters, aka
Bug IDs CSCuq54654 and CSCun18263.
|
| CVE-2015-0577 |
Multiple cross-site scripting (XSS) vulnerabilities in the IronPort
Spam Quarantine (ISQ) page in Cisco AsyncOS, as used on the Cisco
Email Security Appliance (ESA) and Content Security Management
Appliance (SMA), allow remote attackers to inject arbitrary web script
or HTML via unspecified parameters, aka Bug IDs CSCus22925 and
CSCup08113.
|
| CVE-2015-0553 |
Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in
WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary web
script or HTML via the page_id parameter.
|
| CVE-2015-0551 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum
WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01;
Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0
before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital
Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7
before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2
before P23 allow remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-0549 |
Cross-site scripting (XSS) vulnerability in EMC Documentum D2 before
4.5 allows remote authenticated users to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2015-0526 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA
Validation Manager (RVM) 3.2 before build 201 allow remote attackers
to inject arbitrary web script or HTML via the (1) displayMode or (2)
wrapPreDisplayMode parameter.
|
| CVE-2015-0522 |
Cross-site scripting (XSS) vulnerability in EMC RSA Certificate
Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM)
before 6.9 build 558 allows remote attackers to inject arbitrary web
script or HTML via vectors related to the email address parameter.
|
| CVE-2015-0521 |
Cross-site scripting (XSS) vulnerability in EMC RSA Certificate
Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM)
before 6.9 build 558 allows remote authenticated users to inject
arbitrary web script or HTML via vectors related to the CMP shared
secret parameter.
|
| CVE-2015-0513 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1
and ViPR SRM before 3.6.1 allow remote authenticated users to inject
arbitrary web script or HTML by leveraging privileged access to set
crafted values of unspecified fields.
|
| CVE-2015-0345 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before
Update 16 and 11 before Update 5 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-0344 |
Cross-site scripting (XSS) vulnerability in the web app in Adobe
Connect before 9.4 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-0343 |
Cross-site scripting (XSS) vulnerability in admin/home/homepage/search
in the web app in Adobe Connect before 9.4 allows remote attackers to
inject arbitrary web script or HTML via the query parameter.
|
| CVE-2015-0299 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Source
Point of Sale 2.3.1 allow remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-0298 |
Cross-site scripting (XSS) vulnerability in the manager web interface
in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject
arbitrary web script or HTML via a crafted MCMP message.
|
| CVE-2015-0284 |
Cross-site scripting (XSS) vulnerability in spacewalk-java in
Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users
to inject arbitrary web script or HTML via crafted XML data to the
XMLRPC API, involving user details. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2014-7811.
|
| CVE-2015-0265 |
Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in
Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary
web script or HTML via the HTTP User-Agent header.
|
| CVE-2015-0220 |
The django.util.http.is_safe_url function in Django before 1.4.18,
1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle
leading whitespaces, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via a crafted URL, related to
redirect URLs, as demonstrated by a "\njavascript:" URL.
|
| CVE-2015-0216 |
access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not
set the RISK_XSS bit for graders, which allows remote authenticated
users to conduct cross-site scripting (XSS) attacks via crafted essay
feedback.
|
| CVE-2015-0212 |
Cross-site scripting (XSS) vulnerability in course/pending.php in
Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and
2.8.x before 2.8.2 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted course summary.
|
| CVE-2015-0195 |
Cross-site scripting (XSS) vulnerability in IBM Content Template
Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before
4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-0193 |
Cross-site scripting (XSS) vulnerability in IBM Business Process
Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x
through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through
7.2.0.5 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL that triggers an error condition.
|
| CVE-2015-0177 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0
before CF05 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2015-0176 |
Cross-site scripting (XSS) vulnerability in MQ XR WebSockets Listener
in WMQ Telemetry in IBM WebSphere MQ 8.0 before 8.0.0.2 allows remote
attackers to inject arbitrary web script or HTML via a crafted URI
that is included in an error response.
|
| CVE-2015-0168 |
Cross-site scripting (XSS) vulnerability in IBM Security SiteProtector
System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before
3.1.1.2 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-0167 |
Cross-site scripting (XSS) vulnerability in textAngular-sanitize.js in
textAngular before 1.3.7 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors to the editor.
|
| CVE-2015-0158 |
Cross-site scripting (XSS) vulnerability in the Coach NG framework in
IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through
8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-0156 |
Cross-site scripting (XSS) vulnerability in IBM Business Process
Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x
through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through
7.2.0.5 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2015-0145 |
Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC
Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and
7.1 before FP1 allows remote authenticated users to hijack the
authentication of arbitrary users for requests that insert XSS
sequences.
|
| CVE-2015-0144 |
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform
6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1
before FP1 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, a different vulnerability than
CVE-2014-8916.
|
| CVE-2015-0139 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0
through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-0131 |
Cross-site scripting (XSS) vulnerability in IBM Leads 7.x, 8.1.0
before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1,
9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before
9.1.1.0.2 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-0130 |
Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz
Foundation in IBM Rational Collaborative Lifecycle Management (CLM)
4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality
Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational
Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5;
Rational Requirements Composer (RRC) 4.x through 4.0.7; and Rational
DOORS Next Generation (RDNG) 4.x before 4.0.7 IF6 and 5.x before 5.0.2
IF5 allows remote authenticated users to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2015-0129 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality
Manager (RQM) 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted URL.
|
| CVE-2015-0128 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality
Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and
5.x before 5.0.2 allows remote authenticated users to inject arbitrary
web script or HTML via a crafted URL, a different vulnerability than
CVE-2015-0124.
|
| CVE-2015-0125 |
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next
Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational
Requirements Composer 4.x before 4.0.7 iFix3 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2015-0124 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality
Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and
5.x before 5.0.2 allows remote authenticated users to inject arbitrary
web script or HTML via a crafted URL, a different vulnerability than
CVE-2015-0128.
|
| CVE-2015-0123 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert
2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x
before 5.0.2 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, a different vulnerability than
CVE-2015-0122.
|
| CVE-2015-0122 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert
2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x
before 5.0.2 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, a different vulnerability than
CVE-2015-0123.
|
| CVE-2015-0109 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1
through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and
certain other products, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0108.
|
| CVE-2015-0108 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1
through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and
certain other products, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0109.
|
| CVE-2015-0106 |
Cross-site scripting (XSS) vulnerability in IBM Business Process
Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0
through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi
Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-0105 |
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM
Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through
8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2015-0103 |
Multiple cross-site scripting (XSS) vulnerabilities in the Process
Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3,
8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified data fields.
|
| CVE-2015-0101 |
Cross-site scripting (XSS) vulnerability in IBM Business Process
Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before
8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x
before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager
Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5.
|
| CVE-2015-0072 |
Cross-site scripting (XSS) vulnerability in Microsoft Internet
Explorer 9 through 11 allows remote attackers to bypass the Same
Origin Policy and inject arbitrary web script or HTML via vectors
involving an IFRAME element that triggers a redirect, a second IFRAME
element that does not trigger a redirect, and an eval of a WindowProxy
object, aka "Universal XSS (UXSS)."
|
| CVE-2014-9916 |
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) tribe_name or (2) tags parameter in a tribes page request to user/
or the (3) user_id or (4) fullname parameter to signup.php.
|
| CVE-2014-9905 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web
Calendar in SOGo before 2.2.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) title of an appointment or
(2) contact fields.
|
| CVE-2014-9772 |
The validator package before 2.0.0 for Node.js allows remote attackers
to bypass the cross-site scripting (XSS) filter via hex-encoded
characters.
|
| CVE-2014-9760 |
Cross-site scripting (XSS) vulnerability in the displayLogin function
in html/index.php in GOsa allows remote attackers to inject arbitrary
web script or HTML via the username.
|
| CVE-2014-9758 |
Cross-site scripting (XSS) vulnerability in Magento E-Commerce
Platform 1.9.0.1.
|
| CVE-2014-9743 |
Cross-site scripting (XSS) vulnerability in the httpd_HtmlError
function in network/httpd.c in the web interface in VideoLAN VLC Media
Player before 2.2.0 allows remote attackers to inject arbitrary web
script or HTML via the path info.
|
| CVE-2014-9741 |
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for
Desktop, ArcGIS for Engine, and ArcGIS for Server 10.2.2 and earlier
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-9740 |
Cross-site scripting (XSS) vulnerability in the Rules Link module
7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users
with the "administer rules links" permission to inject arbitrary web
script or HTML via unspecified vectors, which are not properly handled
in the (1) question and (2) description strings in a confirmation form
for a triggering Rules link.
|
| CVE-2014-9739 |
Cross-site scripting (XSS) vulnerability in the Node Field module
7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
unspecified vectors involving internal fields.
|
| CVE-2014-9738 |
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament
module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via an (1) account username, a (2) node title, or a (3) team entity
title.
|
| CVE-2014-9716 |
Cross-site scripting (XSS) vulnerability in WebODF before 0.5.4 allows
remote attackers to inject arbitrary web script or HTML via a file
name.
|
| CVE-2014-9714 |
Cross-site scripting (XSS) vulnerability in the
WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual
Machine) before 3.5.0 allows remote attackers to inject arbitrary web
script or HTML via a crafted string to the wddx_serialize_value
function.
|
| CVE-2014-9711 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web
Security and Filter, Web Security Gateway, and Web Security Gateway
Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow
remote attackers to inject arbitrary web script or HTML via the (1)
ReportName (Job Name) parameter to the Explorer report scheduler
(cgi-bin/WsCgiExplorerSchedule.exe) in the Job Queue or the col
parameter to the (2) Names or (3) Anonymous
(explorer_wse/explorer_anon.exe) summary report page.
|
| CVE-2014-9701 |
Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and
1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary
web script or HTML via the url parameter to permalink_page.php.
|
| CVE-2014-9685 |
Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums
before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-9678 |
FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers
to conduct content-spoofing attacks via the Swfile parameter.
|
| CVE-2014-9677 |
Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in
Flexpaper before 2.3.1 allows remote attackers to inject arbitrary web
script or HTML via the Swfile parameter.
|
| CVE-2014-9650 |
CRLF injection vulnerability in the management plugin in RabbitMQ
2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject
arbitrary HTTP headers and conduct HTTP response splitting attacks via
the download parameter to api/definitions.
|
| CVE-2014-9649 |
Cross-site scripting (XSS) vulnerability in the management plugin in
RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to
inject arbitrary web script or HTML via the path info to api/, which
is not properly handled in an error message.
|
| CVE-2014-9599 |
Cross-site scripting (XSS) vulnerability in the filemanager in
b2evolution before 5.2.1 allows remote attackers to inject arbitrary
web script or HTML via the fm_filter parameter to blogs/admin.php.
|
| CVE-2014-9582 |
Cross-site scripting (XSS) vulnerability in
components/filemanager/dialog.php in Codiad 2.4.3 allows remote
attackers to inject arbitrary web script or HTML via the short_name
parameter in a rename action. NOTE: this issue was originally
incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more
information.
|
| CVE-2014-9580 |
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly
cFTP) r561 allows remote attackers to inject arbitrary web script or
HTML via the Description field in a file upload. NOTE: this issue was
originally incorrectly mapped to CVE-2014-1155; see CVE-2014-1155 for
more information.
|
| CVE-2014-9571 |
Cross-site scripting (XSS) vulnerability in admin/install.php in
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote
attackers to inject arbitrary web script or HTML via the (1)
admin_username or (2) admin_password parameter.
|
| CVE-2014-9570 |
Multiple cross-site scripting (XSS) vulnerabilities in the
MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for
WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) datefilter parameter in the access_log page to
wp-admin/users.php or (2) simple_security_ip_blacklist[] parameter in
an add_blacklist_ip action in the ip_blacklist page to
wp-admin/users.php.
|
| CVE-2014-9569 |
Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver
Business Client (NWBC) for HTML 3.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) title or (2) roundtrips
parameter, aka SAP Security Note 2051285.
|
| CVE-2014-9564 |
CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet
and IB6131 40Gb Infiniband Switch firmware before 3.4.1110 allows
remote attackers to inject arbitrary HTTP headers and conduct HTTP
response splitting attacks and resulting web cache poisoning or
cross-site scripting (XSS) attacks, or obtain sensitive information
via multiple unspecified parameters.
|
| CVE-2014-9562 |
Cross-site scripting (XSS) vulnerability in display_dialog.php in M2
OptimalSite 0.1 and 2.4 allows remote attackers to inject arbitrary
web script or HTML via the image parameter.
|
| CVE-2014-9561 |
Cross-site scripting (XSS) vulnerability in redir_last_post_list.php
in SoftBB 0.1.3 allows remote attackers to inject arbitrary web script
or HTML via the post parameter.
|
| CVE-2014-9559 |
Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1,
and 1.0b2 allows remote attackers to inject arbitrary web script or
HTML via the query parameter to /snipsnap-search.
|
| CVE-2014-9557 |
Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2.
|
| CVE-2014-9528 |
SQL injection vulnerability in the actionIndex function in
protected/modules_core/notification/controllers/ListController.php in
HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to
execute arbitrary SQL commands via the from parameter to index.php.
NOTE: this can be leveraged for cross-site scripting (XSS) attacks via
a request that causes an error.
|
| CVE-2014-9526 |
Multiple cross-site scripting (XSS) vulnerabilities in concrete5
5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) gName parameter in
single_pages/dashboard/users/groups/bulkupdate.php or (2) instance_id
parameter in tools/dashboard/sitemap_drag_request.php.
|
| CVE-2014-9525 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Timed Popup (wp-timed-popup) plugin 1.3 for WordPress allow remote
attackers to hijack the authentication of administrators for requests
that (1) change plugin settings via unspecified vectors or (2) conduct
cross-site scripting (XSS) attacks via the sc_popup_subtitle parameter
in the wp-popup.php page to wp-admin/options-general.php.
|
| CVE-2014-9524 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Facebook Like Box (cardoza-facebook-like-box) plugin before 2.8.3 for
WordPress allow remote attackers to hijack the authentication of
administrators for requests that (1) change plugin settings via
unspecified vectors or conduct cross-site scripting (XSS) attacks via
the (2) frm_title, (3) frm_url, (4) frm_border_color, (5) frm_width,
or (6) frm_height parameter in the slug_for_fb_like_box page to
wp-admin/admin.php.
|
| CVE-2014-9523 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Our
Team Showcase (our-team-enhanced) plugin before 1.3 for WordPress
allow remote attackers to hijack the authentication of administrators
for requests that (1) change plugin settings via unspecified vectors
or (2) conduct cross-site scripting (XSS) attacks via the
sc_our_team_member_count parameter in the sc_team_settings page to
wp-admin/edit.php.
|
| CVE-2014-9522 |
Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light
6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web script
or HTML via the (1) author field to guestbook.php or (2) username
field to account.php.
|
| CVE-2014-9518 |
Cross-site scripting (XSS) vulnerability in login.cgi in D-Link router
DIR-655 (rev Bx) with firmware before 2.12b01 allows remote attackers
to inject arbitrary web script or HTML via the html_response_page
parameter.
|
| CVE-2014-9517 |
Cross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103
with firmware before 1.20 allows remote attackers to inject arbitrary
web script or HTML via the QUERY_STRING to vb.htm.
|
| CVE-2014-9516 |
Cross-site scripting (XSS) vulnerability in Social Microblogging PRO
1.5 allows remote attackers to inject arbitrary web script or HTML via
the PATH_INFO to the default URI, related to the "Web Site" input in
the Profile section.
|
| CVE-2014-9514 |
Cross-site scripting (XSS) vulnerability in BMC Footprints Service
Core 11.5.
|
| CVE-2014-9507 |
MediaWiki 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when
$wgContentHandlerUseDB is enabled, allows remote attackers to conduct
cross-site scripting (XSS) attacks by setting the content model for a
revision to JS.
|
| CVE-2014-9505 |
Cross-site scripting (XSS) vulnerability in the School Administration
module 7.x-1.x before 7.x-1.8 for Drupal allows remote authenticated
users with permission to create or edit a class node to inject
arbitrary web script or HTML via a node title.
|
| CVE-2014-9501 |
Cross-site scripting (XSS) vulnerability in the Poll Chart Block
module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated
users to inject arbitrary web script or HTML via a poll node title.
|
| CVE-2014-9500 |
Cross-site scripting (XSS) vulnerability in the Moip module 7.x-1.x
before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors to the notification page
callback.
|
| CVE-2014-9499 |
Cross-site scripting (XSS) vulnerability in the Godwin's Law module
before 7.x-1.1 for Drupal, when using the dblog module, allows remote
authenticated users to inject arbitrary web script or HTML via a
Watchdog message.
|
| CVE-2014-9498 |
Cross-site scripting (XSS) vulnerability in the Webform Invitation
module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.4 for Drupal
allows remote authenticated users with the Webform: Create new
content, Webform: Edit own content, or Webform: Edit any content
permission to inject arbitrary web script or HTML via a node title.
|
| CVE-2014-9480 |
Cross-site scripting (XSS) vulnerability in the Hovercards extension
for MediaWiki allows remote attackers to inject arbitrary web script
or HTML via vectors related to text extracts.
|
| CVE-2014-9479 |
Cross-site scripting (XSS) vulnerability in the preview in the
TemplateSandbox extension for MediaWiki allows remote attackers to
inject arbitrary web script or HTML via the text parameter to
Special:TemplateSandbox.
|
| CVE-2014-9478 |
Cross-site scripting (XSS) vulnerability in the preview in the
ExpandTemplates extension for MediaWiki, when $wgRawHTML is set to
true, allows remote attackers to inject arbitrary web script or HTML
via the wpInput parameter to the Special:ExpandTemplates page.
|
| CVE-2014-9477 |
Multiple cross-site scripting (XSS) vulnerabilities in the Listings
extension for MediaWiki allow remote attackers to inject arbitrary web
script or HTML via the (1) name or (2) url parameter.
|
| CVE-2014-9475 |
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki
before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x
before 1.24.1 allows remote authenticated users to inject arbitrary
web script or HTML via a wikitext message.
|
| CVE-2014-9469 |
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0,
3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
|
| CVE-2014-9468 |
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP
InstantForum.NET 4.1.3, 4.1.2, 4.1.1, 4.0.0, 4.1.0, and 3.4.0 allow
remote attackers to inject arbitrary web script or HTML via the
SessionID parameter to (1) Join.aspx or (2) Logon.aspx.
|
| CVE-2014-9460 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
WP-ViperGB plugin before 1.3.11 for WordPress allow remote attackers
to hijack the authentication of administrators for requests that (1)
change plugin settings via unspecified vectors or conduct cross-site
scripting (XSS) attacks via the (2) vgb_page or (3) vgb_items_per_pg
parameter in the wp-vipergb page to wp-admin/options-general.php.
|
| CVE-2014-9454 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Simple Sticky Footer plugin before 1.3.3 for WordPress allow remote
attackers to hijack the authentication of administrators for requests
that (1) change plugin settings via unspecified vectors or conduct
cross-site scripting (XSS) attacks via the (2) simple_sf_width or (3)
simple_sf_style parameter in the simple-simple-sticky-footer page to
wp-admin/themes.php.
|
| CVE-2014-9453 |
Multiple cross-site scripting (XSS) vulnerabilities in
simple-visitor-stat.php in the Simple visitor stat plugin for
WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) HTTP User-Agent or (2) HTTP Referer header.
|
| CVE-2014-9446 |
Multiple cross-site scripting (XSS) vulnerabilities in the Staff
client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote
attackers to inject arbitrary web script or HTML via the sort_by
parameter to the (1) opac parameter in opac-search.pl or (2) intranet
parameter in catalogue/search.pl.
|
| CVE-2014-9445 |
SQL injection vulnerability in incl/create.inc.php in Installatron GQ
File Manager 0.2.5 allows remote attackers to execute arbitrary SQL
commands via the create parameter to index.php. NOTE: this can be
leveraged for cross-site scripting (XSS) attacks by creating a file
that generates an error. NOTE: this issue was originally incorrectly
mapped to CVE-2014-1137; see CVE-2014-1137 for more information.
|
| CVE-2014-9444 |
Cross-site scripting (XSS) vulnerability in the Frontend Uploader
plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the errors[fu-disallowed-mime-type][0][name]
parameter to the default URI.
|
| CVE-2014-9443 |
Cross-site scripting (XSS) vulnerability in the Relevanssi plugin
before 3.3.8 for WordPress allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-9441 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers
to hijack the authentication of administrators for requests that (1)
change plugin settings via unspecified vectors or conduct cross-site
scripting (XSS) attacks via the (2) ll__opt[image2_url] or (3)
ll__opt[image3_url] parameter in a ll_save_settings action to
wp-admin/admin-ajax.php.
|
| CVE-2014-9439 |
Cross-site scripting (XSS) vulnerability in Easy File Sharing Web
Server 6.8 allows remote attackers to inject arbitrary web script or
HTML via the username field during registration, which is not properly
handled by forum.ghp.
|
| CVE-2014-9437 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Sliding Social Icons plugin 1.61 for WordPress allow remote attackers
to hijack the authentication of administrators for requests that (1)
change plugin settings via unspecified vectors or (2) conduct
cross-site scripting (XSS) attacks via the sc_social_slider_margin
parameter in a wpbs_save_settings action in the wpbs_panel page to
wp-admin/admin.php.
|
| CVE-2014-9435 |
Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow
remote authenticated users to execute arbitrary SQL commands via the
(1) sectionID parameter to admin/managersection.php, (2) userID
parameter to admin/edituser.php, (3) username parameter to
admin/admin.php, or (4) title parameter to admin/managerrelated.php.
|
| CVE-2014-9434 |
Cross-site scripting (XSS) vulnerability in admin/managerrelated.php
in the administrative backend in Absolut Engine 1.73 allows remote
authenticated users to inject arbitrary web script or HTML via the
title parameter.
|
| CVE-2014-9433 |
Multiple cross-site scripting (XSS) vulnerabilities in
cms/front_content.php in Contenido before 4.9.6, when advanced mod
rewrite (AMR) is disabled, allow remote attackers to inject arbitrary
web script or HTML via the (1) idart, (2) lang, or (3) idcat
parameter.
|
| CVE-2014-9432 |
Multiple cross-site scripting (XSS) vulnerabilities in
templates/2k11/admin/overview.inc.tpl in Serendipity before 2.0-rc2
allow remote attackers to inject arbitrary web script or HTML via a
blog comment in the QUERY_STRING to serendipity/index.php.
|
| CVE-2014-9430 |
Cross-site scripting (XSS) vulnerability in
httpd/cgi-bin/vpn.cgi/vpnconfig.dat in Smoothwall Express 3.0 SP3
allows remote attackers to inject arbitrary web script or HTML via the
COMMENT parameter in an Add action.
|
| CVE-2014-9429 |
Multiple cross-site scripting (XSS) vulnerabilities in Smoothwall
Express 3.1 and 3.0 SP3 allow remote attackers to inject arbitrary web
script or HTML via the (1) PROFILENAME parameter in a Save action to
httpd/cgi-bin/pppsetup.cgi or (2) COMMENT parameter in an Add action
to httpd/cgi-bin/ddns.cgi.
|
| CVE-2014-9413 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the IP
Ban (simple-ip-ban) plugin 1.2.3 for WordPress allow remote attackers
to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks via the (1) ip_list, (2)
user_agent_list, or (3) redirect_url parameter in the simple-ip-ban
page to wp-admin/options-general.php.
|
| CVE-2014-9412 |
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access
Manager (NAM) 4.x before 4.1 allow remote attackers to inject
arbitrary web script or HTML via (1) an arbitrary parameter to
roma/jsp/debug/debug.jsp or (2) an arbitrary parameter in a
debug.DumpAll action to nps/servlet/webacc, a different issue than
CVE-2014-5216.
|
| CVE-2014-9401 |
Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts
Automatically plugin 0.7 and earlier for WordPress allows remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via the
lpa_post_letters parameter in the wp-limit-posts-automatically.php
page to wp-admin/options-general.php.
|
| CVE-2014-9400 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Wp
Unique Article Header Image plugin 1.0 and earlier for WordPress allow
remote attackers to hijack the authentication of administrators for
requests that conduct cross-site scripting (XSS) attacks via the (1)
gt_default_header or (2) gt_homepage_header parameter in the
wp-unique-header.php page to wp-admin/options-general.php.
|
| CVE-2014-9399 |
Cross-site request forgery (CSRF) vulnerability in the TweetScribe
plugin 1.1 and earlier for WordPress allows remote attackers to hijack
the authentication of administrators for requests that conduct
cross-site scripting (XSS) attacks via the tweetscribe_username
parameter in a save action in the tweetscribe.php page to
wp-admin/options-general.php.
|
| CVE-2014-9398 |
Cross-site request forgery (CSRF) vulnerability in the Twitter
LiveBlog plugin 1.1.2 and earlier for WordPress allows remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via the
mashtlb_twitter_username parameter in the twitter-liveblog.php page to
wp-admin/options-general.php.
|
| CVE-2014-9397 |
Cross-site request forgery (CSRF) vulnerability in the twimp-wp plugin
for WordPress allows remote attackers to hijack the authentication of
administrators for requests that conduct cross-site scripting (XSS)
attacks via the message_format parameter in the twimp-wp.php page to
wp-admin/options-general.php.
|
| CVE-2014-9396 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
SimpleFlickr plugin 3.0.3 and earlier for WordPress allow remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via the (1)
simpleflickr_width, (2) simpleflickr_bgcolor, or (3)
simpleflickr_xmldatapath parameter in the simpleFlickr.php page to
wp-admin/options-general.php.
|
| CVE-2014-9395 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Simplelife plugin 1.2 and earlier for WordPress allow remote attackers
to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks via the (1)
simplehoverback, (2) simplehovertext, (3) flickrback, or (4)
simple_flimit parameter in the simplelife.php page to
wp-admin/options-general.php.
|
| CVE-2014-9394 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
PWGRandom plugin 1.11 and earlier for WordPress allow remote attackers
to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks via the (1) pwgrandom_title
or (2) pwgrandom_category parameter in the pwgrandom page to
wp-admin/options-general.php.
|
| CVE-2014-9393 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Post
to Twitter plugin 0.7 and earlier for WordPress allow remote attackers
to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks via the (1)
idptt_twitter_username or (2) idptt_tweet_prefix parameter to
wp-admin/options-general.php.
|
| CVE-2014-9392 |
Cross-site request forgery (CSRF) vulnerability in the PictoBrowser
(pictobrowser-gallery) plugin 0.3.1 and earlier for WordPress allows
remote attackers to hijack the authentication of administrators for
requests that conduct cross-site scripting (XSS) attacks via the
pictoBrowserFlickrUser parameter in the options-page.php page to
wp-admin/options-general.php.
|
| CVE-2014-9391 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
gSlideShow plugin 0.1 and earlier for WordPress allow remote attackers
to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks via the (1) rss, (2)
display_time or (3) transistion_time parameter in the gslideshow.php
page to wp-admin/options-general.php.
|
| CVE-2014-9368 |
Cross-site request forgery (CSRF) vulnerability in the twitterDash
plugin 2.1 and earlier for WordPress allows remote attackers to hijack
the authentication of administrators for requests that conduct
cross-site scripting (XSS) attacks via the username_twitterDash
parameter in the twitterDash.php page to wp-admin/options-general.php.
|
| CVE-2014-9367 |
Incomplete blacklist vulnerability in the urlEncode function in
lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to
conduct cross-site scripting (XSS) attacks via a "'" (single quote) in
the scope parameter to do/view/TWiki/WebSearch.
|
| CVE-2014-9364 |
Cross-site scripting (XSS) vulnerability in the Unified Login form in
the LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-9362 |
Cross-site scripting (XSS) vulnerability in the path-based meta tag
editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for
Drupal allows remote authenticated users with the "Edit path based
meta tags" permission to inject arbitrary web script or HTML via
vectors related to deleting a Path-based Metatag.
|
| CVE-2014-9360 |
XML external entity (XXE) vulnerability in Scalix Web Access
11.4.6.12377 and 12.2.0.14697 allows remote attackers to read
arbitrary files and trigger requests to intranet servers via a crafted
request.
|
| CVE-2014-9352 |
Cross-site scripting (XSS) vulnerability in the mail administration
login panel in Scalix Web Access 11.4.6.12377 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-9349 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/robots.lib.php in RobotStats 1.0 allow remote attackers to
inject arbitrary web script or HTML via the (1) nom or (2) user_agent
parameter to admin/robots.php.
|
| CVE-2014-9346 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via vectors related to the (1) taxonomy
term title for instances with Save term lineage enabled or (2) entity
type fields.
|
| CVE-2014-9342 |
Cross-site scripting (XSS) vulnerability in the tree view
(pl_tree.php) feature in Application Security Manager (ASM) in F5
BIG-IP 11.3.0 allows remote attackers to inject arbitrary web script
or HTML by accessing a crafted URL during automatic policy generation.
|
| CVE-2014-9341 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the yURL
ReTwitt plugin 1.4 and earlier for WordPress allow remote attackers to
hijack the authentication of administrators for requests that conduct
cross-site scripting (XSS) attacks via the (1) yurl_login or (2)
yurl_anchor parameter in the yurl page to
wp-admin/options-general.php.
|
| CVE-2014-9340 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
wpCommentTwit plugin 0.5 and earlier for WordPress allow remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via the (1) username
or (2) password parameter in the wpCommentTwit.php page to
wp-admin/options-general.php.
|
| CVE-2014-9339 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
SPNbabble plugin 1.4.1 and earlier for WordPress allow remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via the (1) username
or (2) password parameter in the spnbabble.php page to
wp-admin/options-general.php.
|
| CVE-2014-9338 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
O2Tweet plugin 0.0.4 and earlier for WordPress allow remote attackers
to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks via the (1) o2t_username or
(2) o2t_tags parameter to wp-admin/options-general.php.
|
| CVE-2014-9337 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Mikiurl Wordpress Eklentisi plugin 2.0 and earlier for WordPress allow
remote attackers to hijack the authentication of administrators for
requests that conduct cross-site scripting (XSS) attacks via the (1)
twitter_kullanici or (2) twitter_sifre parameter in a kaydet action in
the mikiurl.php page to wp-admin/options-general.php.
|
| CVE-2014-9336 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
iTwitter plugin 0.04 and earlier for WordPress allow remote attackers
to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks via the (1)
itex_t_twitter_username or (2) itex_t_twitter_userpass parameter in
the iTwitter.php page to wp-admin/options-general.php.
|
| CVE-2014-9335 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
DandyID Services plugin 1.5.9 and earlier for WordPress allow remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via the (1)
email_address or (2) sidebarTitle parameter in the
dandyid-services.php page to wp-admin/options-general.php.
|
| CVE-2014-9334 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird
Feeder plugin 1.2.3 for WordPress allow remote attackers to hijack the
authentication of administrators for requests that conduct cross-site
scripting (XSS) attacks via the (1) user or (2) password parameter in
the bird-feeder page to wp-admin/options-general.php.
|
| CVE-2014-9325 |
Multiple cross-site scripting (XSS) vulnerabilities in TWiki 6.0.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) QUERYSTRING variable in lib/TWiki.pm or (2) QUERYPARAMSTRING
variable in lib/TWiki/UI/View.pm, as demonstrated by the QUERY_STRING
to do/view/Main/TWikiPreferences.
|
| CVE-2014-9311 |
Cross-site scripting (XSS) vulnerability in admin.php in the
Shareaholic plugin before 7.6.1.0 for WordPress allows remote
authenticated users to inject arbitrary web script or HTML via the
location[id] parameter in a shareaholic_add_location action to
wp-admin/admin-ajax.php.
|
| CVE-2014-9310 |
Cross-site scripting (XSS) vulnerability in the WordPress Backup to
Dropbox plugin before 4.1 for WordPress.
|
| CVE-2014-9281 |
Cross-site scripting (XSS) vulnerability in admin/copy_field.php in
MantisBT before 1.2.18 allows remote attackers to inject arbitrary web
script or HTML via the dest_id field.
|
| CVE-2014-9276 |
Cross-site request forgery (CSRF) vulnerability in the
Special:ExpandedTemplates page in MediaWiki before 1.19.22, 1.20.x
through 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when
$wgRawHTML is set to true, allows remote attackers to hijack the
authentication of users with edit permissions for requests that
cross-site scripting (XSS) attacks via the wpInput parameter, which is
not properly handled in the preview.
|
| CVE-2014-9272 |
The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x
before 1.2.18 does not properly validate the URL protocol, which
allows remote attackers to conduct cross-site scripting (XSS) attacks
via the javascript:// protocol.
|
| CVE-2014-9271 |
Cross-site scripting (XSS) vulnerability in file_download.php in
MantisBT before 1.2.18 allows remote authenticated users to inject
arbitrary web script or HTML via a Flash file with an image extension,
related to inline attachments, as demonstrated by a .swf.jpeg
filename.
|
| CVE-2014-9270 |
Cross-site scripting (XSS) vulnerability in the
projax_array_serialize_for_autocomplete function in
core/projax_api.php in MantisBT 1.1.0a3 through 1.2.17 allows remote
attackers to inject arbitrary web script or HTML via the
"profile/Platform" field.
|
| CVE-2014-9269 |
Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT
1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is
enabled, allows remote attackers to inject arbitrary web script or
HTML via the project cookie.
|
| CVE-2014-9253 |
The default file type whitelist configuration in conf/mime.conf in the
Media Manager in DokuWiki before 2014-09-29b allows remote attackers
to execute arbitrary web script or HTML by uploading an SWF file, then
accessing it via the media parameter to lib/exe/fetch.php.
|
| CVE-2014-9243 |
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker
2.8.3 allow remote attackers to inject arbitrary web script or HTML
via the (1) QUERY_STRING to wb/admin/admintools/tool.php or (2)
section_id parameter to edit_module_files.php, (3) news/add_post.php,
(4) news/modify_group.php, (5) news/modify_post.php, or (6)
news/modify_settings.php in wb/modules/.
|
| CVE-2014-9241 |
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka
MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject
arbitrary web script or HTML via the (1) type parameter to report.php,
(2) signature parameter in a do_editsig action to usercp.php, or (3)
title parameter in the style-templates module in an edit_template
action or (4) file parameter in the config-languages module in an edit
action to admin/index.php.
|
| CVE-2014-9236 |
Cross-site scripting (XSS) vulnerability in php/edit_photos.php in
Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote
attackers to inject arbitrary web script or HTML via the (1)
photographer_id or (2) _crumb parameter.
|
| CVE-2014-9230 |
Cross-site scripting (XSS) vulnerability in the administration console
in the Enforce Server in Symantec Data Loss Prevention (DLP) before
12.5.2 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-9224 |
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the
Management Console server in the management server in Symantec
Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data
Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-9219 |
Cross-site scripting (XSS) vulnerability in the redirection feature in
url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to
inject arbitrary web script or HTML via the url parameter.
|
| CVE-2014-9212 |
Multiple cross-site scripting (XSS) vulnerabilities in Altitude uAgent
in Altitude uCI (Unified Customer Interaction) 7.5 allow remote
attackers to inject arbitrary web script or HTML via (1) an email
hyperlink or the (2) style parameter in the image attribute section.
|
| CVE-2014-9179 |
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket
System plugin 1.2.5 for WordPress allows remote authenticated users to
inject arbitrary web script or HTML via the "URL (optional)" field in
a new ticket.
|
| CVE-2014-9176 |
Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy
Squeeze Pages plugin for WordPress allows remote attackers to inject
arbitrary web script or HTML via the id parameter to lp/index.php.
|
| CVE-2014-9174 |
Cross-site scripting (XSS) vulnerability in the Google Analytics by
Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the "Manually enter your UA code" (manual_ua_code_field)
field in the General Settings.
|
| CVE-2014-9153 |
Cross-site scripting (XSS) vulnerability in the Services module
7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users
to inject arbitrary web script or HTML via the callback parameter in a
JSONP response.
|
| CVE-2014-9146 |
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS
2.0.1.8 allow remote attackers to inject arbitrary web script or HTML
via the (1) view, (2) id, (3) page, or (4) app parameter to the
default URI or the (5) act parameter to dapur/index.php.
|
| CVE-2014-9144 |
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote
attackers to execute arbitrary commands via shell metacharacters in
the ping field (setobject_ip parameter).
|
| CVE-2014-9143 |
Open redirect vulnerability in Technicolor Router TD5130 with firmware
2.05.C29GV allows remote attackers to redirect users to arbitrary web
sites and conduct phishing attacks via a URL in the failrefer
parameter.
|
| CVE-2014-9142 |
Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130
with firmware 2.05.C29GV allows remote attackers to inject arbitrary
web script or HTML via the failrefer parameter.
|
| CVE-2014-9129 |
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds
CM Downloads Manager plugin before 2.0.7 for WordPress allows remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via the addons_title
parameter in the CMDM_admin_settings page to wp-admin/admin.php.
|
| CVE-2014-9120 |
Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to subrion/search/.
|
| CVE-2014-9103 |
Multiple cross-site scripting (XSS) vulnerabilities in the Kunena
component before 3.0.6 for Joomla! allow remote attackers to inject
arbitrary web script or HTML via the (1) index value of an array
parameter or the filename parameter in the Content-Disposition header
to the (2) file or (3) profile image upload functionality.
|
| CVE-2014-9101 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0
(build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote
attackers to hijack the authentication of administrators for requests that
conduct cross-site scripting (XSS) attacks or possibly have other unspecified
impact via the (1) label parameter to admin/users/roles/, (2)
lang[1][base][questions_account_type_5615100a931845eca8da20cfdf7327e0] in an
AddAccountType action or (3) qst_name parameter in an addQuestion action to
admin/questions/ajax-responder/, or (4) form_name or (5) restrictedUsername
parameter to admin/restricted-usernames.
|
| CVE-2014-9100 |
Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense
plugin 1.2 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the idcode parameter in the whydowork_adsense
page to wp-admin/options-general.php.
|
| CVE-2014-9098 |
Multiple cross-site scripting (XSS) vulnerabilities in the Apptha
WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
before 2014-07-23, for WordPress allow remote authenticated users to
inject arbitrary web script or HTML via the videoadssearchQuery
parameter to (1) videoads/videoads.php, (2) video/video.php, or (3)
playlist/playlist.php.
|
| CVE-2014-9094 |
Multiple cross-site scripting (XSS) vulnerabilities in
deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video
Gallery plugin for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) swfloc or (2) designrand
parameter.
|
| CVE-2014-9059 |
lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x
before 2.6.6, and 2.7.x before 2.7.3 does not provide charset
information in HTTP headers, which might allow remote attackers to
conduct cross-site scripting (XSS) attacks via UTF-7 characters during
interaction with AJAX scripts.
|
| CVE-2014-9042 |
Cross-site scripting (XSS) vulnerability in the import functionality
in the bookmarks application in ownCloud before 5.0.18, 6.x before
6.0.6, and 7.x before 7.0.3 allows remote authenticated users to
inject arbitrary web script or HTML by importing a link with an
unspecified protocol. NOTE: this can be leveraged by remote attackers
using CVE-2014-9041.
|
| CVE-2014-9036 |
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5,
3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows
remote attackers to inject arbitrary web script or HTML via a crafted
Cascading Style Sheets (CSS) token sequence in a post.
|
| CVE-2014-9035 |
Cross-site scripting (XSS) vulnerability in Press This in WordPress
before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before
4.0.1 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-9032 |
Cross-site scripting (XSS) vulnerability in the media-playlists
feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-9031 |
Cross-site scripting (XSS) vulnerability in the wptexturize function
in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3
allows remote attackers to inject arbitrary web script or HTML via
crafted use of shortcode brackets in a text field, as demonstrated by
a comment or a post.
|
| CVE-2014-9021 |
Multiple cross-site scripting (XSS) vulnerabilities in ZTE ZXDSL 831
allow remote attackers to inject arbitrary web script or HTML via the
(1) tr69cAcsURL, (2) tr69cAcsUser, (3) tr69cAcsPwd, (4)
tr69cConnReqPwd, or (5) tr69cDebugEnable parameter to the TR-069
client page (tr69cfg.cgi); the (6) timezone parameter to the Time and
date page (sntpcfg.sntp); or the (7) hostname parameter in a save
action to the Quick Stats page (psilan.cgi). NOTE: this issue was
SPLIT from CVE-2014-9020 per ADT1 due to different affected products
and codebases.
|
| CVE-2014-9020 |
Cross-site scripting (XSS) vulnerability in the Quick Stats page
(psilan.cgi) in ZTE ZXDSL 831 and 831CII allows remote attackers to
inject arbitrary web script or HTML via the domainname parameter in a
save action. NOTE: this issue was SPLIT from CVE-2014-9021 per ADT1
due to different affected products and codebases.
|
| CVE-2014-9019 |
Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE
ZXDSL 831CII allow remote attackers to hijack the authentication of
administrators for requests that (1) change the admin user name or (2)
conduct cross-site scripting (XSS) attacks via the sysUserName
parameter in a save action to adminpasswd.cgi or (3) change the admin
user password via the sysPassword parameter in a save action to
adminpasswd.cgi.
|
| CVE-2014-9017 |
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19
(build 23338) allows remote authenticated users to inject arbitrary
web script or HTML via the Subject field in a Task to
frontend/index.jsp.
|
| CVE-2014-9004 |
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1
allows remote attackers to inject arbitrary web script or HTML via the
id parameter in a member_profile action to index.php.
|
| CVE-2014-8996 |
Multiple cross-site scripting (XSS) vulnerabilities in Nibbleblog
before 4.0.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) author_name or (2) content parameter to index.php.
|
| CVE-2014-8993 |
Cross-site scripting (XSS) vulnerability in the backend in
Open-Xchange (OX) AppSuite before 7.4.2-rev40, 7.6.0 before
7.6.0-rev32, and 7.6.1 before 7.6.1-rev11 allows remote attackers to
inject arbitrary web script or HTML via a crafted XHTML file with the
application/xhtml+xml MIME type.
|
| CVE-2014-8992 |
Cross-site scripting (XSS) vulnerability in
manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution
2.3.2-pl allows remote attackers to inject arbitrary web script or
HTML via the callback parameter.
|
| CVE-2014-8987 |
Cross-site scripting (XSS) vulnerability in the "set configuration"
box in the Configuration Report page (adm_config_report.php) in
MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject
arbitrary web script or HTML via the config_option parameter, a
different vulnerability than CVE-2014-8986.
|
| CVE-2014-8986 |
Cross-site scripting (XSS) vulnerability in the selection list in the
filters in the Configuration Report page (adm_config_report.php) in
MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject
arbitrary web script or HTML via a crafted config option, a different
vulnerability than CVE-2014-8987.
|
| CVE-2014-8960 |
Cross-site scripting (XSS) vulnerability in
libraries/error_report.lib.php in the error-reporting feature in
phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted filename.
|
| CVE-2014-8958 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12
allow remote authenticated users to inject arbitrary web script or
HTML via a crafted (1) database, (2) table, or (3) column name that is
improperly handled during rendering of the table browse page; a
crafted ENUM value that is improperly handled during rendering of the
(4) table print view or (5) zoom search page; or (6) a crafted
pma_fontsize cookie that is improperly handled during rendering of the
home page.
|
| CVE-2014-8957 |
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19
allows remote authenticated users to inject arbitrary web script or
HTML via the Tasks parameter.
|
| CVE-2014-8955 |
Cross-site scripting (XSS) vulnerability in the Contact Form Clean and
Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0
and earlier for WordPress allows remote attackers to inject arbitrary
web script or HTML via the cscf[name] parameter to contact-us/.
|
| CVE-2014-8954 |
Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) Title or (2) Description fields in a playlist or the (3) filter
parameter in an explore action to index.php.
|
| CVE-2014-8925 |
Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in
IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before
8.0.0.14, and 8.0.1.x before 8.0.1.7 allows remote attackers to hijack
the authentication of arbitrary users for requests that trigger a
logout or insert XSS sequences.
|
| CVE-2014-8917 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
dojox/form/resources/uploader.swf (aka upload.swf), (2)
dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3)
dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in
the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before
IF11 and other products, allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-8916 |
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform
6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1
before FP1 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, a different vulnerability than
CVE-2015-0144.
|
| CVE-2014-8914 |
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM
Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1,
and 8.5.5 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, a different vulnerability than
CVE-2014-8913.
|
| CVE-2014-8913 |
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM
Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1,
and 8.5.5 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL, a different vulnerability than
CVE-2014-8914.
|
| CVE-2014-8911 |
Cross-site scripting (XSS) vulnerability in IBM Content Navigator
2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 before 2.0.3.2
FP002 allows remote attackers to inject arbitrary web script or HTML
via the Accept-Language HTTP header.
|
| CVE-2014-8909 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal
6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x
through 7.0.0.2 CF29, 8.0.0.x before 8.0.0.1 CF15, and 8.5.0 before
CF05 allows remote authenticated users to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2014-8902 |
Cross-site scripting (XSS) vulnerability in the Blog Portlet in IBM
WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3
CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and
8.5.0 before CF04 allows remote attackers to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2014-8899 |
Cross-site scripting (XSS) vulnerability in the Collaboration Server
in IBM InfoSphere Master Data Management Server for Product
Information Management 9.x through 9.1 and InfoSphere Master Data
Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7,
and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL, a different
vulnerability than CVE-2014-8897 and CVE-2014-8898.
|
| CVE-2014-8898 |
Cross-site scripting (XSS) vulnerability in the Collaboration Server
in IBM InfoSphere Master Data Management Server for Product
Information Management 9.x through 9.1 and InfoSphere Master Data
Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7,
and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL, a different
vulnerability than CVE-2014-8897 and CVE-2014-8899.
|
| CVE-2014-8897 |
Cross-site scripting (XSS) vulnerability in the Collaboration Server
in IBM InfoSphere Master Data Management Server for Product
Information Management 9.x through 9.1 and InfoSphere Master Data
Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7,
and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL, a different
vulnerability than CVE-2014-8898 and CVE-2014-8899.
|
| CVE-2014-8893 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
mainpage.jsp and (2) GetImageServlet.img in IBM TRIRIGA Application
Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allow
remote authenticated users to inject arbitrary web script or HTML via
a crafted URL.
|
| CVE-2014-8869 |
Multiple cross-site scripting (XSS) vulnerabilities in
mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4)
plugin 1.x before 1.1.2 for Woltlab Burning Board 4.0 allow remote
attackers to inject arbitrary web script or HTML via the (1)
app_android_id or (2) app_kindle_url parameter.
|
| CVE-2014-8809 |
Multiple cross-site scripting (XSS) vulnerabilities in the WP
Symposium plugin before 14.11 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) text parameter in an
addComment action to ajax/profile_functions.php, (2) compose_text
parameter in a sendMail action to ajax/mail_functions.php, (3) comment
parameter in an add_comment action to ajax/lounge_functions.php, or
(4) name parameter in a create_album action to
ajax/gallery_functions.php.
|
| CVE-2014-8800 |
Cross-site scripting (XSS) vulnerability in
nextend-facebook-settings.php in the Nextend Facebook Connect plugin
before 1.5.1 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the fb_login_button parameter in a
newfb_update_options action.
|
| CVE-2014-8793 |
Cross-site scripting (XSS) vulnerability in
lib/max/Admin/UI/Field/PublisherIdField.php in Revive Adserver before
3.0.6 allows remote attackers to inject arbitrary web script or HTML
via the refresh_page parameter to www/admin/report-generate.php.
|
| CVE-2014-8774 |
Cross-site scripting (XSS) vulnerability in manager/index.php in MODX
Revolution 2.x before 2.2.15 allows remote attackers to inject
arbitrary web script or HTML via the context_key parameter.
|
| CVE-2014-8772 |
Cross-site scripting (XSS) vulnerability in the search_controller in
X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticated users to inject
arbitrary web script or HTML via the search parameter.
|
| CVE-2014-8765 |
Multiple cross-site scripting (XSS) vulnerabilities in the Project
Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for
Drupal allow (1) remote attackers to inject arbitrary web script or
HTML via a crafted patch, which triggers a PIFR client to test the
patch and return the results to the PIFR_Server test results page or
(2) remote authenticated users with the "manage PIFR environments"
permission to inject arbitrary web script or HTML via vectors
involving a PIFR_Server administrative page.
|
| CVE-2014-8758 |
Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin
before 3.0.70for WordPress allows remote attackers to inject arbitrary
web script or HTML via the order_id parameter in the
gallery_album_sorting page to wp-admin/admin.php.
|
| CVE-2014-8753 |
Multiple cross-site scripting (XSS) vulnerabilities in Cit-e-Net
Cit-e-Access 6.
|
| CVE-2014-8752 |
Multiple cross-site scripting (XSS) vulnerabilities in view.php in
JCE-Tech PHP Video Script (aka Video Niche Script) 4.0 allow remote
attackers to inject arbitrary web script or HTML via the (1) video or
(2) title parameter.
|
| CVE-2014-8751 |
Multiple cross-site scripting (XSS) vulnerabilities in goYWP WebPress
13.00.06 allow remote attackers to inject arbitrary web script or HTML
via the (1) search_param parameter to search.php or (2) name, (3)
address, or (4) comment parameter to forms.php.
|
| CVE-2014-8748 |
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for
Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows
remote authenticated users with the "administer dfp" permission to
inject arbitrary web script or HTML via a slot name.
|
| CVE-2014-8747 |
Cross-site scripting (XSS) vulnerability in the Drupal Commons module
7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject
arbitrary web script or HTML via vectors related to content creation
and activity stream messages.
|
| CVE-2014-8746 |
Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2
through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated
users with the "administer themes" permission to inject arbitrary web
script or HTML via vectors related to theme settings.
|
| CVE-2014-8745 |
Cross-site scripting (XSS) vulnerability in the Custom Search module
6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows
remote authenticated users with the "administer taxonomy" permission
to inject arbitrary web script or HTML via a taxonomy vocabulary
label.
|
| CVE-2014-8744 |
Cross-site scripting (XSS) vulnerability in the Nivo Slider module
7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users
with the "administer nivo slider" permission to inject arbitrary web
script or HTML via an image title.
|
| CVE-2014-8743 |
Multiple cross-site scripting (XSS) vulnerabilities in the Maestro
module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via a (1) Role or (2) Organic Group name.
|
| CVE-2014-8732 |
Cross-site scripting (XSS) vulnerability in phpMemcachedAdmin 1.2.2
and earlier allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-8724 |
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin
before 0.9.4.1 for WordPress, when debug mode is enabled, allows
remote attackers to inject arbitrary web script or HTML via the "Cache
key" in the HTML-Comments, as demonstrated by the PATH_INFO to the
default URI.
|
| CVE-2014-8707 |
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2
allows remote authenticated users to inject arbitrary web script or
HTML via the "edit HTML source" option.
|
| CVE-2014-8703 |
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows
remote attackers to inject arbitrary web script or HTML.
|
| CVE-2014-8690 |
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS
before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, and 2.3.x before
2.3.1 patch 4 allow remote attackers to inject arbitrary web script or
HTML via the (1) PATH_INFO, the (2) src parameter in a none action to
index.php, or the (3) "First Name" or (4) "Last Name" field to
users/edituser.
|
| CVE-2014-8683 |
Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs
(aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.8 allows remote
attackers to inject arbitrary web script or HTML via the text
parameter to api/v1/markdown.
|
| CVE-2014-8672 |
Cross-site scripting (XSS) vulnerability in the RewardingYourself
application for Android and BlackBerry OS allows remote attackers to
inject arbitrary web script or HTML via a crafted QR code.
|
| CVE-2014-8671 |
Cross-site scripting (XSS) vulnerability in the GWT Mobile PhoneGap
Showcase application for Android allows remote attackers to inject
arbitrary web script or HTML via a crafted Bluetooth Device Name
field.
|
| CVE-2014-8667 |
Cross-site scripting (XSS) vulnerability in SAP HANA Web-based
Development Workbench allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-8658 |
Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme
3.x before 3.5.13 and 4.x before 4.0.12 for Confluence allows remote
authenticated users with permissions to create or edit content to
inject arbitrary web script or HTML via the versionComment parameter
to pages/doeditpage.action.
|
| CVE-2014-8653 |
Cross-site scripting (XSS) vulnerability in Compal Broadband Networks
(CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware
CH6640-3.5.11.7-NOSH allows remote attackers to inject arbitrary web
script or HTML via the userData cookie.
|
| CVE-2014-8629 |
Cross-site scripting (XSS) vulnerability in the Page visualization
agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to
inject arbitrary web script or HTML via the refr parameter to
index.php.
|
| CVE-2014-8622 |
Cross-site scripting (XSS) vulnerability in compfight-search.php in
the Compfight plugin 1.4 for WordPress allows remote authenticated
users to inject arbitrary web script or HTML via the search-value
parameter.
|
| CVE-2014-8619 |
Cross-site scripting (XSS) vulnerability in the autolearn
configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-8618 |
Cross-site scripting (XSS) vulnerability in the theme login page in
Fortinet FortiADC D models before 4.2 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-8617 |
Cross-site scripting (XSS) vulnerability in the Web Action Quarantine
Release feature in the WebGUI in Fortinet FortiMail before 4.3.9,
5.0.x before 5.0.8, 5.1.x before 5.1.5, and 5.2.x before 5.2.3 allows
remote attackers to inject arbitrary web script or HTML via the
release parameter to module/releasecontrol.
|
| CVE-2014-8616 |
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet
FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors to the (1) user group or
(2) vpn template menus.
|
| CVE-2014-8600 |
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime
4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras
5.1.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via a crafted URI using the (1) zip, (2) trash, (3)
tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8) remote, (9)
recentdocuments, (10) nntps, (11) nntp, (12) network, (13) mbox, (14)
ldaps, (15) ldap, (16) fonts, (17) file, (18) desktop, (19) cgi, (20)
bookmarks, or (21) ar scheme, which is not properly handled in an
error message.
|
| CVE-2014-8593 |
Multiple cross-site scripting (XSS) vulnerabilities in Allomani
Weblinks 1.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) default URI to admin.php or the (2) id parameter to
admin.php or (3) go.php.
|
| CVE-2014-8584 |
Cross-site scripting (XSS) vulnerability in the Web Dorado Spider
Video Player (aka WordPress Video Player) plugin before 1.5.2 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-8578 |
Cross-site scripting (XSS) vulnerability in the Groups panel in
OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2,
and Juno before Juno-2 allows remote administrators to inject arbitrary
web script or HTML via a user email address, a different vulnerability
than CVE-2014-3475.
|
| CVE-2014-8577 |
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before
2.1.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) data[Contact][title] parameter to
admin/contacts/contacts/add page; (2) data[Block][title] or (3)
data[Block][alias] parameter to admin/blocks/blocks/edit page; (4)
data[Region][title] parameter to admin/blocks/regions/add page; (5)
data[Menu][title] or (6) data[Menu][alias] parameter to
admin/menus/menus/add page; or (7) data[Link][title] parameter to
admin/menus/links/add/menu page.
|
| CVE-2014-8557 |
Multiple cross-site scripting (XSS) vulnerabilities in JExperts
Channel Platform 5.0.33_CCB allow remote attackers to inject arbitrary
web script or HTML via the (1) usuario.nome variable in an
editarUsuario action to usuario.do or (2) titulo.form variable in a
novoChamado action to ticket.do.
|
| CVE-2014-8539 |
Cross-site scripting (XSS) vulnerability in Simple Email Form 1.8.5
and earlier allows remote attackers to inject arbitrary web script or
HTML via the mod_simpleemailform_field2_1 parameter to index.php.
|
| CVE-2014-8521 |
Cross-site scripting (XSS) vulnerability in McAfee Network Data Loss
Prevention (NDLP) before 9.3 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-8508 |
Cross-site scripting (XSS) vulnerability in s_network.asp in the Denon
AVR-3313CI audio/video receiver allows remote attackers to inject
arbitrary web script or HTML via unspecified parameters, related to
Friendlyname.
|
| CVE-2014-8505 |
Multiple cross-site scripting (XSS) vulnerabilities in Etiko CMS allow
remote attackers to inject arbitrary web script or HTML via the (1)
page_id parameter to loja/index.php or (2) article_id parameter to
index.php.
|
| CVE-2014-8492 |
Multiple cross-site scripting (XSS) vulnerabilities in
assets/misc/fallback-page.php in the Profile Builder plugin before
2.0.3 for WordPress allow remote attackers to inject arbitrary web
script or HTML via the (1) site_name, (2) message, or (3) site_url
parameter.
|
| CVE-2014-8488 |
Cross-site scripting (XSS) vulnerability in the administrator panel in
Yourls 1.7 allows remote attackers to inject arbitrary web script or
HTML via a URL that is processed by the Shorten functionality.
|
| CVE-2014-8469 |
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in
Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary
web script or HTML via the User-Agent header.
|
| CVE-2014-8381 |
Multiple cross-site scripting (XSS) vulnerabilities in
Megapolis.Portal Manager allow remote attackers to inject arbitrary
web script or HTML via the (1) dateFrom or (2) dateTo parameter.
|
| CVE-2014-8380 |
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote
attackers to inject arbitrary web script or HTML via the HTTP Referer
Header in a "404 Not Found" response. NOTE: this vulnerability might
exist because of a CVE-2010-2429 regression.
|
| CVE-2014-8379 |
Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA
module before 7.x-1.5 for Drupal allow remote authenticated users with
certain permissions to inject arbitrary web script or HTML via vectors
related to field titles to the (1) Webform or (2) User sub-modules.
|
| CVE-2014-8378 |
Cross-site scripting (XSS) vulnerability in the TableField module
7.x-2.x before 7.x-2.3 allows remote authenticated users with the
"administer content types" or "administer taxonomy" permission to
inject arbitrary web script or HTML via vectors related to the field
help text in an entity edit form.
|
| CVE-2014-8377 |
Cross-site scripting (XSS) vulnerability in Webasyst Shop-Script
5.2.2.30933 allows remote attackers to inject arbitrary web script or
HTML via the phone number field in a new contact to
phpecom/index.php/webasyst/contacts/.
|
| CVE-2014-8376 |
Cross-site scripting (XSS) vulnerability in the context administration
sub-panel in the Site Banner module before 7.x-4.1 for Drupal allows
remote authenticated users with the "Administer contexts" Context UI
module permission to inject arbitrary web script or HTML via vectors
related to context settings.
|
| CVE-2014-8365 |
Multiple cross-site scripting (XSS) vulnerabilities in Xornic Contact
Us allow remote attackers to inject arbitrary web script or HTML via
the (1) name or (2) email parameter to contact.php or (3) PATH_INFO to
setup.php, related to the "PHP_SELF" variable.
|
| CVE-2014-8364 |
Cross-site scripting (XSS) vulnerability in ss_handler.php in the
WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the ss_id
parameter.
|
| CVE-2014-8352 |
Cross-site scripting (XSS) vulnerability in json.php in French
National Commission on Informatics and Liberty (aka CNIL) CookieViz
allows remote we servers to inject arbitrary web script or HTML via
the max_date parameter.
|
| CVE-2014-8351 |
SQL injection vulnerability in info.php in French National Commission
on Informatics and Liberty (aka CNIL) CookieViz before 1.0.1 allows
remote web servers to execute arbitrary SQL commands via the domain
parameter.
|
| CVE-2014-8349 |
Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise
Edition (EE) 6.2 SP8 and earlier allows remote authenticated users to
inject arbitrary web script or HTML via the _20_body parameter in the
comment field in an uploaded file.
|
| CVE-2014-8330 |
Cross-site scripting (XSS) vulnerability in EspoCRM allows remote
authenticated users to inject arbitrary web script or HTML via the
Name field in a new account.
|
| CVE-2014-8326 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before
4.2.10.1 allow remote authenticated users to inject arbitrary web
script or HTML via a crafted (1) database name or (2) table name,
related to the libraries/DatabaseInterface.class.php code for SQL
debug output and the js/server_status_monitor.js code for the server
monitor page.
|
| CVE-2014-8320 |
Cross-site scripting (XSS) vulnerability in the Custom Search module
6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via the "Label text" field to the results
configuration page.
|
| CVE-2014-8319 |
Cross-site scripting (XSS) vulnerability in the
easy_social_admin_summary function in the Easy Social module 7.x-2.x
before 7.x-2.11 for Drupal allows remote authenticated users with
certain permissions to inject arbitrary web script or HTML via a block
title.
|
| CVE-2014-8318 |
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x
before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before
7.x-4.0-beta2 for Drupal allows remote authenticated users with
certain permissions to inject arbitrary web script or HTML via a field
label title, when two fields have the same form_key.
|
| CVE-2014-8317 |
Cross-site scripting (XSS) vulnerability in the Webform Validation
module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.4 for Drupal
allows remote authenticated users with certain permissions to inject
arbitrary web script or HTML via a component name text.
|
| CVE-2014-8314 |
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA
Developer Edition Revision 70 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors to (1)
epm/admin/DataGen.xsjs or (2) epm/services/multiply.xsjs in the
democontent.
|
| CVE-2014-8308 |
Cross-site scripting (XSS) vulnerability in the Send to Inbox
functionality in SAP BusinessObjects BI EDGE 4.0 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-8307 |
Multiple cross-site scripting (XSS) vulnerabilities in
skins/default/outline.tpl in C97net Cart Engine before 4.0 allow
remote attackers to inject arbitrary web script or HTML via the (1)
path parameter in the "drop down TOP menu (with path)" section or (2)
print_this_page variable in the footer_content_block section, as
demonstrated by the QUERY_STRING to (a) index.php, (b) checkout.php,
(c) contact.php, (d) detail.php, (e) distro.php, (f) newsletter.php,
(g) page.php, (h) profile.php, (i) search.php, (j) sitemap.php, (k)
task.php, or (l) tell.php.
|
| CVE-2014-8306 |
SQL injection vulnerability in the sql_query function in cart.php in
C97net Cart Engine before 4.0 allows remote attackers to execute
arbitrary SQL commands via the item_id variable, as demonstrated by
the (1) item_id[0] or (2) item_id[] parameter.
|
| CVE-2014-8305 |
Open redirect vulnerability in the redir function in
includes/function.php in C97net Cart Engine before 4.0 allows remote
attackers to redirect users to arbitrary web sites and conduct
phishing attacks via a URL in the HTTP Referer header to (1)
index.php, (2) cart.php, (3) msg.php, or (4) page.php.
|
| CVE-2014-8304 |
Cross-site scripting (XSS) vulnerability in In-Portal CMS 5.2.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the next_template parameter to admin/index.php.
|
| CVE-2014-8303 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk
Enterprise 6.1.x before 6.1.4 and 6.0.x before 6.0.6 allows remote
attackers to inject arbitrary web script or HTML via vectors related
to event parsing.
|
| CVE-2014-8302 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk
Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.6, and 5.0.x before
5.0.10 allows remote attackers to inject arbitrary web script or HTML
via vectors related to dashboard.
|
| CVE-2014-8301 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk
Enterprise 5.0.x before 5.0.10 allows remote attackers to inject
arbitrary web script or HTML via the HTTP Referer header.
|
| CVE-2014-8296 |
Cross-site scripting (XSS) vulnerability in the Modal Frame API module
6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-8293 |
Cross-site scripting (XSS) vulnerability in Voice Of Web AllMyGuests
0.4.1 allows remote attackers to inject arbitrary web script or HTML
via the AMG_signin_topic parameter to index.php.
|
| CVE-2014-8267 |
Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the RID parameter.
|
| CVE-2014-8266 |
Multiple cross-site scripting (XSS) vulnerabilities in the
note-creation page in QPR Portal 2014.1.1 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1) title or
(2) body field.
|
| CVE-2014-8247 |
Cross-site scripting (XSS) vulnerability in CA Release Automation
(formerly iTKO LISA Release Automation) before 4.7.1 b448 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-8110 |
Multiple cross-site scripting (XSS) vulnerabilities in the web based
administration console in Apache ActiveMQ 5.x before 5.10.1 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-8087 |
Cross-site scripting (XSS) vulnerability in the post highlights plugin
before 2.6.1 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the txt parameter in a headline action to
ajax/ph_save.php.
|
| CVE-2014-8079 |
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x
before 7.x-1.3 for Drupal allows remote authenticated users with the
"administer themes" permission to inject arbitrary web script or HTML
via vectors related to header background setting.
|
| CVE-2014-8078 |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer,
e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x
before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via vectors related to nodes.
|
| CVE-2014-8077 |
Cross-site scripting (XSS) vulnerability in the NewsFlash theme
6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows
remote authenticated users with the "administer themes" permission to
inject arbitrary web script or HTML via vectors related to font family
CSS property.
|
| CVE-2014-8076 |
Cross-site scripting (XSS) vulnerability in the Professional theme 7.x
before 7.x-2.04 for Drupal allows remote authenticated users with the
"administer themes" permission to inject arbitrary web script or HTML
via vectors related to custom copyright information.
|
| CVE-2014-8075 |
Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x
and 7.x-3.x for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via a node title.
|
| CVE-2014-8071 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1
Standalone Edition allow remote attackers to inject arbitrary web
script or HTML via the (1) givenName, (2) familyName, (3) address1, or
(4) address2 parameter to registrationapp/registerPatient.page; the
(5) comment parameter to allergyui/allergy.page; the (6) w10 parameter
to htmlformentryui/htmlform/enterHtmlForm/submit.action; the (7) HTTP
Referer Header to login.htm; the (8) returnUrl parameter to
htmlformentryui/htmlform/enterHtmlFormWithStandardUi.page or (9)
coreapps/mergeVisits.page; or the (10) visitId parameter to
htmlformentryui/htmlform/enterHtmlFormWithSimpleUi.page.
|
| CVE-2014-8069 |
Multiple cross-site scripting (XSS) vulnerabilities in YOOtheme
Pagekit CMS 0.8.7 allow remote attackers to inject arbitrary web
script or HTML via the (1) HTTP Referer header to index.php/user or
(2) PATH_INFO to index.php.
|
| CVE-2014-8030 |
Cross-site scripting (XSS) vulnerability in sendPwMail.do in Cisco
WebEx Meetings Server allows remote attackers to inject arbitrary web
script or HTML via the email parameter, aka Bug ID CSCuj40381.
|
| CVE-2014-8028 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
framework in Cisco Secure Access Control System (ACS) allow remote
attackers to inject arbitrary web script or HTML via unspecified
parameters, aka Bug ID CSCuq79019.
|
| CVE-2014-8026 |
Cross-site scripting (XSS) vulnerability in the Guest Server in Cisco
Jabber allows remote attackers to inject arbitrary web script or HTML
via a (1) GET or (2) POST parameter, aka Bug ID CSCus08074.
|
| CVE-2014-8022 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Identity
Services Engine allow remote attackers to inject arbitrary web script
or HTML via input to unspecified web pages, aka Bug IDs CSCur69835 and
CSCur69776.
|
| CVE-2014-8021 |
Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure
Mobility Client 3.1(.02043) and earlier and Cisco HostScan Engine
3.1(.05183) and earlier allows remote attackers to inject arbitrary
web script or HTML via vectors involving an applet-path URL, aka Bug
IDs CSCup82990 and CSCuq80149.
|
| CVE-2014-8018 |
Multiple cross-site scripting (XSS) vulnerabilities in Business Voice
Services Manager (BVSM) pages in the Application Software in Cisco
Unified Communications Domain Manager 8 allow remote attackers to
inject arbitrary web script or HTML via a crafted URL, aka Bug IDs
CSCur19651, CSCur18555, CSCur19630, and CSCur19661.
|
| CVE-2014-8012 |
Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login
page in Cisco Adaptive Security Appliance (ASA) Software allows remote
attackers to inject arbitrary web script or HTML via crafted
attributes in a cookie, aka Bug ID CSCuh24695.
|
| CVE-2014-7987 |
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0
allows remote attackers to inject arbitrary web script or HTML via the
desc parameter in an errors action to install/index.php.
|
| CVE-2014-7983 |
Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS
3.1.2 through 3.2.x before 3.2.3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-7982 |
Cross-site scripting (XSS) vulnerability in Joomla! CMS 2.5.x before
2.5.19 and 3.x before 3.2.3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-7980 |
Multiple cross-site scripting (XSS) vulnerabilities in template.php in
Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal
allow remote authenticated users with the "administer themes"
permission to inject arbitrary web script or HTML via the
skip_link_text setting and unspecified other theme settings.
|
| CVE-2014-7979 |
Cross-site scripting (XSS) vulnerability in the SimpleCorp theme
7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users
with the "administer themes" permission to inject arbitrary web script
or HTML via vectors related to theme settings.
|
| CVE-2014-7978 |
Cross-site scripting (XSS) vulnerability in the BlueMasters theme
7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users
with the "administer themes" permission to inject arbitrary web script
or HTML via vectors related to theme settings.
|
| CVE-2014-7958 |
Cross-site scripting (XSS) vulnerability in
admin/htaccess/bpsunlock.php in the BulletProof Security plugin before
.51.1 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the dbhost parameter.
|
| CVE-2014-7957 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods
plugin before 2.5 for WordPress allow remote attackers to hijack the
authentication of administrators for requests that (1) conduct
cross-site scripting (XSS) attacks via the toggled parameter in a
toggle action in the pods-components page to wp-admin/admin.php, (2)
delete a pod in a delete action in the pods page to
wp-admin/admin.php, (3) reset pod settings and data via the pods_reset
parameter in the pod-settings page to wp-admin/admin.php, (4)
deactivate and reset pod data via the pods_reset_deactivate parameter
in the pod-settings page to wp-admin/admin.php, (5) delete the admin
role via the id parameter in a delete action in the
pods-component-roles-and-capabilities page to wp-admin/admin.php, or
(6) enable "roles and capabilities" in a toggle action in the
pods-components page to wp-admin/admin.php.
|
| CVE-2014-7956 |
Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5
for WordPress allows remote attackers to inject arbitrary web script
or HTML via the id parameter in an edit action in the pods page to
wp-admin/admin.php.
|
| CVE-2014-7896 |
Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000
Command View Advanced Edition Software Online Help, as used in HP
Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered
Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000
Replication Manager 6.x and 7.x before 7.6.1-06, and HP XP7 Global
Link Manager Software (aka HGLM) 6.x through 8.x before 8.1.2-00,
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-7881 |
Cross-site scripting (XSS) vulnerability in the server in HP Insight
Control allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-7870 |
Cross-site scripting (XSS) vulnerability in the Custom Search module
6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows
remote authenticated users with the "administer custom search"
permission to inject arbitrary web script or HTML via the "Label text"
field to admin/config/search/custom_search/results.
|
| CVE-2014-7869 |
Cross-site scripting (XSS) vulnerability in the configuration UI in
the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal
allows remote authenticated users with the "administer contexts"
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-7852 |
Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used
in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web
script or HTML via crafted URL, which is not properly handled in a CSS
file.
|
| CVE-2014-7850 |
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x
before 4.1.2 allows remote attackers to inject arbitrary web script or
HTML via vectors related to breadcrumb navigation.
|
| CVE-2014-7835 |
webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before
2.7.3 does not ensure that a file upload is for a private or draft
area, which allows remote authenticated users to upload files
containing JavaScript, and consequently conduct cross-site scripting
(XSS) attacks, by specifying the profile-picture area.
|
| CVE-2014-7830 |
Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php
in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9,
2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated
users to inject arbitrary web script or HTML by leveraging the
mod/feedback:mapcourse capability to provide a searchcourse parameter.
|
| CVE-2014-7812 |
Cross-site scripting (XSS) vulnerability in Spacewalk and Red Hat
Network (RHN) Satellite before 5.7.0 allows remote authenticated users
to inject arbitrary web script or HTML via the System Groups field.
|
| CVE-2014-7811 |
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and
Red Hat Network (RHN) Satellite before 5.7.0 allow remote
authenticated users to inject arbitrary web script or HTML via crafted
XML data to the REST API.
|
| CVE-2014-7297 |
Unspecified vulnerability in the folder framework in the Enfold theme
before 3.0.1 for WordPress has unknown impact and attack vectors.
|
| CVE-2014-7295 |
The (1) Special:Preferences and (2) Special:UserLogin pages in
MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.x before
1.23.5 allows remote authenticated users to conduct cross-site
scripting (XSS) attacks or have unspecified other impact via crafted
CSS, as demonstrated by modifying MediaWiki:Common.css.
|
| CVE-2014-7293 |
Cross-site scripting (XSS) vulnerability in the logon page in NYU
OpenSSO Integration 2.1 and earlier for Ex Libris Patron Directory
Services (PDS) allows remote attackers to inject arbitrary web script
or HTML via the url parameter.
|
| CVE-2014-7291 |
Multiple cross-site scripting (XSS) vulnerabilities in api_events.php
in Springshare LibCal 2.0 allow remote attackers to inject arbitrary
web script or HTML via the (1) m or (2) cid parameter.
|
| CVE-2014-7290 |
Multiple cross-site scripting (XSS) vulnerabilities in Atlas Systems
Aeon 3.5 and 3.6 allow remote attackers to inject arbitrary web script
or HTML via the (1) Action or (2) Form parameter to aeon.dll.
|
| CVE-2014-7280 |
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4
Build #85 for Tenable Nessus 5.x allows remote web servers to inject
arbitrary web script or HTML via the server header.
|
| CVE-2014-7277 |
Cross-site scripting (XSS) vulnerability in the login page on the
ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified "welcome message" form data that is improperly handled
during rendering of the loginMessage list item, a different
vulnerability than CVE-2014-7278.
|
| CVE-2014-7268 |
Cross-site scripting (XSS) vulnerability in the data-export feature in
the Ricksoft WBS Gantt-Chart add-on 7.8.1 and earlier for JIRA allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2014-7267.
|
| CVE-2014-7267 |
Cross-site scripting (XSS) vulnerability in the output-page generator
in the Ricksoft WBS Gantt-Chart add-on 7.8.1 and earlier for JIRA
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors, a different vulnerability than
CVE-2014-7268.
|
| CVE-2014-7265 |
Cross-site scripting (XSS) vulnerability in LinPHA allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-7264 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/themes/default/pages/manage_users.twig in the Users Management
feature in the admin component in Chyrp before 2.5.1 allow remote
authenticated users to inject arbitrary web script or HTML via the (1)
user.email or (2) user.website field in a user registration.
|
| CVE-2014-7263 |
Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows
remote attackers to inject arbitrary web script or HTML via a crafted
HTTP header, a different vulnerability than CVE-2014-7261.
|
| CVE-2014-7262 |
Cross-site scripting (XSS) vulnerability in the Omake BBS component in
ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web
script or HTML via a crafted string.
|
| CVE-2014-7261 |
Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows
remote attackers to inject arbitrary web script or HTML via a crafted
string that is improperly rendered during construction of a directory
index page, a different vulnerability than CVE-2014-7263.
|
| CVE-2014-7258 |
Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91
and earlier, when running certain versions of Internet Explorer,
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-7248 |
Cross-site scripting (XSS) vulnerability in IPA iLogScanner 4.0 allows
remote attackers to inject arbitrary web script or HTML by triggering
a crafted entry in a log file.
|
| CVE-2014-7240 |
Cross-site scripting (XSS) vulnerability in the Easy Contact Form
Solution plugin before 1.7 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the value parameter in a
master_response action to wp-admin/admin-ajax.php.
|
| CVE-2014-7217 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.0.x before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.x before 4.2.9.1
allow remote authenticated users to inject arbitrary web script or
HTML via a crafted ENUM value that is improperly handled during
rendering of the (1) table search or (2) table structure page, related
to libraries/TableSearch.class.php and libraries/Util.class.php.
|
| CVE-2014-7200 |
Cross-site scripting (XSS) vulnerability in
pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol)
extension 2.14.0 and earlier for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via the
tx_dmmjobcontrol_pi1[search][keyword] parameter to jobs/.
|
| CVE-2014-7199 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19,
1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote
attackers to inject arbitrary web script or HTML via a crafted SVG
file.
|
| CVE-2014-7183 |
Multiple cross-site scripting (XSS) vulnerabilities in the search.php
in LiteCart 1.1.2.1 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) query parameter or (2)
QUERY_STRING.
|
| CVE-2014-7182 |
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google
Maps plugin before 6.0.27 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the poly_id parameter in an
(1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the
wp-google-maps-menu page to wp-admin/admin.php.
|
| CVE-2014-7181 |
Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons
plugin before 1.26.1 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the id parameter in a button action
on the maxbuttons-controller page to wp-admin/admin.php, related to
the button creation page.
|
| CVE-2014-7158 |
Cross-site request forgery (CSRF) vulnerability in Exinda WAN
Optimization Suite 7.0.0 (2160) allows remote attackers to hijack the
authentication of administrators for requests that change the admin
password via a request to admin/launch.
|
| CVE-2014-7157 |
Cross-site scripting (XSS) vulnerability in Exinda WAN Optimization
Suite 7.0.0 (2160) allows remote attackers to inject arbitrary web
script or HTML via the tabsel parameter to admin/launch.
|
| CVE-2014-7152 |
Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms
plugin 3.0 through 5.0.6 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the update_options action to
wp-admin/admin-ajax.php.
|
| CVE-2014-7151 |
Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms
Lite plugin 2.1.0 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the form_fields parameter in a (1)
do_edit or (2) do_insert action to wp-admin/admin-ajax.php.
|
| CVE-2014-7139 |
Multiple cross-site scripting (XSS) vulnerabilities in the Contact
Form DB (aka CFDB and contact-form-7-to-database-extension) plugin
before 2.8.16 for WordPress allow remote attackers to inject arbitrary
web script or HTML via the (1) form or (2) enc parameter in the
CF7DBPluginShortCodeBuilder page to wp-admin/admin.php.
|
| CVE-2014-7138 |
Cross-site scripting (XSS) vulnerability in the Google Calendar Events
plugin before 2.0.4 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the gce_feed_ids parameter in a
gce_ajax action to wp-admin/admin-ajax.php.
|
| CVE-2014-6635 |
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.0 allows
remote attackers to inject arbitrary web script or HTML via the src
parameter in the search action to index.php.
|
| CVE-2014-6631 |
Cross-site scripting (XSS) vulnerability in com_media in Joomla! 3.2.x
before 3.2.5 and 3.3.x before 3.3.4 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-6620 |
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass
before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-6619 |
Multiple cross-site scripting (XSS) vulnerabilities in
register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 allow
remote attackers to inject arbitrary web script or HTML via the (1)
fname, (2) lname, or (3) login parameter.
|
| CVE-2014-6618 |
Cross-site scripting (XSS) vulnerability in Your Online Shop allows
remote attackers to inject arbitrary web script or HTML via the
products_id parameter.
|
| CVE-2014-6616 |
Cross-site scripting (XSS) vulnerability in Softing FG-100 PROFIBUS
Single Channel (FG-100-PB) with firmware FG-x00-PB_V2.02.0.00 allows
remote attackers to inject arbitrary web script or HTML via the
DEVICE_NAME parameter to cgi-bin/CFGhttp/.
|
| CVE-2014-6445 |
Multiple cross-site scripting (XSS) vulnerabilities in
includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through
1.3.10 for WordPress allow remote attackers to inject arbitrary web
script or HTML via the (1) uE or (2) uC parameter.
|
| CVE-2014-6444 |
Multiple cross-site scripting (XSS) vulnerabilities in the Titan
Framework plugin before 1.6 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) t parameter to
iframe-googlefont-preview.php or the (2) text parameter to
iframe-font-preview.php.
|
| CVE-2014-6439 |
Cross-site scripting (XSS) vulnerability in the CORS functionality in
Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-6393 |
The Express web framework before 3.11 and 4.x before 4.5 for Node.js
does not provide a charset field in HTTP Content-Type headers in 400
level responses, which might allow remote attackers to conduct
cross-site scripting (XSS) attacks via characters in a non-standard
encoding.
|
| CVE-2014-6392 |
** DISPUTED ** Cross-site scripting (XSS) vulnerability in the
Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows
remote attackers to inject arbitrary web script or HTML via a crafted
filename extension that is improperly handled during MIME sniffing of
chat traffic. NOTE: the vendor disputes the significance of this
report, because the user must accept an interstitial warning before
the HTML file content is rendered, and because the HTML content's
origin is a sandbox domain.
|
| CVE-2014-6365 |
Microsoft Internet Explorer 8 through 11 allows remote attackers to
bypass the XSS filter via a crafted attribute of an element in an HTML
document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a
different vulnerability than CVE-2014-6328.
|
| CVE-2014-6328 |
Microsoft Internet Explorer 8 through 11 allows remote attackers to
bypass the XSS filter via a crafted attribute of an element in an HTML
document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a
different vulnerability than CVE-2014-6365.
|
| CVE-2014-6326 |
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server
2013 SP1 and Cumulative Update 6 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka "OWA XSS
Vulnerability," a different vulnerability than CVE-2014-6325.
|
| CVE-2014-6325 |
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server
2013 SP1 and Cumulative Update 6 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka "OWA XSS
Vulnerability," a different vulnerability than CVE-2014-6326.
|
| CVE-2014-6315 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado
Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) callback,
(2) dir, or (3) extensions parameter in an addImages action to
wp-admin/admin-ajax.php.
|
| CVE-2014-6313 |
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin
before 2.2.3 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the range parameter on the wc-reports page to
wp-admin/admin.php.
|
| CVE-2014-6312 |
Cross-site request forgery (CSRF) vulnerability in the Login Widget
With Shortcode (login-sidebar-widget) plugin before 3.2.1 for
WordPress allows remote attackers to hijack the authentication of
administrators for requests that conduct cross-site scripting (XSS)
attacks via the custom_style_afo parameter on the login_widget_afo
page to wp-admin/options-general.php.
|
| CVE-2014-6301 |
Multiple cross-site scripting (XSS) vulnerabilities in the
tables-management module in PNMsoft Sequence Kinetics before 7.7 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-6300 |
Cross-site scripting (XSS) vulnerability in the micro history
implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before
4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject
arbitrary web script or HTML, and consequently conduct a cross-site
request forgery (CSRF) attack to create a root account, via a crafted
URL, related to js/ajax.js.
|
| CVE-2014-6297 |
Cross-site scripting (XSS) vulnerability in the mm_forum extension
before 1.9.3 for TYPO3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-6296 |
Cross-site scripting (XSS) vulnerability in the WEC Map (wec_map)
extension before 3.0.3 for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-6294 |
Cross-site scripting (XSS) vulnerability in the External links click
statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-6291 |
Cross-site scripting (XSS) vulnerability in the Alphabetic Sitemap
(alpha_sitemap) extension 0.0.3 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-6280 |
Multiple cross-site scripting (XSS) vulnerabilities in OSClass before
3.4.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) action or (2) nsextt parameter to oc-admin/index.php or
the (3) nsextt parameter in an items_reported action to
oc-admin/index.php.
|
| CVE-2014-6254 |
Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core
through 5 Beta 3 allow remote attackers to inject arbitrary web script
or HTML via an attribute in a (1) device name, (2) device detail, (3)
report name, (4) report detail, or (5) portlet name, or (6) a string
to a helper method, aka ZEN-15381 and ZEN-15410.
|
| CVE-2014-6243 |
Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer
plugin before 2.0.2 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the error parameter in the
ewww-image-optimizer.php page to wp-admin/options-general.php, which
is not properly handled in a pngout error message.
|
| CVE-2014-6240 |
Cross-site scripting (XSS) vulnerability in the Google Sitemap
(weeaar_googlesitemap) extension 0.4.3 and earlier for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-6238 |
Cross-site scripting (XSS) vulnerability in the Akronymmanager (aka SB
Folderdownload) extension 0.5.0 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-6237 |
Cross-site scripting (XSS) vulnerability in the News Pack extension
0.1.0 and earlier for TYPO3 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-6234 |
Cross-site scripting (XSS) vulnerability in the Open Graph protocol
(jh_opengraphprotocol) extension before 1.0.2 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-6215 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0
through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2
CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-6214 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere
Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote
attackers to hijack the authentication of arbitrary users for requests
that insert XSS sequences.
|
| CVE-2014-6196 |
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory
(WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework
(WDF) and Lotus Widget Factory (LWF), allows remote attackers to
inject arbitrary web script or HTML by leveraging a Dojo builder error
in an unspecified WebSphere Portal configuration, leading to improper
construction of a response page by an application.
|
| CVE-2014-6192 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program
Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5
before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-6191 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program
Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors. IBM X-Force ID:
98568.
|
| CVE-2014-6189 |
Cross-site scripting (XSS) vulnerability in IBM Security Network
Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before
5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-6188 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere
Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x
through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-6180 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5
and 7.5.x before 7.5.0.1 allows remote authenticated users to inject
arbitrary web script or HTML via the HTTP User-Agent header.
|
| CVE-2014-6179 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4
and 8.0.x before 8.0.0.2 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-6178 |
Cross-site scripting (XSS) vulnerability in the widgets in IBM
WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4
and 8.0.x before 8.0.0.3 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-6175 |
Cross-site scripting (XSS) vulnerability in IBM Marketing Operations
7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before
9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-6173 |
Cross-site scripting (XSS) vulnerability in the Process Inspector in
IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x
through 8.5.5 allows remote authenticated users to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2014-6171 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0
through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through
7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL.
|
| CVE-2014-6168 |
Cross-site request forgery (CSRF) vulnerability in IBM Security
Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote
authenticated users to hijack the authentication of arbitrary users
for requests that insert XSS sequences.
|
| CVE-2014-6167 |
Cross-site scripting (XSS) vulnerability in the URL rewriting feature
in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before
8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-6163 |
Cross-site scripting (XSS) vulnerability on the IBM WebSphere
DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-6161 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool/Impact
6.1.1 before 6.1.1.1-TIV-NCI-IF0001 allows remote authenticated users
to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-6152 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli
Integrated Portal (TIP) 2.2.x allow remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-6150 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Application
Dependency Discovery Manager (TADDM) 7.2.1.0 through 7.2.1.6 and
7.2.2.0 through 7.2.2.2 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-6145 |
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos
Business Intelligence 10.1 before IF10, 10.1.1 before IF9, 10.2 before
IF11, 10.2.1 before IF8, and 10.2.1.1 before IF7 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-6144 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality
Manager (RQM) 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7
iFix3, and 5.x before 5.0.2 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-6137 |
Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page
in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-6132 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
WebSphere Service Registry and Repository (WSRR) 6.3 through 6.3.0.5,
7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3,
and 8.5.x before 8.5.0.1 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-6126 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0
before CF03 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-6125 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere
Portal 8.5.0 before CF03 allows remote attackers to hijack the
authentication of arbitrary users for requests that insert XSS
sequences.
|
| CVE-2014-6121 |
Cross-site scripting (XSS) vulnerability in IBM Security AppScan
Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7
before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix
003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users
to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-6113 |
Cross-site scripting (XSS) vulnerability in the Web Reports component
in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-6101 |
Cross-site scripting (XSS) vulnerability in the redirect-login feature
in IBM Business Process Manager (BPM) Advanced 7.5 through 8.5.5
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-6100 |
Cross-site scripting (XSS) vulnerability in the Admin UI in IBM Tivoli
Directory Server 6.1 before 6.1.0.64-ISS-ITDS-IF0064, 6.2 before
6.2.0.39-ISS-ITDS-FP0039, and 6.3 before 6.3.0.33-ISS-ITDS-IF0033, and
IBM Security Directory Server 6.3.1 before 6.3.1.7-ISS-ISDS-IF0007,
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2014-6096 |
Cross-site scripting (XSS) vulnerability in IBM Security Identity
Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-6093 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x
before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before
8.5.0 CF02 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2014-6091 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program
Management (SPM) 6.0.4 before 6.0.4.5 iFix7 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-6090 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1)
DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3)
IEGEditorCommands servlets in IBM Curam Social Program Management
(SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0
iFix8, 6.0.4 before 6.0.4.5 iFix10, and 6.0.5 before 6.0.5.6 allow
remote attackers to hijack the authentication of arbitrary users for
requests that insert XSS sequences.
|
| CVE-2014-6079 |
Cross-site scripting (XSS) vulnerability in the Local Management
Interface in IBM Security Access Manager for Web 7.x before
7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security
Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL.
|
| CVE-2014-6077 |
Cross-site request forgery (CSRF) vulnerability in IBM Security Access
Manager for Mobile 8.x before 8.0.1 and Security Access Manager for
Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers
to hijack the authentication of arbitrary users for requests that
insert XSS sequences.
|
| CVE-2014-6070 |
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon
LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary
web script or HTML via the hostname in (1) index.php or (2)
detail.php.
|
| CVE-2014-5466 |
Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk
Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.7, and
5.0.x before 5.0.10 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-5464 |
Cross-site scripting (XSS) vulnerability in the nDPI traffic
classification library in ntopng (aka ntop) before 1.2.1 allows remote
attackers to inject arbitrary web script or HTML via the HTTP Host
header.
|
| CVE-2014-5456 |
Cross-site scripting (XSS) vulnerability in the Social Stats module
before 7.x-1.5 for Drupal allows remote authenticated users with the
"[Content Type]: Create new content" permission to inject arbitrary
web script or HTML via vectors related to the configuration.
|
| CVE-2014-5452 |
CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the
possibility of invalid C-CDA documents with crafted XML attributes,
which allows remote attackers to conduct XSS attacks via a document
containing a table that is improperly handled during unrestricted
xsl:copy operations.
|
| CVE-2014-5451 |
Cross-site scripting (XSS) vulnerability in
manager/templates/default/header.tpl in MODX Revolution 2.3.1-pl and
earlier allows remote attackers to inject arbitrary web script or HTML
via the "a" parameter to manager/. NOTE: this issue exists because of
a CVE-2014-2080 regression.
|
| CVE-2014-5441 |
Multiple cross-site scripting (XSS) vulnerabilities in
app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3
allow remote attackers to inject arbitrary web script or HTML via the
(1) username, (2) first name, or (3) last name in a (a) create or (b)
edit user action.
|
| CVE-2014-5438 |
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT
Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote
authenticated users to inject arbitrary web script or HTML via the
computer_name parameter to connected_devices_computers_edit.php.
|
| CVE-2014-5437 |
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS
Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and
earlier allow remote attackers to hijack the authentication of
administrators for requests that (1) enable remote management via a
request to remote_management.php, (2) add a port forwarding rule via a
request to port_forwarding_add.php, (3) change the wireless network to
open via a request to wireless_network_configuration_edit.php, or (4)
conduct cross-site scripting (XSS) attacks via the keyword parameter
to managed_sites_add_keyword.php.
|
| CVE-2014-5417 |
Cross-site scripting (XSS) vulnerability in Meinberg NTP Server
firmware on LANTIME M-Series devices 6.15.019 and earlier allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-5411 |
Multiple cross-site scripting (XSS) vulnerabilities in Schneider
Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1
allow remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-5408 |
Cross-site scripting (XSS) vulnerability in the login script in the
Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the username parameter.
|
| CVE-2014-5397 |
Cross-site scripting (XSS) vulnerability in Schneider Electric
Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-5391 |
Cross-site scripting (XSS) vulnerability in the JobScheduler
Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x
before 1.7.4241 allows remote attackers to inject arbitrary web script
or HTML via the hash property (location.hash).
|
| CVE-2014-5382 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface in Schrack Technik microControl with firmware 1.7.0 (937)
allow remote attackers to inject arbitrary web script or HTML via the
position textbox in the configuration menu or other unspecified
vectors.
|
| CVE-2014-5360 |
Cross-site scripting (XSS) vulnerability in the admin interface in
LANDESK Management Suite before 9.6 SP1 allows remote attackers to
inject arbitrary web script or HTML via the AMTVersion parameter to
remote/serverlist_grouptree.aspx.
|
| CVE-2014-5348 |
Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in
Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6
patchlevel 9620140312 allows remote attackers to inject arbitrary web
script or HTML via the logfile parameter.
|
| CVE-2014-5347 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Disqus Comment System plugin before 2.76 for WordPress allow remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via the (1)
disqus_replace, (2) disqus_public_key, or (3) disqus_secret_key
parameter to wp-admin/edit-comments.php in manage.php or that (4)
reset or (5) delete plugin options via the reset parameter to
wp-admin/edit-comments.php.
|
| CVE-2014-5345 |
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus
Comment System plugin before 2.76 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the step
parameter.
|
| CVE-2014-5344 |
Multiple cross-site scripting (XSS) vulnerabilities in the Mobiloud
(mobiloud-mobile-app-plugin) plugin before 2.3.8 for WordPress allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: some of these details are obtained from
third party information.
|
| CVE-2014-5343 |
Cross-site scripting (XSS) vulnerability in Feng Office allows remote
attackers to inject arbitrary web script or HTML via a client Name
field.
|
| CVE-2014-5338 |
Multiple cross-site scripting (XSS) vulnerabilities in the multisite
component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors to the (1) render_status_icons function in
htmllib.py or (2) ajax_action function in actions.py.
|
| CVE-2014-5331 |
Cross-site scripting (XSS) vulnerability in Aflax allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-5330 |
Cross-site scripting (XSS) vulnerability in BirdBlog allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-5326 |
Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR)
through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-5322 |
Cross-site scripting (XSS) vulnerability in the Instant Web Publish
function in FileMaker Pro before 13 and Pro Advanced before 13 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: this vulnerability exists because of an
incorrect fix for CVE-2013-3640.
|
| CVE-2014-5317 |
Cross-site scripting (XSS) vulnerability in php365.com 365 Links 3.11
and earlier, 365 Links2 3.11 and earlier, 365 Links+ 2.10 and earlier,
and 365 Links2+ 2.10 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-5316 |
Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4
allows remote attackers to inject arbitrary web script or HTML via a
crafted page.
|
| CVE-2014-5315 |
Cross-site scripting (XSS) vulnerability in the Help page in Adobe
Acrobat 9.5.2 and earlier and ColdFusion 8.0.1 and earlier allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-5313 |
Cross-site scripting (XSS) vulnerability in the management page in Six
Apart Movable Type before 5.2 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-5276 |
Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms
Text Chat Rooms 8.2.0 allow remote authenticated users to inject
arbitrary web script or HTML via (1) an uploaded profile picture or
(2) the edit parameter to profiles/index.php.
|
| CVE-2014-5274 |
Cross-site scripting (XSS) vulnerability in the view operations page
in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted view name, related to js/functions.js.
|
| CVE-2014-5273 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1
allow remote authenticated users to inject arbitrary web script or
HTML via the (1) browse table page, related to js/sql.js; (2) ENUM
editor page, related to js/functions.js; (3) monitor page, related to
js/server_status_monitor.js; (4) query charts page, related to
js/tbl_chart.js; or (5) table relations page, related to
libraries/tbl_relation.lib.php.
|
| CVE-2014-5259 |
Cross-site scripting (XSS) vulnerability in cattranslate.php in the
CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows
remote attackers to inject arbitrary web script or HTML via the msg
parameter.
|
| CVE-2014-5257 |
Multiple cross-site scripting (XSS) vulnerabilities in Forma Lms
before 1.2.1 p01 allow remote attackers to inject arbitrary web script
or HTML via the (1) id_custom parameter in an amanmenu request or (2)
id_game parameter in an alms/games/edit request to appCore/index.php.
|
| CVE-2014-5248 |
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows
remote attackers to inject arbitrary web script or HTML via vectors
related to video MyCode.
|
| CVE-2014-5242 |
Cross-site scripting (XSS) vulnerability in
mediawiki.page.image.pagination.js in MediaWiki 1.22.x before 1.22.9
and 1.23.x before 1.23.2 allows remote attackers to inject arbitrary
web script or HTML via vectors involving the multipageimagenavbox
class in conjunction with an action=raw value.
|
| CVE-2014-5240 |
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php
in WordPress before 3.9.2, when Multisite is enabled, allows remote
authenticated administrators to inject arbitrary web script or HTML,
and obtain Super Admin privileges, via a crafted avatar URL.
|
| CVE-2014-5235 |
Cross-site scripting (XSS) vulnerability in the frontend in
Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before
7.6.0-rev16 allows remote attackers to inject arbitrary web script or
HTML via vectors related to unspecified fields in RSS feeds.
|
| CVE-2014-5234 |
Cross-site scripting (XSS) vulnerability in the backend in
Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before
7.6.0-rev16 allows remote attackers to inject arbitrary web script or
HTML via a folder publication name.
|
| CVE-2014-5216 |
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access
Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject
arbitrary web script or HTML via (1) the location parameter in a
dev.Empty action to nps/servlet/webacc, (2) the error parameter to
nidp/jsp/x509err.jsp, (3) the lang parameter to
sslvpn/applet_agent.jsp, or (4) the secureLoggingServersA parameter to
roma/system/cntl, a different issue than CVE-2014-9412.
|
| CVE-2014-5213 |
nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in
iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote
authenticated users to obtain sensitive information from process
memory via a direct request.
|
| CVE-2014-5212 |
Cross-site scripting (XSS) vulnerability in nds/search/data in
iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote
attackers to inject arbitrary web script or HTML via the rdn
parameter.
|
| CVE-2014-5202 |
Cross-site scripting (XSS) vulnerability in compfight-search.php in
the Compfight plugin 1.4 for WordPress allows remote authenticated
users to inject arbitrary web script or HTML via the search-value
parameter.
|
| CVE-2014-5198 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk
Enterprise 6.1.x before 6.1.3 allows remote attackers to inject
arbitrary web script or HTML via the Referer HTTP header.
|
| CVE-2014-5196 |
Cross-site request forgery (CSRF) vulnerability in
improved-user-search-in-backend.php in the backend in the Improved
user search in backend plugin before 1.2.5 for WordPress allows remote
attackers to hijack the authentication of administrators for requests
that insert XSS sequences via the iusib_meta_fields parameter.
|
| CVE-2014-5193 |
Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider
1.3.6 allows remote attackers to inject arbitrary web script or HTML
via the category parameter. NOTE: the url parameter vector is already
covered by CVE-2014-5082.
|
| CVE-2014-5191 |
Cross-site scripting (XSS) vulnerability in the Preview plugin before
4.4.3 in CKEditor allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-5190 |
Cross-site scripting (XSS) vulnerability in
captcha-secureimage/test/index.php in the SI CAPTCHA Anti-Spam plugin
2.7.4 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO.
|
| CVE-2014-5188 |
Cross-site scripting (XSS) vulnerability in doemailpassword.tml in
Lyris ListManager (LM) 8.95a allows remote attackers to inject
arbitrary web script or HTML via the EmailAddr parameter.
|
| CVE-2014-5178 |
Multiple cross-site scripting (XSS) vulnerabilities in Easy File
Sharing (EFS) Web Server 6.8 allow remote authenticated users to
inject arbitrary web script or HTML via the content parameter when (1)
creating a topic or (2) posting an answer. NOTE: some of these details
are obtained from third party information.
|
| CVE-2014-5172 |
Multiple cross-site scripting (XSS) vulnerabilities in the XS
Administration Tools in SAP HANA allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-5169 |
Cross-site scripting (XSS) vulnerability in the Date module before
7.x-2.8 for Drupal allows remote authenticated users with the
permission to create a date field to inject arbitrary web script or
HTML via the date field title.
|
| CVE-2014-5144 |
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3
allows remote authenticated users to inject arbitrary web script or
HTML via crafted markdown.
|
| CVE-2014-5136 |
Cross-site scripting (XSS) vulnerability in Innovative Interfaces
Sierra Library Services Platform 1.2_3 allows remote attackers to
inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2014-5129 |
Cross-site scripting (XSS) vulnerability in Avolve Software ProjectDox
8.1 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-5121 |
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for
Server 10.1.1 allow remote attackers to inject arbitrary web script or
HTML via unspecified parameters.
|
| CVE-2014-5113 |
Multiple cross-site scripting (XSS) vulnerabilities in test.php in
Visualware MyConnection Server 9.7i allow remote attackers to inject
arbitrary web script or HTML via the (1) testtype, (2) ver, (3) cm,
(4) map, (5) lines, (6) pps, (7) bpp, (8) codec, (9) provtext, (10)
provtextextra, (11) provlink, or (12) duration parameter.
|
| CVE-2014-5110 |
Cross-site scripting (XSS) vulnerability in user/help/html/index.php
in Fonality trixbox allows remote attackers to inject arbitrary web
script or HTML via the id_nodo parameter.
|
| CVE-2014-5108 |
Cross-site scripting (XSS) vulnerability in
single_pages\download_file.php in concrete5 before 5.6.3 allows remote
attackers to inject arbitrary web script or HTML via the HTTP Referer
header to index.php/download_file.
|
| CVE-2014-5106 |
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board
(aka IPB or Power Board) 3.4.x through 3.4.6 allows remote attackers
to inject arbitrary web script or HTML via the HTTP Referer header to
admin/install/index.php.
|
| CVE-2014-5105 |
Multiple cross-site scripting (XSS) vulnerabilities in ol-commerce
2.1.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) a_country parameter in a process action to
affiliate_signup.php or (2) entry_country_id parameter in an edit
action to admin/create_account.php.
|
| CVE-2014-5103 |
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog
Analyzer 9 build 9000 allows remote attackers to inject arbitrary web
script or HTML via the j_username parameter to event/j_security_check.
|
| CVE-2014-5101 |
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5)
TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9) TPL_phone,
(10) TPL_pp_email, (11) TPL_authnet_id, (12) TPL_authnet_pass, (13)
TPL_worldpay_id, (14) TPL_toocheckout_id, or (15)
TPL_moneybookers_email in a first action to register.php or the (16)
username parameter in a login action to user_login.php.
|
| CVE-2014-5100 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka
before 2.2.1 allow remote attackers to hijack the authentication of
administrators for requests that (1) add a new super user account via
a request to admin/users/add, (2) insert cross-site scripting (XSS)
sequences via the api_key_label parameter to admin/users/api-keys/1,
or (3) disable file validation via a request to
admin/settings/edit-security.
|
| CVE-2014-5098 |
Cross-site scripting (XSS) vulnerability in the Search module before
1.2.2 in Jamroom allows remote attackers to inject arbitrary web
script or HTML via the query string to search/results/.
|
| CVE-2014-5088 |
Cross-site scripting (XSS) vulnerability in Status2k allows remote
attackers to inject arbitrary web script or HTML via the username to
login.php.
|
| CVE-2014-5069 |
Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15
allows remote attackers to inject arbitrary web script or HTML via
vectors involving system logs.
|
| CVE-2014-5027 |
Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before
1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject
arbitrary web script or HTML via a query parameter to a diff fragment
page.
|
| CVE-2014-5026 |
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b
allow remote authenticated users with console access to inject
arbitrary web script or HTML via a (1) Graph Tree Title in a delete or
(2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5)
Host Templates Name in a delete action; (6) Data Source Title; (7)
Graph Title; or (8) Graph Template Name in a delete or (9) duplicate
action.
|
| CVE-2014-5025 |
Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti
0.8.8b allows remote authenticated users with console access to inject
arbitrary web script or HTML via the name_cache parameter in a ds_edit
action.
|
| CVE-2014-5024 |
Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell
SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote
attackers to inject arbitrary web script or HTML via the node_id
parameter.
|
| CVE-2014-5022 |
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal
7.x before 7.29 allows remote attackers to inject arbitrary web script
or HTML via vectors involving forms with an Ajax-enabled textfield and
a file field.
|
| CVE-2014-5021 |
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x
before 6.32 and possibly 7.x before 7.29 allows remote authenticated
users with the "administer taxonomy" permission to inject arbitrary
web script or HTML via an option group label.
|
| CVE-2014-5018 |
Incomplete blacklist vulnerability in the autoEscape function in
common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote
attackers to conduct cross-site scripting (XSS) attacks via the GBK
charset in the loadname parameter to index.php, related to the survey
resume.
|
| CVE-2014-5016 |
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey
2.05+ Build 140618 allow remote attackers to inject arbitrary web
script or HTML via (1) the pid attribute to the getAttribute_json
function to application/controllers/admin/participantsaction.php in
CPDB, (2) the sa parameter to
application/views/admin/globalSettings_view.php, or (3) a crafted CSV
file to the "Import CSV" functionality.
|
| CVE-2014-4986 |
Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js
in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x
before 4.2.6 allow remote authenticated users to inject arbitrary web
script or HTML via a crafted (1) table name or (2) column name that is
improperly handled during construction of an AJAX confirmation
message.
|
| CVE-2014-4965 |
Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) customername parameter to
central/orders/searchcriteria.action; (2) productname, (3)
availability, or (4) status parameter to
central/catalog/productlist.action; or unspecified vectors in (5)
WebContent/orders/orderlist.jsp.
|
| CVE-2014-4958 |
Cross-site scripting (XSS) vulnerability in Telerik UI for ASP.NET
AJAX RadEditor control 2014.1.403.35, 2009.3.1208.20, and other
versions allows remote attackers to inject arbitrary web script or
HTML via CSS expressions in style attributes.
|
| CVE-2014-4955 |
Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList
function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before
4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted trigger name that is improperly handled on the database
triggers page.
|
| CVE-2014-4954 |
Cross-site scripting (XSS) vulnerability in the
PMA_getHtmlForActionLinks function in libraries/structure.lib.php in
phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted table comment that
is improperly handled during construction of a database structure
page.
|
| CVE-2014-4946 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet
Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail
Edition before 5.1.5, allow remote attackers to inject arbitrary web
script or HTML via (1) unspecified flags or (2) a mailbox name in the
dynamic mailbox view.
|
| CVE-2014-4945 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet
Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail
Edition before 5.1.5, allow remote attackers to inject arbitrary web
script or HTML via an unspecified flag in the basic (1) mailbox or (2)
message view.
|
| CVE-2014-4930 |
Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do
in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote
attackers to inject arbitrary web script or HTML via the (1) width,
(2) height, (3) url, (4) helpP, (5) tab, (6) module, (7) completeData,
(8) RBBNAME, (9) TC, (10) rtype, (11) eventCriteria, (12) q, (13)
flushCache, or (14) product parameter.
|
| CVE-2014-4925 |
Cross-site scripting (XSS) vulnerability in Good for Enterprise for
Android 2.8.0.398 and 1.9.0.40.
|
| CVE-2014-4908 |
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios
through 0.6.22 allow remote attackers to inject arbitrary web script
or HTML via the URI used for reaching (1)
share/pnp/application/views/kohana_error_page.php or (2)
share/pnp/application/views/template.php, leading to improper handling
within an http-equiv="refresh" META element.
|
| CVE-2014-4907 |
Cross-site scripting (XSS) vulnerability in
share/pnp/application/views/kohana_error_page.php in PNP4Nagios before
0.6.22 allows remote attackers to inject arbitrary web script or HTML
via a parameter that is not properly handled in an error message.
|
| CVE-2014-4871 |
Cross-site scripting (XSS) vulnerability in wlsecurity.html on
NetCommWireless NB604N routers with firmware before
GAN5.CZ56T-B-NC.AU-R4B030.EN allows remote attackers to inject
arbitrary web script or HTML via the wlWpaPsk parameter.
|
| CVE-2014-4857 |
Cross-site scripting (XSS) vulnerability in Gurock TestRail before
3.1.3 allows remote attackers to inject arbitrary web script or HTML
via the Created By field in a project activity.
|
| CVE-2014-4856 |
Cross-site scripting (XSS) vulnerability in the Polldaddy Polls &
Ratings plugin before 2.0.25 for WordPress allows remote attackers to
inject arbitrary web script or HTML via vectors related to a ratings
shortcode and a unique ID. NOTE: some of these details are obtained
from third party information.
|
| CVE-2014-4855 |
Cross-site scripting (XSS) vulnerability in the Polylang plugin before
1.5.2 for WordPress allows remote attackers to inject arbitrary web
script or HTML via vectors related to a user description. NOTE: some
of these details are obtained from third party information.
|
| CVE-2014-4854 |
Cross-site scripting (XSS) vulnerability in the WP Construction Mode
plugin 1.8 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the wuc_logo parameter in a save action to
wp-admin/admin.php.
|
| CVE-2014-4853 |
Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan
before 1.2.7.3 allows remote authenticated users to inject arbitrary
web script or HTML via the file name of an uploaded file.
|
| CVE-2014-4849 |
Multiple cross-site scripting (XSS) vulnerabilities in msg.php in
FoeCMS allow remote attackers to inject arbitrary web script or HTML
via the (1) e or (2) r parameter.
|
| CVE-2014-4848 |
Cross-site scripting (XSS) vulnerability in the Blogstand Banner
(blogstand-smart-banner) plugin 1.0 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the bs_blog_id
parameter to wp-admin/options-general.php.
|
| CVE-2014-4847 |
Cross-site scripting (XSS) vulnerability in the Random Banner plugin
1.1.2.1 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the buffercode_RBanner_url_banner1 parameter in an
update action to wp-admin/options.php.
|
| CVE-2014-4846 |
Cross-site scripting (XSS) vulnerability in the Meta Slider
(ml-slider) plugin 2.5 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the id parameter to
wp-admin/admin.php.
|
| CVE-2014-4845 |
Cross-site scripting (XSS) vulnerability in the BannerMan plugin 0.2.4
for WordPress allows remote attackers to inject arbitrary web script
or HTML via the bannerman_background parameter to
wp-admin/options-general.php.
|
| CVE-2014-4839 |
Cross-site request forgery (CSRF) vulnerability in birtviewer.query in
IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1
before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows
remote authenticated users to hijack the authentication of arbitrary
users for requests that insert XSS sequences.
|
| CVE-2014-4838 |
Cross-site scripting (XSS) vulnerability in
GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2
and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2,
and 3.4 before 3.4.0.1 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-4837 |
Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM
TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before
3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-4836 |
Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in
IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1
before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted URL.
|
| CVE-2014-4829 |
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar
SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before
7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch
1, allows remote attackers to hijack the authentication of arbitrary
users for requests that insert XSS sequences.
|
| CVE-2014-4827 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM
QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-4820 |
Cross-site scripting (XSS) vulnerability in IBM Integration Bus
Manufacturing Pack 1.x before 1.0.0.1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4816 |
Cross-site request forgery (CSRF) vulnerability in the Administrative
Console in IBM WebSphere Application Server (WAS) 6.x through
6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before
8.5.5.4 allows remote authenticated users to hijack the authentication
of arbitrary users for requests that insert XSS sequences.
|
| CVE-2014-4801 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality
Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before
4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users
to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-4787 |
Cross-site scripting (XSS) vulnerability in IBM Initiate Master Data
Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before
10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4785 |
Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master
Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before
10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated
users to hijack the authentication of arbitrary users for requests
that insert XSS sequences.
|
| CVE-2014-4783 |
Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master
Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before
10.0.093013, and 10.1 before 10.1.093013 allows remote attackers to
hijack the authentication of arbitrary users for requests that insert
XSS sequences.
|
| CVE-2014-4770 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application
Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before
8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated
administrators to inject arbitrary web script or HTML via a crafted
URL.
|
| CVE-2014-4763 |
Cross-site scripting (XSS) vulnerability in Content Navigator in
Content Engine in IBM FileNet Content Manager 5.2.x before
5.2.0.3-P8CPE-IF003 and Content Foundation 5.2.x before
5.2.0.3-P8CPE-IF003 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-4762 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0
through 8.0.0.1 CF13 and 8.5.0 before CF02 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-4751 |
Cross-site scripting (XSS) vulnerability in IBM Security Access
Manager for Mobile 8.0.0.0, 8.0.0.1, and 8.0.0.3 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-4748 |
Cross-site scripting (XSS) vulnerability in the Classic Meeting Server
in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-4744 |
Multiple cross-site scripting (XSS) vulnerabilities in osTicket before
1.9.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) Phone Number field to open.php or (2) Phone number field,
(3) passwd1 field, (4) passwd2 field, or (5) do parameter to
account.php.
|
| CVE-2014-4743 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
search_ajax.tpl and (2) search_ajax_small.tpl in
templates/default/tpl/module_search/ in the Search module
(module_search) in Kajona before 4.5 allow remote attackers to inject
arbitrary web script or HTML via the search parameter.
|
| CVE-2014-4742 |
Cross-site scripting (XSS) vulnerability in system/class_link.php in
the System module (module_system) in Kajona before 4.5 allows remote
attackers to inject arbitrary web script or HTML via the systemid
parameter in a mediaFolder action to index.php.
|
| CVE-2014-4738 |
Multiple cross-site scripting (XSS) vulnerabilities in FortiGuard
FortiWeb 5.0.x, 5.1.x, and 5.2.x before 5.2.1 allow remote attackers
to inject arbitrary web script or HTML via unspecified vectors to (1)
user/ldap_user/check_dlg or (2) user/radius_user/check_dlg.
|
| CVE-2014-4737 |
Cross-site scripting (XSS) vulnerability in Textpattern CMS before
4.5.7 allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to setup/index.php.
|
| CVE-2014-4735 |
Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
table parameter to index.php.
|
| CVE-2014-4734 |
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107
2.0 alpha2 and earlier allows remote attackers to inject arbitrary web
script or HTML via the type parameter.
|
| CVE-2014-4728 |
The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router
(TL-WDR4300) with firmware before 140916 allows remote attackers to
cause a denial of service (crash) via a long header in a GET request.
|
| CVE-2014-4727 |
Cross-site scripting (XSS) vulnerability in the DHCP clients page in
the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with
firmware before 140916 allows remote attackers to inject arbitrary web
script or HTML via the hostname in a DHCP request.
|
| CVE-2014-4724 |
Cross-site scripting (XSS) vulnerability in the Custom Banners plugin
1.2.2.2 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the custom_banners_registered_name parameter to
wp-admin/options.php.
|
| CVE-2014-4723 |
Cross-site scripting (XSS) vulnerability in the Easy Banners plugin
1.4 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the name parameter to wp-admin/options-general.php.
|
| CVE-2014-4722 |
Multiple cross-site scripting (XSS) vulnerabilities in the OCS Reports
Web Interface in OCS Inventory NG allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4719 |
Cross-site scripting (XSS) vulnerability in the login panel
(svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 allows
remote attackers to inject arbitrary web script or HTML via the
username field.
|
| CVE-2014-4718 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar
CMS before 3.3-3 allow remote attackers to hijack the authentication
of administrators for requests that (1) add Super users via a request
to admin/user_create.php or conduct cross-site scripting (XSS) attacks
via the (2) email or (3) subject parameter in contact_form.ext.php to
admin/extensions.php.
|
| CVE-2014-4717 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Simple Share Buttons Adder plugin before 4.5 for WordPress allow
remote attackers to hijack the authentication of administrators for
requests that conduct cross-site scripting (XSS) attacks via the (1)
ssba_share_text parameter in a save action to
wp-admin/options-general.php, which is not properly handled in the
homepage, and unspecified vectors related to (2) Pages, (3) Posts, (4)
Category/Archive pages or (5) post Excerpts.
|
| CVE-2014-4710 |
Cross-site scripting (XSS) vulnerability in zero_user_account.php in
ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or
HTML via the Full Name field.
|
| CVE-2014-4694 |
Multiple cross-site scripting (XSS) vulnerabilities in
suricata_select_alias.php in the Suricata package before 1.0.6 for
pfSense through 2.1.4 allow remote attackers to inject arbitrary web
script or HTML via unspecified variables.
|
| CVE-2014-4693 |
Multiple cross-site scripting (XSS) vulnerabilities in the Snort
package before 3.0.13 for pfSense through 2.1.4 allow remote attackers
to inject arbitrary web script or HTML via (1) the eng parameter to
snort_import_aliases.php or (2) unspecified variables to
snort_select_alias.php.
|
| CVE-2014-4687 |
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before
2.1.4 allow remote attackers to inject arbitrary web script or HTML
via (1) the starttime0 parameter to firewall_schedule.php, (2) the
rssfeed parameter to rss.widget.php, (3) the servicestatusfilter
parameter to services_status.widget.php, (4) the txtRecallBuffer
parameter to exec.php, or (5) the HTTP Referer header to
log.widget.php.
|
| CVE-2014-4664 |
Cross-site scripting (XSS) vulnerability in the Wordfence Security
plugin before 5.1.4 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the whoisval parameter on the
WordfenceWhois page to wp-admin/admin.php.
|
| CVE-2014-4661 |
Cross-site scripting (XSS) vulnerability in HP Records Manager before
7.3.5 and 8.x before 8.1 Patch 3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4645 |
Cross-site scripting (XSS) vulnerability in dhcpinfo.html in D-link
DSL-2760U-E1 allows remote attackers to inject arbitrary web script or
HTML via a hostname.
|
| CVE-2014-4635 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum
Web Development Kit (WDK) before 6.8 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4633 |
Cross-site scripting (XSS) vulnerability in EMC RSA Archer GRC
Platform 5.x before 5.5.1.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4628 |
Cross-site scripting (XSS) vulnerability in EMC Isilon InsightIQ 2.x
and 3.x before 3.1 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-4606 |
Cross-site scripting (XSS) vulnerability in redirect_to_zeenshare.php
in the ZeenShare plugin 1.0.1 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the zs_sid
parameter.
|
| CVE-2014-4605 |
Cross-site scripting (XSS) vulnerability in cal/test.php in the
ZdStatistics (zdstats) plugin 2.0.1 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the lang
parameter.
|
| CVE-2014-4604 |
Cross-site scripting (XSS) vulnerability in settings/pwsettings.php in
the Your Text Manager plugin 0.3.0 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the ytmpw
parameter.
|
| CVE-2014-4603 |
Multiple cross-site scripting (XSS) vulnerabilities in
yupdates_application.php in the Yahoo! Updates for WordPress plugin
1.0 and earlier for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid
parameter.
|
| CVE-2014-4602 |
Multiple cross-site scripting (XSS) vulnerabilities in
xencarousel-admin.js.php in the XEN Carousel plugin 0.12.2 and earlier
for WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) path or (2) ajaxpath parameter.
|
| CVE-2014-4601 |
Cross-site scripting (XSS) vulnerability in wu-ratepost.php in the
Wu-Rating plugin 1.0 12319 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the v parameter.
|
| CVE-2014-4600 |
Multiple cross-site scripting (XSS) vulnerabilities in
contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and
earlier for WordPress allow remote attackers to inject arbitrary web
script or HTML via the (1) listname or (2) contact parameter.
|
| CVE-2014-4599 |
Multiple cross-site scripting (XSS) vulnerabilities in
forms/search.php in the WP-Business Directory (wp-ttisbdir) plugin
1.0.2 and earlier for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) edit, (2) search_term, (3)
page_id, (4) page, or (5) page_links parameter.
|
| CVE-2014-4598 |
Cross-site scripting (XSS) vulnerability in wp-tmkm-amazon-search.php
in the wp-tmkm-amazon plugin 1.5b and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the AID
parameter.
|
| CVE-2014-4597 |
Cross-site scripting (XSS) vulnerability in test.php in the WP Social
Invitations plugin before 1.4.4.3 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the xhrurl
parameter.
|
| CVE-2014-4596 |
Multiple cross-site scripting (XSS) vulnerabilities in
js/button-snapapp.php in the SnapApp plugin 1.5 and earlier for
WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) msg or (2) act parameter.
|
| CVE-2014-4595 |
Multiple cross-site scripting (XSS) vulnerabilities in the WP RESTful
plugin 0.1 and earlier for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) oauth_callback parameter to
html_api_authorize.php or the (2) oauth_token_temp or (3)
oauth_callback_temp parameter to html_api_login.php.
|
| CVE-2014-4594 |
Cross-site scripting (XSS) vulnerability in index.php in the WordPress
Responsive Preview plugin before 1.2 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the url
parameter.
|
| CVE-2014-4593 |
Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php
in the WP Plugin Manager (wppm) plugin 1.6.4.b and earlier for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the filter parameter.
|
| CVE-2014-4591 |
Cross-site scripting (XSS) vulnerability in picasa_upload.php in the
WP-Picasa-Image plugin 1.0 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the post_id
parameter.
|
| CVE-2014-4590 |
Cross-site scripting (XSS) vulnerability in get.php in the WP
Microblogs plugin 0.4.0 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the
oauth_verifier parameter.
|
| CVE-2014-4589 |
Cross-site scripting (XSS) vulnerability in uploader.php in the WP
Silverlight Media Player (wp-media-player) plugin 0.8 and earlier for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the post_id parameter.
|
| CVE-2014-4588 |
Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the
Hot Files: File Sharing and Download Manager (wphotfiles) plugin 1.0.0
and earlier for WordPress allows remote attackers to inject arbitrary
web script or HTML via the mediaid parameter.
|
| CVE-2014-4587 |
Multiple cross-site scripting (XSS) vulnerabilities in the WP GuestMap
plugin 1.8 and earlier for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) zl, (2) mt, or (3) dc
parameter to guest-locator.php; the (4) zl, (5) mt, (6) activate, or
(7) dc parameter to online-tracker.php; the (8) zl, (9) mt, or (10) dc
parameter to stats-map.php; or the (11) zl, (12) mt, (13) activate, or
(14) dc parameter to weather-map.php.
|
| CVE-2014-4586 |
Multiple cross-site scripting (XSS) vulnerabilities in the wp-football
plugin 1.1 and earlier for WordPress allow remote attackers to inject
arbitrary web script or HTML via the league parameter to (1)
football_classification.php, (2) football_criteria.php, (3)
templates/template_default_preview.php, or (4)
templates/template_worldCup_preview.php; the (5) f parameter to
football-functions.php; the id parameter in an "action" action to (6)
football_groups_list.php, (7) football_matches_list.php, (8)
football_matches_phase.php, or (9) football_phases_list.php; or the
(10) id_league parameter in a delete action to
football_matches_load.php.
|
| CVE-2014-4585 |
Cross-site scripting (XSS) vulnerability in the WP-FaceThumb plugin
possibly 1.0 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the ajax_url parameter to
index.php.
|
| CVE-2014-4584 |
Cross-site scripting (XSS) vulnerability in admin/editFacility.php in
the wp-easybooking plugin 1.0.3 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the fID
parameter.
|
| CVE-2014-4583 |
Multiple cross-site scripting (XSS) vulnerabilities in
forms/messages.php in the WP-Contact (wp-contact-sidebar-widget)
plugin 1.0 and earlier for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) edit, (2) order_direction,
(3) limit_start, (4) id, or (5) order parameter.
|
| CVE-2014-4582 |
Cross-site scripting (XSS) vulnerability in
admin/admin_show_dialogs.php in the WP Consultant plugin 1.0 and
earlier for WordPress allows remote attackers to inject arbitrary web
script or HTML via the dialog_id parameter.
|
| CVE-2014-4581 |
Cross-site scripting (XSS) vulnerability in facture.php in the WPCB
plugin 2.4.8 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the id parameter.
|
| CVE-2014-4580 |
Cross-site scripting (XSS) vulnerability in blipbot.ajax.php in the WP
BlipBot plugin 3.0.9 and earlier for WordPress allows remote attackers
to inject arbitrary web script or HTML via the BlipBotID parameter.
|
| CVE-2014-4579 |
Cross-site scripting (XSS) vulnerability in js/test.php in the
Appointments Scheduler plugin 1.5 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the lang
parameter.
|
| CVE-2014-4578 |
Cross-site scripting (XSS) vulnerability in
asset-studio/icons-launcher.php in the WP App Maker plugin 1.0.16.4
and earlier for WordPress allows remote attackers to inject arbitrary
web script or HTML via the uid parameter.
|
| CVE-2014-4576 |
Cross-site scripting (XSS) vulnerability in services/diagnostics.php
in the WordPress Social Login plugin 2.0.3 and earlier for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
xhrurl parameter.
|
| CVE-2014-4575 |
Cross-site scripting (XSS) vulnerability in js/window.php in the
Wikipop plugin 2.0 and earlier for WordPress allows remote attackers
to inject arbitrary web script or HTML via the s parameter.
|
| CVE-2014-4574 |
Cross-site scripting (XSS) vulnerability in resize.php in the
WebEngage plugin before 2.0.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the height parameter.
|
| CVE-2014-4573 |
Multiple cross-site scripting (XSS) vulnerabilities in frame-maker.php
in the Walk Score plugin 0.5.5 and earlier for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) s or (2)
o parameter.
|
| CVE-2014-4572 |
Cross-site scripting (XSS) vulnerability in bvc.php in the Votecount
for Balatarin plugin 0.1.1 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the (1) url or
(2) bvcurl parameter.
|
| CVE-2014-4571 |
Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in
the VN-Calendar plugin 1.0 and earlier for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) fs or (2)
w parameter.
|
| CVE-2014-4570 |
Multiple cross-site scripting (XSS) vulnerabilities in the
VideoWhisper Video Presentation plugin before 3.31 for WordPress allow
remote attackers to inject arbitrary web script or HTML via the (1)
room_name parameter to c_login.php or (2) room parameter to index.php
in vp/.
|
| CVE-2014-4569 |
Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the
VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the room_name parameter.
|
| CVE-2014-4568 |
Cross-site scripting (XSS) vulnerability in
posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder
plugin 1.55.4 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the message parameter.
|
| CVE-2014-4566 |
Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php
in the "verwei.se - WordPress - Twitter" (verweise-wordpress-twitter)
plugin 1.0.2 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the base parameter.
|
| CVE-2014-4565 |
Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in
the Verification Code for Comments plugin 2.1.0 and earlier for
WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter.
|
| CVE-2014-4564 |
Cross-site scripting (XSS) vulnerability in check.php in the Validated
plugin 1.0.2 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the slug parameter.
|
| CVE-2014-4563 |
Cross-site scripting (XSS) vulnerability in go.php in the URL Cloak &
Encrypt (url-cloak-encrypt) plugin 2.0 and earlier for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
url parameter.
|
| CVE-2014-4560 |
Cross-site scripting (XSS) vulnerability in includes/getTipo.php in
the ToolPage plugin 1.6.1 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the t parameter.
|
| CVE-2014-4557 |
Cross-site scripting (XSS) vulnerability in test-plugin.php in the
Swipe Checkout for Jigoshop (swipe-hq-checkout-for-jigoshop) plugin
3.1.0 and earlier for WordPress allows remote attackers to inject
arbitrary web script or HTML via the api_url parameter.
|
| CVE-2014-4556 |
Cross-site scripting (XSS) vulnerability in test-plugin.php in the
Swipe Checkout for eShop plugin 3.7.0 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the
api_url parameter.
|
| CVE-2014-4555 |
Cross-site scripting (XSS) vulnerability in fonts/font-form.php in the
Style It plugin 1.0 and earlier for WordPress allows remote attackers
to inject arbitrary web script or HTML via the mode parameter.
|
| CVE-2014-4554 |
Cross-site scripting (XSS) vulnerability in templates/download.php in
the SS Downloads plugin before 1.5 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the title
parameter.
|
| CVE-2014-4552 |
Cross-site scripting (XSS) vulnerability in
library/includes/payment/paypalexpress/DoDirectPayment.php in the
Spotlight (spotlightyour) plugin 4.7 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the
paymentType parameter.
|
| CVE-2014-4551 |
Cross-site scripting (XSS) vulnerability in diagnostics/test.php in
the Social Connect plugin 1.0.4 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the
testing parameter.
|
| CVE-2014-4549 |
Multiple cross-site scripting (XSS) vulnerabilities in
pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway
plugin before 0.1.6.7 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) MD or (2) PARes parameter.
|
| CVE-2014-4547 |
Multiple cross-site scripting (XSS) vulnerabilities in
templates/default/index_ajax.php in the Rezgo Online Booking plugin
before 1.8.2 for WordPress allow remote attackers to inject arbitrary
web script or HTML via the (1) tags or (2) search_for parameter.
|
| CVE-2014-4546 |
Cross-site scripting (XSS) vulnerability in book_ajax.php in the Rezgo
plugin 1.4.2 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the response parameter.
|
| CVE-2014-4545 |
Multiple cross-site scripting (XSS) vulnerabilities in pq_dialog.php
in the Pro Quoter plugin 1.0 and earlier for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1)
leftorright or (2) author parameter.
|
| CVE-2014-4543 |
Multiple cross-site scripting (XSS) vulnerabilities in
payper/payper.php in the Pay Per Media Player plugin 1.24 and earlier
for WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) fcolor, (2) links, (3) stitle, (4) height, (5) width,
(6) host, (7) bcolor, (8) msg, (9) id, or (10) size parameter.
|
| CVE-2014-4542 |
Cross-site scripting (XSS) vulnerability in redirect.php in the Ooorl
plugin for WordPress allows remote attackers to inject arbitrary web
script or HTML via the url parameter.
|
| CVE-2014-4541 |
Cross-site scripting (XSS) vulnerability in
shortcode-generator/preview-shortcode-external.php in the OMFG Mobile
Pro plugin 1.1.26 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the shortcode parameter.
|
| CVE-2014-4540 |
Cross-site scripting (XSS) vulnerability in
oleggo-twitter/twitter_login_form.php in the Oleggo LiveStream plugin
0.2.6 and earlier for WordPress allows remote attackers to inject
arbitrary web script or HTML via the msg parameter.
|
| CVE-2014-4538 |
Cross-site scripting (XSS) vulnerability in process.php in the Malware
Finder plugin 1.1 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the query parameter.
|
| CVE-2014-4537 |
Cross-site scripting (XSS) vulnerability in inpage.tpl.php in the
Keyword Strategy Internal Links plugin 2.0 and earlier for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
(1) sort, (2) search, or (3) dir parameter.
|
| CVE-2014-4534 |
Multiple cross-site scripting (XSS) vulnerabilities in
videoplayer/autoplay.php in the HTML5 Video Player with Playlist
plugin 2.4.0 and earlier for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) theme or (2)
playlistmod parameter.
|
| CVE-2014-4533 |
Cross-site scripting (XSS) vulnerability in ajax_functions.php in the
GEO Redirector plugin 1.0.1 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the hid_id
parameter.
|
| CVE-2014-4532 |
Cross-site scripting (XSS) vulnerability in
templates/printAdminUsersList_Footer.tpl.php in the GarageSale plugin
before 1.2.3 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the page parameter.
|
| CVE-2014-4531 |
Cross-site scripting (XSS) vulnerability in main_page.php in the Game
tabs plugin 0.4.0 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the n parameter.
|
| CVE-2014-4529 |
Cross-site scripting (XSS) vulnerability in fpg_preview.php in the
Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the path
parameter.
|
| CVE-2014-4528 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/swarm-settings.php in the Bugs Go Viral : Facebook Promotion
Generator (fbpromotions) plugin 1.3.4 and earlier for WordPress allow
remote attackers to inject arbitrary web script or HTML via the (1)
promo_type, (2) fb_edit_action, or (3) promo_id parameter.
|
| CVE-2014-4527 |
Multiple cross-site scripting (XSS) vulnerabilities in
paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing
and Newsletters (envialosimple-email-marketing-y-newsletters-gratis)
plugin before 1.98 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) FormID or (2) AdministratorID
parameter.
|
| CVE-2014-4526 |
Multiple cross-site scripting (XSS) vulnerabilities in callback.php in
the efence plugin 1.3.2 and earlier for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) message,
(2) zoneid, (3) pubKey, or (4) privKey parameter.
|
| CVE-2014-4524 |
Cross-site scripting (XSS) vulnerability in
classes/custom-image/media.php in the WP Easy Post Types plugin before
1.4.4 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the ref parameter.
|
| CVE-2014-4522 |
Cross-site scripting (XSS) vulnerability in client-assist.php in the
dsSearchAgent: WordPress Edition plugin 1.0-beta10 and earlier for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the action parameter.
|
| CVE-2014-4521 |
Cross-site scripting (XSS) vulnerability in client-assist.php in the
dsIDXpress IDX plugin before 2.1.1 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the action
parameter.
|
| CVE-2014-4520 |
Cross-site scripting (XSS) vulnerability in phprack.php in the DMCA
WaterMarker plugin before 1.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the plugin_dir parameter.
|
| CVE-2014-4518 |
Cross-site scripting (XSS) vulnerability in xd_resize.php in the
Contact Form by ContactMe.com plugin 2.3 and earlier for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
width parameter.
|
| CVE-2014-4517 |
Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the
CBI Referral Manager plugin 1.2.1 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the
searchString parameter.
|
| CVE-2014-4516 |
Cross-site scripting (XSS) vulnerability in bicm-carousel-preview.php
in the BIC Media Widget plugin 1.0 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the param
parameter.
|
| CVE-2014-4515 |
Cross-site scripting (XSS) vulnerability in mce_anyfont/dialog.php in
the AnyFont plugin 2.2.3 and earlier for WordPress allows remote
attackers to inject arbitrary web script or HTML via the text
parameter.
|
| CVE-2014-4514 |
Cross-site scripting (XSS) vulnerability in
includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0
and earlier for WordPress allows remote attackers to inject arbitrary
web script or HTML via vectors related to the getDebugInfo function.
|
| CVE-2014-4513 |
Multiple cross-site scripting (XSS) vulnerabilities in
server/offline.php in the ActiveHelper LiveHelp Live Chat plugin 3.1.0
and earlier for WordPress allow remote attackers to inject arbitrary
web script or HTML via the (1) MESSAGE, (2) EMAIL, or (3) NAME
parameter.
|
| CVE-2014-4510 |
Cross-site scripting (XSS) vulnerability in job.cc in apt-cacher-ng
0.7.26 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL.
|
| CVE-2014-4506 |
Cross-site scripting (XSS) vulnerability in the Custom Meta module
6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows
remote authenticated users with the "administer custom meta settings"
permission to inject arbitrary web script or HTML via the (1)
attribute or (2) content value for a meta tag.
|
| CVE-2014-4505 |
Cross-site scripting (XSS) vulnerability in the Easy Breadcrumb module
7.x-2.x before 7.x-2.10 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4406 |
Cross-site scripting (XSS) vulnerability in Xcode Server in
CoreCollaboration in Apple OS X Server before 3.2.1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-4349 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote
authenticated users to inject arbitrary web script or HTML via a
crafted table name that is improperly handled after a (1) hide or (2)
unhide action.
|
| CVE-2014-4348 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
4.2.x before 4.2.4 allow remote authenticated users to inject
arbitrary web script or HTML via a crafted (1) database name or (2)
table name that is improperly handled after presence in (a) the
favorite list or (b) recent tables.
|
| CVE-2014-4346 |
Cross-site scripting (XSS) vulnerability in administration user
interface in Citrix NetScaler Application Delivery Controller (ADC)
and NetScaler Gateway (formerly Access Gateway Enterprise Edition)
10.1 before 10.1-126.12 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-4335 |
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive
6.7.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) host or (2) password parameter to
rtl/protected/admin/ddns/.
|
| CVE-2014-4331 |
Cross-site scripting (XSS) vulnerability in admin/viewer.php in
OctavoCMS allows remote attackers to inject arbitrary web script or
HTML via the src parameter.
|
| CVE-2014-4329 |
Cross-site scripting (XSS) vulnerability in lua/host_details.lua in
ntopng 1.1 allows remote attackers to inject arbitrary web script or
HTML via the host parameter.
|
| CVE-2014-4312 |
Multiple cross-site scripting (XSS) vulnerabilities in Epicor
Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote attackers to
inject arbitrary web script or HTML via the (1) Notes section to Order
details; (2) Description section to "Order to consume"; (3) Favorites
name section to Favorites; (4) FiltKeyword parameter to
Procurement/EKPHTML/search_item_bt.asp; (5) Act parameter to
Procurement/EKPHTML/EnterpriseManager/Budget/ImportBudget_fr.asp; (6)
hdnOpener or (7) hdnApproverFieldName parameter to
Procurement/EKPHTML/EnterpriseManager/UserSearchDlg.asp; or (8)
INTEGRATED parameter to
Procurement/EKPHTML/EnterpriseManager/Codes.asp.
|
| CVE-2014-4309 |
Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99
allow remote attackers to inject arbitrary web script or HTML via the
(1) TinkerAjax parameter to uptime.html, or remote authenticated users
to inject arbitrary web script or HTML via the (2) MaxInstances, (3)
PassivePorts, (4) Port, (5) ServerName, (6) TimeoutLogin, (7)
TimeoutNoTransfer, or (8) TimeoutStalled parameter to
admin/services_ftp.html; the (9) dns1 or (10) dns2 parameter to
admin/system.html; the (11) newTgtName parameter to
admin/volumes_iscsi_targets.html; the User-Agent HTTP header to (12)
language.html, (13) login.html, or (14) password.html in account/; or
the User-Agent HTTP header to (15) account_groups.html, (16)
account_users.html, (17) services.html, (18) services_ftp.html, (19)
services_iscsi_target.html, (20) services_rsync.html, (21)
system_clock.html, (22) system_info.html, (23) system_ups.html, (24)
volumes_editpartitions.html, or (25) volumes_iscsi_targets.html in
admin/.
|
| CVE-2014-4308 |
Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording
eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers to
inject arbitrary web script or HTML via the (1) USRLNM parameter to
myaccount/mysettings.edit.validate.asp or the frame parameter to (2)
iframe.picker.statchannels.asp, (3) iframe.picker.channelgroups.asp,
(4) iframe.picker.extensions.asp, (5)
iframe.picker.licenseusergroups.asp, (6)
iframe.picker.licenseusers.asp, (7) iframe.picker.lookup.asp, or (8)
iframe.picker.marks.asp in _ifr/.
|
| CVE-2014-4304 |
Cross-site scripting (XSS) vulnerability in browse.php in SQL Buddy
1.3.3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the table parameter.
|
| CVE-2014-4303 |
Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme
7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users
with the Administer themes permission to inject arbitrary web script
or HTML via vectors related to the (1) Twitter and (2) Facebook
username settings.
|
| CVE-2014-4302 |
Cross-site scripting (XSS) vulnerability in rating/rating.php in HAM3D
Shop Engine allows remote attackers to inject arbitrary web script or
HTML via the ID parameter.
|
| CVE-2014-4301 |
Multiple cross-site scripting (XSS) vulnerabilities in the
respond_error function in routing.py in Eugene Pankov Ajenti before
1.2.21.7 allow remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to (1) resources.js or (2) resources.css in
ajenti:static/, related to the traceback page.
|
| CVE-2014-4195 |
Cross-site scripting (XSS) vulnerability in zero_view_article.php in
ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or
HTML via the article_id parameter.
|
| CVE-2014-4189 |
Cross-site scripting (XSS) vulnerability in Hitachi Tuning Manager
before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Performance Management
- Manager Web Option 07-00 through 07-54 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4187 |
Cross-site scripting (XSS) vulnerability in signup.php in ClipBucket
allows remote attackers to inject arbitrary web script or HTML via the
Username field.
|
| CVE-2014-4166 |
Cross-site scripting (XSS) vulnerability in the song history in
SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web
script or HTML via the mp3 title field.
|
| CVE-2014-4165 |
Cross-site scripting (XSS) vulnerability in ntop allows remote
attackers to inject arbitrary web script or HTML via the title
parameter in a list action to plugins/rrdPlugin.
|
| CVE-2014-4164 |
Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 6.3-b230
allows remote attackers to inject arbitrary web script or HTML via a
user signature to SelfService/Prefs.html.
|
| CVE-2014-4161 |
Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP
Supplier Relationship Management (SRM) allows remote attackers to
inject arbitrary web script or HTML via the url parameter.
|
| CVE-2014-4160 |
Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas
node in SAP NetWeaver Business Client (NWBC) allow remote attackers to
inject arbitrary web script or HTML via the (1) title or (2)
sap-accessibility parameter.
|
| CVE-2014-4116 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Foundation 2010 SP2 allows remote authenticated users to inject
arbitrary web script or HTML via a modified list, aka "SharePoint
Elevation of Privilege Vulnerability."
|
| CVE-2014-4075 |
Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in
Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows
remote attackers to inject arbitrary web script or HTML via a crafted
web page, aka "MVC XSS Vulnerability."
|
| CVE-2014-4070 |
Cross-site scripting (XSS) vulnerability in the Web Components Server
in Microsoft Lync Server 2013 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka "Lync XSS
Information Disclosure Vulnerability."
|
| CVE-2014-4037 |
Cross-site scripting (XSS) vulnerability in
editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php
in FCKeditor before 2.6.11 and earlier allows remote attackers to
inject arbitrary web script or HTML via an array key in the
textinputs[] parameter, a different issue than CVE-2012-4000.
|
| CVE-2014-4036 |
Cross-site scripting (XSS) vulnerability in modules/system/admin.php
in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web
script or HTML via the query parameter in a listimg action.
|
| CVE-2014-4035 |
Cross-site scripting (XSS) vulnerability in booking_details.php in
Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote
attackers to inject arbitrary web script or HTML via the title
parameter.
|
| CVE-2014-4033 |
Cross-site scripting (XSS) vulnerability in
libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4
allows remote attackers to inject arbitrary web script or HTML via the
surname parameter to student.php.
|
| CVE-2014-4032 |
Cross-site scripting (XSS) vulnerability in
apps/app_comment/form_comment.php in Fiyo CMS 1.5.7 allows remote
attackers to inject arbitrary web script or HTML via the Nama field.
|
| CVE-2014-4023 |
Cross-site scripting (XSS) vulnerability in tmui/dashboard/echo.jsp in
the Configuration utility in F5 BIG-IP LTM, APM, ASM, GTM, and Link
Controller 11.0.0 before 11.6.0 and 10.1.0 through 10.2.4, AAM 11.4.0
before 11.6.0, AFM and PEM 11.3.0 before 11.6.0, Analytics 11.0.0
through 11.5.1, Edge Gateway, WebAccelerator, and WOM 11.0.0 through
11.3.0 and 10.1.0 through 10.2.4, and PSM 11.0.0 through 11.4.1 and
10.1.0 through 10.2.4 and Enterprise Manager 3.0.0 through 3.1.1 and
2.1.0 through 2.3.0 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-4017 |
Cross-site scripting (XSS) vulnerability in the Conversion Ninja
plugin for WordPress allows remote attackers to inject arbitrary web
script or HTML via the id parameter to lp/index.php.
|
| CVE-2014-4002 |
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b
allow remote attackers to inject arbitrary web script or HTML via the
(1) drp_action parameter to cdef.php, (2) data_input.php, (3)
data_queries.php, (4) data_sources.php, (5) data_templates.php, (6)
graph_templates.php, (7) graphs.php, (8) host.php, or (9)
host_templates.php or the (10) graph_template_input_id or (11)
graph_template_id parameter to graph_templates_inputs.php.
|
| CVE-2014-3995 |
Cross-site scripting (XSS) vulnerability in
gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x
before 0.8.3 for Django allows remote attackers to inject arbitrary
web script or HTML via a user display name.
|
| CVE-2014-3994 |
Cross-site scripting (XSS) vulnerability in
util/templatetags/djblets_js.py in Djblets before 0.7.30 and 0.8.x
before 0.8.3 for Django, as used in Review Board, allows remote
attackers to inject arbitrary web script or HTML via a JSON object, as
demonstrated by the name field when changing a user name.
|
| CVE-2014-3991 |
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr
ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or
HTML via the (1) dol_use_jmobile, (2) dol_optimize_smallscreen, (3)
dol_no_mouse_hover, (4) dol_hide_topmenu, (5) dol_hide_leftmenu, (6)
mainmenu, or (7) leftmenu parameter to index.php; the (8)
dol_use_jmobile, (9) dol_optimize_smallscreen, (10)
dol_no_mouse_hover, (11) dol_hide_topmenu, or (12) dol_hide_leftmenu
parameter to user/index.php; the (13) dol_use_jmobile, (14)
dol_optimize_smallscreen, (15) dol_no_mouse_hover, (16)
dol_hide_topmenu, or (17) dol_hide_leftmenu parameter to
user/logout.php; the (18) email, (19) firstname, (20) job, (21)
lastname, or (22) login parameter in an update action in a "User Card"
to user/fiche.php; or the (23) modulepart or (24) file parameter to
viewimage.php.
|
| CVE-2014-3988 |
Cross-site scripting (XSS) vulnerability in index.php in SunHater
KCFinder 3.11 and earlier allows remote attackers to inject arbitrary
web script or HTML via (1) file or (2) directory (folder) name of an
uploaded file.
|
| CVE-2014-3974 |
Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS
3.0 and earlier allows remote attackers to inject arbitrary web script
or HTML via the viewdir parameter.
|
| CVE-2014-3966 |
Cross-site scripting (XSS) vulnerability in Special:PasswordReset in
MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before
1.22.7, when wgRawHtml is enabled, allows remote attackers to inject
arbitrary web script or HTML via an invalid username.
|
| CVE-2014-3960 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before
1.12.7 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-3959 |
Cross-site scripting (XSS) vulnerability in list.jsp in the
Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM,
and Link Controller 11.2.1 through 11.5.1, AAM 11.4.0 through 11.5.1
PEM 11.3.0 through 11.5.1, PSM 11.2.1 through 11.4.1, WebAccelerator
and WOM 11.2.1 through 11.3.0, and Enterprise Manager 3.0.0 through
3.1.1 allows remote attackers to inject arbitrary web script or HTML
via unspecified parameters.
|
| CVE-2014-3949 |
Cross-site scripting (XSS) vulnerability in the layout wizard in the
Grid Elements (gridelements) extension before 1.5.1 and 2.0.x before
2.0.3 for TYPO3 allows remote authenticated backend users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-3948 |
Cross-site scripting (XSS) vulnerability in the HTML export wizard in
the backend module in the powermail extension before 1.6.11 for TYPO3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-3943 |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified
backend components in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19,
6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allow
remote authenticated editors to inject arbitrary web script or HTML
via unknown parameters.
|
| CVE-2014-3933 |
Cross-site scripting (XSS) vulnerability in the address components
field formatter in the AddressField Tokens module 7.x-1.x before
7.x-1.4 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via an address field.
|
| CVE-2014-3926 |
Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9
allows remote attackers to inject arbitrary web script or HTML via the
"addr" parameter.
|
| CVE-2014-3924 |
Multiple cross-site scripting (XSS) vulnerabilities in Webmin before
1.690 and Usermin before 1.600 allow remote attackers to inject
arbitrary web script or HTML via vectors related to popup windows.
|
| CVE-2014-3923 |
Multiple cross-site scripting (XSS) vulnerabilities in the Digital
Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote
attackers to inject arbitrary web script or HTML via the logoLink
parameter to (1) preview.swf, (2) preview_skin_rouge.swf, (3)
preview_allchars.swf, or (4) preview_skin_overlay.swf in deploy/.
|
| CVE-2014-3922 |
Cross-site scripting (XSS) vulnerability in Trend Micro InterScan
Messaging Security Virtual Appliance 8.5.1.1516 allows remote
authenticated users to inject arbitrary web script or HTML via the
addWhiteListDomainStr parameter to addWhiteListDomain.imss.
|
| CVE-2014-3921 |
Cross-site scripting (XSS) vulnerability in popup.php in the Simple
Popup Images plugin for WordPress allows remote attackers to inject
arbitrary web script or HTML via the z parameter.
|
| CVE-2014-3905 |
Cross-site scripting (XSS) vulnerability in tenfourzero Shutter 0.1.4
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-3903 |
Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x
before 1.6.2 for WordPress allows remote authenticated users to inject
arbitrary web script or HTML via crafted Exif data.
|
| CVE-2014-3900 |
Cross-site scripting (XSS) vulnerability in admin/picture_modify.php
in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote
attackers to inject arbitrary web script or HTML via the associate[]
field, a different vulnerability than CVE-2014-4649.
|
| CVE-2014-3898 |
Cross-site scripting (XSS) vulnerability in Fujitsu ServerView
Operations Manager 5.00.09 through 6.30.05 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-3897 |
Cross-site scripting (XSS) vulnerability in Homepage Decorator
PerlMailer 3.10 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-3894 |
Cross-site scripting (XSS) vulnerability in PHP Kobo Multifunctional
MailForm Free 2014/1/28 and earlier allows remote attackers to inject
arbitrary web script or HTML via an HTTP Referer header.
|
| CVE-2014-3892 |
Cross-site scripting (XSS) vulnerability in Nexa Meridian before 2014
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-3887 |
Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk
with firmware before 1.05e1-2.0.5 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors. NOTE:
This vulnerability exists because of an incomplete fix for
CVE-2013-4713.
|
| CVE-2014-3886 |
Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when
referrer checking is disabled, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors. NOTE: this might
overlap CVE-2014-3924.
|
| CVE-2014-3885 |
Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors. NOTE: this might overlap CVE-2014-3924.
|
| CVE-2014-3884 |
Cross-site scripting (XSS) vulnerability in Usermin before 1.600
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: this might overlap CVE-2014-3924.
|
| CVE-2014-3878 |
Multiple cross-site scripting (XSS) vulnerabilities in the web client
interface in Ipswitch IMail Server 12.3 and 12.4, possibly before
12.4.1.15, allow remote attackers to inject arbitrary web script or
HTML via (1) the Name field in an add new contact action in the
Contacts section or unspecified vectors in (2) an Add Group task in
the Contacts section, (3) an add new event action in the Calendar
section, or (4) the Task section.
|
| CVE-2014-3877 |
Incomplete blacklist vulnerability in Frams' Fast File EXchange (F*EX,
aka fex) before fex-20140530 allows remote attackers to conduct
cross-site scripting (XSS) attacks via the addto parameter to fup.
|
| CVE-2014-3876 |
Multiple cross-site scripting (XSS) vulnerabilities in Frams' Fast
File EXchange (F*EX, aka fex) before fex-20140530 allow remote
attackers to inject arbitrary web script or HTML via the (1) akey
parameter to rup or (2) disclaimer or (3) gm parameter to fuc.
|
| CVE-2014-3870 |
Cross-site scripting (XSS) vulnerability in the bib2html plugin 0.9.3
for WordPress allows remote attackers to inject arbitrary web script
or HTML via the styleShortName parameter in an adminStyleAdd action to
OSBiB/create/index.php.
|
| CVE-2014-3863 |
Cross-site scripting (XSS) vulnerability in the JChatSocial component
before 2.3 for Joomla! allows remote attackers to inject arbitrary web
script or HTML via the filename parameter in a file upload in an
active JChat chat window.
|
| CVE-2014-3861 |
Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1
and earlier allows remote attackers to inject arbitrary web script or
HTML via a crafted reference element within a nonXMLBody element.
|
| CVE-2014-3854 |
Cross-site request forgery (CSRF) vulnerability in admin/addScript.py
in Pyplate 0.08 allows remote attackers to hijack the authentication
of administrators for requests that conduct cross-site scripting (XSS)
attacks via the title parameter.
|
| CVE-2014-3846 |
Cross-site scripting (XSS) vulnerability in Flying Cart allows remote
attackers to inject arbitrary web script or HTML via the p parameter
to index.php.
|
| CVE-2014-3842 |
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360
plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt
parameter.
|
| CVE-2014-3841 |
Cross-site scripting (XSS) vulnerability in the Contact Bank plugin
before 2.0.20 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the Label field, related to form
layout configuration. NOTE: some of these details are obtained from
third party information.
|
| CVE-2014-3840 |
Multiple cross-site scripting (XSS) vulnerabilities in
apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13
allow remote authenticated users to inject arbitrary web script or
HTML via a (1) tag or the (2) title of a source in a Staging folder,
(3) Name field in a bootstrap setup, or Title field in a (4) smart
link or (5) web form.
|
| CVE-2014-3836 |
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud
Server before 6.0.3 allow remote attackers to hijack the
authentication of users for requests that (1) conduct cross-site
scripting (XSS) attacks, (2) modify files, or (3) rename files via
unspecified vectors.
|
| CVE-2014-3833 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Gallery
and (2) core components in ownCloud Server before 5.016 and 6.0.x
before 6.0.3 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors, possibly related to the print_unescaped
function.
|
| CVE-2014-3832 |
Cross-site scripting (XSS) vulnerability in the Documents component in
ownCloud Server 6.0.x before 6.0.3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, possibly related
to the print_unescaped function.
|
| CVE-2014-3830 |
Cross-site scripting (XSS) vulnerability in info.php in TomatoCart
1.1.8.6.1 allows remote attackers to inject arbitrary web script or
HTML via the faqs_id parameter.
|
| CVE-2014-3824 |
Cross-site scripting (XSS) vulnerability in the web server in the
Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE
OS 8.0 before 8.0r6, 7.4 before 7.4r13, and 7.1 before 7.1r20 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-3821 |
Cross-site scripting (XSS) vulnerability in SRX Web Authentication
(webauth) in Juniper Junos 11.4 before 11.4R11, 12.1X44 before
12.1X44-D34, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20,
and 12.1X47 before 12.1X47-D10 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-3820 |
Cross-site scripting (XSS) vulnerability in the SSL VPN/UAC web server
in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices
with IVE OS 7.1 before 7.1r16, 7.4 before 7.4r3, and 8.0 before 8.0r1
and the Juniper Junos Pulse Access Control Service devices with UAC OS
4.1 before 4.1r8, 4.4 before 4.4r3 and 5.0 before 5.0r1 allows remote
administrators to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-3808 |
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive
before 6.7.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) role parameter to roles.lsp, (2) name parameter to
user.lsp, (3) path parameter to wizard/setuser.lsp, (4) host parameter
to tunnelconstr.lsp, or (5) newpath parameter to wfsconstr.lsp in
rtl/protected/admin/.
|
| CVE-2014-3807 |
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive
6.7.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) blog, (2) bloggeruser, or (3) bloggerpasswd parameter to
private/manage/.
|
| CVE-2014-3797 |
Cross-site scripting (XSS) vulnerability in VMware vCenter Server
Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-3786 |
Multiple cross-site scripting (XSS) vulnerabilities in the contact
module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote
attackers to inject arbitrary web script or HTML via the (1) uemail or
(2) subject parameter in the Contact form to contact/.
|
| CVE-2014-3779 |
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine
ADSelfService Plus before 5.2 Build 5202 allows remote attackers to
inject arbitrary web script or HTML via the name parameter to
GroupSubscription.do.
|
| CVE-2014-3774 |
Multiple cross-site scripting (XSS) vulnerabilities in items.php in
TeamPass before 2.1.20 allow remote attackers to inject arbitrary web
script or HTML via the group parameter, which is not properly handled
in a (1) hid_cat or (2) open_folder form element, or (3) id parameter,
which is not properly handled in the open_id form element.
|
| CVE-2014-3764 |
Cross-site scripting (XSS) vulnerability in the web-based device
management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x
before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka Ref
ID 64563.
|
| CVE-2014-3761 |
Cross-site scripting (XSS) vulnerability in D-Link DAP 1150 with
firmware 1.2.94 allows remote attackers to inject arbitrary web script
or HTML via the res_buf parameter to index.cgi in the
Control/URL-filter section.
|
| CVE-2014-3760 |
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link
DAP 1150 with firmware 1.2.94 allow remote attackers to hijack the
authentication of administrators for requests that (1) enable or (2)
disable the DMZ in the Firewall/DMZ section via a request to index.cgi
or (3) add, (4) modify, or (5) delete URL-filter settings in the
Control/URL-filter section via a request to index.cgi, as demonstrated
by adding a rule that blocks access to google.com.
|
| CVE-2014-3759 |
Multiple SQL injection vulnerabilities in the BibTex Publications
(si_bibtex) extension 0.2.3 for TYPO3 allow remote attackers to
execute arbitrary SQL commands via vectors related to the (1) search
or (2) list functionality.
|
| CVE-2014-3758 |
Cross-site scripting (XSS) vulnerability in the BibTex Publications
(si_bibtex) extension 0.2.3 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via vectors related to the import
functionality.
|
| CVE-2014-3740 |
Cross-site scripting (XSS) vulnerability in SpiceWorks before
7.2.00195 allows remote authenticated users to inject arbitrary web
script or HTML via the Summary field in a ticket request to the portal
page.
|
| CVE-2014-3739 |
Open redirect vulnerability in
zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows
remote attackers to redirect users to arbitrary web sites and conduct
phishing attacks via a URL in the came_from parameter.
|
| CVE-2014-3738 |
Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote
attackers to inject arbitrary web script or HTML via the title of a
device.
|
| CVE-2014-3737 |
Cross-site scripting (XSS) vulnerability in
templates/defaultheader.php in Lamp Design Storesprite before 7 -
19-06-14, when using the currency selection dropdown, allows remote
attackers to inject arbitrary web script or HTML via the PATH_INFO to
brand.php, related to the currencyUrl function.
|
| CVE-2014-3681 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and
LTS before 1.565.3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-3678 |
Cross-site scripting (XSS) vulnerability in the Monitoring plugin
before 1.53.0 for Jenkins allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-3654 |
Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java
2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2)
channels/software/Entitlements.do, or (3) admin/multiorg/OrgUsers.do.
|
| CVE-2014-3653 |
Cross-site scripting (XSS) vulnerability in the template preview
function in Foreman before 1.6.1 allows remote attackers to inject
arbitrary web script or HTML via a crafted provisioning template.
|
| CVE-2014-3628 |
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin /
Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to
inject arbitrary web script or HTML via the fieldvaluecache object.
|
| CVE-2014-3595 |
Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39,
1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4
through 5.6 allows remote attackers to inject arbitrary web script or
HTML via a crafted request that is not properly handled when logging.
|
| CVE-2014-3594 |
Cross-site scripting (XSS) vulnerability in the Host Aggregates
interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1
before 2014.1.2, and Juno before Juno-3 allows remote administrators
to inject arbitrary web script or HTML via a new host aggregate name.
|
| CVE-2014-3551 |
Multiple cross-site scripting (XSS) vulnerabilities in the
advanced-grading implementation in Moodle through 2.3.11, 2.4.x before
2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1
allow remote authenticated users to inject arbitrary web script or
HTML via a crafted (1) qualification or (2) rating field in a rubric.
|
| CVE-2014-3550 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 allow
remote attackers to inject arbitrary web script or HTML via vectors
that trigger a crafted (1) error or (2) success message for a
scheduled task.
|
| CVE-2014-3549 |
Cross-site scripting (XSS) vulnerability in the get_description
function in lib/classes/event/user_login_failed.php in Moodle 2.7.x
before 2.7.1 allows remote attackers to inject arbitrary web script or
HTML via a crafted username that is improperly handled during the
logging of an invalid login attempt.
|
| CVE-2014-3548 |
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through
2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4,
and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web
script or HTML via vectors that trigger an AJAX exception dialog.
|
| CVE-2014-3547 |
Multiple cross-site scripting (XSS) vulnerabilities in
badges/renderer.php in Moodle 2.5.x before 2.5.7, 2.6.x before 2.6.4,
and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web
script or HTML via an external badge.
|
| CVE-2014-3544 |
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle
through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before
2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to
inject arbitrary web script or HTML via the Skype ID profile field.
|
| CVE-2014-3531 |
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before
1.5.2 allow remote authenticated users to inject arbitrary web script
or HTML via the operating system (1) name or (2) description.
|
| CVE-2014-3497 |
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0
through 1.13.1 allows remote attackers to inject arbitrary web script
or HTML via the WWW-Authenticate header.
|
| CVE-2014-3492 |
Multiple cross-site scripting (XSS) vulnerabilities in the host YAML
view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote
attackers to inject arbitrary web script or HTML via a parameter (1)
name or (2) value related to the host.
|
| CVE-2014-3491 |
Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and
1.5.x before 1.5.1 allows remote attackers to inject arbitrary web
script or HTML via the Name field to the New Host groups page, related
to create, update, and destroy notification boxes.
|
| CVE-2014-3475 |
Cross-site scripting (XSS) vulnerability in the Users panel
(admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4,
2014.1 before 2014.1.2, and Juno before Juno-2 allows remote
administrators to inject arbitrary web script or HTML via a user email
address, a different vulnerability than CVE-2014-8578.
|
| CVE-2014-3474 |
Cross-site scripting (XSS) vulnerability in
horizon/static/horizon/js/horizon.instances.js in the Launch Instance
menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before
2014.1.2, and Juno before Juno-2 allows remote authenticated users to
inject arbitrary web script or HTML via a network name.
|
| CVE-2014-3473 |
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack
section in the Horizon Orchestration dashboard in OpenStack Dashboard
(Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before
Juno-2, when used with Heat, allows remote Orchestration template
owners or catalogs to inject arbitrary web script or HTML via a
crafted template.
|
| CVE-2014-3456 |
Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition
(EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-3439 |
ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1
before RU5 allows remote attackers to write to arbitrary files via
unspecified vectors.
|
| CVE-2014-3438 |
Multiple cross-site scripting (XSS) vulnerabilities in console
interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1
before RU5 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-3437 |
The management console in Symantec Endpoint Protection Manager (SEPM)
12.1 before RU5 allows remote attackers to read arbitrary files or
send TCP requests to intranet servers via XML data containing an
external entity declaration in conjunction with an entity reference,
related to an XML External Entity (XXE) issue.
|
| CVE-2014-3433 |
Cross-site scripting (XSS) vulnerability in the management console in
Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers
to inject arbitrary web script or HTML via an unspecified form field,
related to an "HTML script injection" issue.
|
| CVE-2014-3432 |
Cross-site scripting (XSS) vulnerability in the management console in
Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers
to inject arbitrary web script or HTML via an unspecified form field.
|
| CVE-2014-3428 |
Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with
firmware 28.72.0.2 allows remote attackers to inject arbitrary web
script or HTML via the model parameter to servlet.
|
| CVE-2014-3427 |
CRLF injection vulnerability in Yealink VoIP Phones with firmware
28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and
conduct HTTP response splitting attacks via the model parameter to
servlet.
|
| CVE-2014-3408 |
Cross-site scripting (XSS) vulnerability in the web framework in Cisco
Prime Optical 10 allows remote attackers to inject arbitrary web
script or HTML via an unspecified parameter, aka Bug ID CSCuq80763.
|
| CVE-2014-3393 |
The Clientless SSL VPN portal customization framework in Cisco ASA
Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before
8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before
9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement
authentication, which allows remote attackers to modify RAMFS
customization objects via unspecified vectors, as demonstrated by
inserting XSS sequences or capturing credentials, aka Bug ID
CSCup36829.
|
| CVE-2014-3375 |
Multiple cross-site scripting (XSS) vulnerabilities in the CCM Service
interface in the Server in Cisco Unified Communications Manager allow
remote attackers to inject arbitrary web script or HTML via
unspecified parameters, aka Bug ID CSCuq90597.
|
| CVE-2014-3374 |
Multiple cross-site scripting (XSS) vulnerabilities in the CCM admin
interface in the Server in Cisco Unified Communications Manager allow
remote attackers to inject arbitrary web script or HTML via
unspecified parameters, aka Bug ID CSCuq90582.
|
| CVE-2014-3373 |
Multiple cross-site scripting (XSS) vulnerabilities in the CCM Dialed
Number Analyzer interface in the Server in Cisco Unified
Communications Manager allow remote attackers to inject arbitrary web
script or HTML via unspecified parameters, aka Bug ID CSCup92550.
|
| CVE-2014-3372 |
Multiple cross-site scripting (XSS) vulnerabilities in the CCM reports
interface in the Server in Cisco Unified Communications Manager allow
remote attackers to inject arbitrary web script or HTML via
unspecified parameters, aka Bug ID CSCuq90589.
|
| CVE-2014-3367 |
Cross-site scripting (XSS) vulnerability in the vCloud Director
component in Cisco Nexus 1000V InterCloud for VMware allows remote
attackers to inject arbitrary web script or HTML via an unspecified
value, aka Bug ID CSCuq90524.
|
| CVE-2014-3365 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime
Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers
to inject arbitrary web script or HTML via crafted input to the (1)
Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.
|
| CVE-2014-3364 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and
earlier allow remote attackers to inject arbitrary web script or HTML
via a (1) Access Policies or (2) Device Summary Dashboard parameter,
aka Bug ID CSCuq80661.
|
| CVE-2014-3363 |
Cross-site scripting (XSS) vulnerability in the web framework in Cisco
Unified Communications Manager (UCM) 9.1(2.10000.28) allows remote
authenticated users to inject arbitrary web script or HTML via an
unspecified parameter, aka Bug ID CSCuq68443.
|
| CVE-2014-3344 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH
or Transport Gateway Installation Software) 4.0 allow remote attackers
to inject arbitrary web script or HTML via unspecified parameters, aka
Bug IDs CSCuq31129, CSCuq31134, CSCuq31137, and CSCuq31563.
|
| CVE-2014-3329 |
Cross-site scripting (XSS) vulnerability in the web-server component
in Cisco Prime Data Center Network Manager (DCNM) 6.3(2) and earlier
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL, aka Bug ID CSCum86620.
|
| CVE-2014-3325 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified
Customer Voice Portal (CVP) allow remote attackers to inject arbitrary
web script or HTML via a crafted parameter, aka Bug IDs CSCuh61711,
CSCuh61720, CSCuh61723, CSCuh61726, CSCuh61727, CSCuh61731, and
CSCuh61733.
|
| CVE-2014-3324 |
Multiple cross-site scripting (XSS) vulnerabilities in the login page
in the administrative web interface in Cisco TelePresence Server
Software 4.0(2.8) allow remote attackers to inject arbitrary web
script or HTML via a crafted parameter, aka Bug ID CSCup90060.
|
| CVE-2014-3315 |
Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the
Dialed Number Analyzer (DNA) component in Cisco Unified Communications
Manager allows remote attackers to inject arbitrary web script or HTML
via an unspecified parameter, aka Bug ID CSCup76308.
|
| CVE-2014-3313 |
Cross-site scripting (XSS) vulnerability in the web user interface on
Cisco Small Business SPA300 and SPA500 phones allows remote attackers
to inject arbitrary web script or HTML via a crafted URL, aka Bug ID
CSCuo52582.
|
| CVE-2014-3289 |
Cross-site scripting (XSS) vulnerability in the web management
interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0,
Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and
Content Security Management Appliance (SMA) 8.3 and earlier allows
remote attackers to inject arbitrary web script or HTML via a crafted
parameter, as demonstrated by the date_range parameter to
monitor/reports/overview on the IronPort ESA, aka Bug IDs CSCun07998,
CSCun07844, and CSCun07888.
|
| CVE-2014-3266 |
Cross-site scripting (XSS) vulnerability in the web framework in Cisco
Security Manager 4.6 and earlier allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug ID
CSCun65189.
|
| CVE-2014-3265 |
Cross-site scripting (XSS) vulnerability in the Auto Update Server
(AUS) web framework in Cisco Security Manager 4.2 and earlier allows
remote attackers to inject arbitrary web script or HTML via an
unspecified parameter, aka Bug ID CSCuo06900.
|
| CVE-2014-3247 |
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows
remote authenticated users to inject arbitrary web script or HTML via
the desc parameter in an Add project (addpro) action to admin.php.
|
| CVE-2014-3207 |
Cross-site scripting (XSS) vulnerability in wserver.ml in SKS
Keyserver before 1.1.5 allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO to pks/lookup/undefined1.
|
| CVE-2014-3197 |
The NavigationScheduler::schedulePageBlock function in
core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome
before 38.0.2125.101, does not properly provide substitute data for
pages blocked by the XSS auditor, which allows remote attackers to
obtain sensitive information via a crafted web site.
|
| CVE-2014-3149 |
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board
(aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded
before 20140424, or IP.Nexus 1.5.x through 1.5.9, as downloaded before
20140424, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-3148 |
Cross-site scripting (XSS) vulnerability in libahttp/err.c in OkCupid
OKWS (OK Web Server) allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO to a non-existent page, which is not
properly handled in a 404 error page.
|
| CVE-2014-3147 |
Cross-site scripting (XSS) vulnerability in the auto-complete feature
in Splunk Enterprise before 6.0.4 allows remote authenticated users to
inject arbitrary web script or HTML via a CSV file.
|
| CVE-2014-3146 |
Incomplete blacklist vulnerability in the lxml.html.clean module in
lxml before 3.3.5 allows remote attackers to conduct cross-site
scripting (XSS) attacks via control characters in the link scheme to
the clean_html function.
|
| CVE-2014-3135 |
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 5.1.1
Alpha 9 allow remote attackers to inject arbitrary web script or HTML
via (1) the PATH_INFO to privatemessage/new/, (2) the folderid
parameter to a private message in privatemessage/view, (3) a fragment
indicator to /help, or (4) the view parameter to a topic, as
demonstrated by a request to
forum/anunturi-importante/rst-power/67030-rst-admin-restore.
|
| CVE-2014-3134 |
Cross-site scripting (XSS) vulnerability in the InfoView application
in SAP BusinessObjects allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-3123 |
Cross-site scripting (XSS) vulnerability in admin/manage-images.php in
the NextCellent Gallery plugin before 1.19.18 for WordPress allows
remote authenticated users with the NextGEN Upload images, NextGEN
Manage gallery, or NextGEN Manage others gallery permission to inject
arbitrary web script or HTML via the "Alt & Title Text" field.
|
| CVE-2014-3111 |
Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27
through 0.32 allow remote authenticated users to inject arbitrary web
script or HTML via the (1) Printer Model field to the Printer
Management page, (2) Image Name field to the Image Management page,
(3) Storage Group Name field to the Storage Management page, (4)
Username field to the User Cleanup FOG Configuration page, or (5)
Directory Path field to the Directory Cleaner FOG Configuration page.
|
| CVE-2014-3110 |
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell
FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON
XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote
attackers to inject arbitrary web script or HTML via invalid input.
|
| CVE-2014-3102 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0
through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-3096 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program
Management before 6.0.5.5a allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-3091 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM
7.1.x and 7.2.x allows remote attackers to inject arbitrary web script
or HTML via a crafted URL.
|
| CVE-2014-3080 |
Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and
GCM32 Global Console Manager switches with firmware before
1.20.20.23447 allow remote attackers to inject arbitrary web script or
HTML via (1) the query string to kvm.cgi or (2) the key parameter to
avctalert.php.
|
| CVE-2014-3075 |
Cross-site scripting (XSS) vulnerability in IBM Business Process
Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition
7.2.0.x allows remote authenticated users to inject arbitrary web
script or HTML via an uploaded file.
|
| CVE-2014-3071 |
Cross-site scripting (XSS) vulnerability in the Data Quality Console
in IBM InfoSphere Information Server 11.3 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL for adding a
project connection.
|
| CVE-2014-3061 |
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend
Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x
before 10.0.2.4 allows remote attackers to hijack the authentication
of arbitrary users for requests that insert XSS sequences.
|
| CVE-2014-3058 |
Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere
DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote
authenticated users to hijack the authentication of arbitrary users
for requests that insert XSS sequences.
|
| CVE-2014-3057 |
Cross-site scripting (XSS) vulnerability in the Unified Task List
(UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1
CF12 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL.
|
| CVE-2014-3040 |
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris
Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before
10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before
10.0.2.2 iFix 2; Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3,
10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x
before 10.0.2.4; and Emptoris Spend Analysis 9.5.x before 9.5.0.4,
10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote
authenticated users to hijack the authentication of arbitrary users
for requests that insert XSS sequences.
|
| CVE-2014-3037 |
Cross-site request forgery (CSRF) vulnerability in IBM Configuration
Management Application (aka VVC) in IBM Rational Engineering Lifecycle
Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect
Design Manager before 4.0.7 and 5.x before 5.0.1, and Rational
Rhapsody Design Manager before 4.0.7 and 5.x before 5.0.1 allows
remote authenticated users to hijack the authentication of arbitrary
users for requests that insert XSS sequences.
|
| CVE-2014-3035 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend
Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x
before 10.0.2.4 allows remote authenticated users to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2014-3034 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract
Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix
10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2014-3033 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing
Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x
before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-3032 |
Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli
Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0
before 7.4.0.3 allows remote authenticated users to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2014-3031 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business
Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 before 4.2.1.3 IF9
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2014-3025 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo
Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and
7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and
7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset
Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli
Asset Management for IT and certain other products allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified input to a .jsp file under webclient/utility/.
|
| CVE-2014-3015 |
Cross-site request forgery (CSRF) vulnerability in the Web player in
IBM Sametime Proxy Server and Web Client 9.0 through 9.0.0.1 allows
remote attackers to hijack the authentication of arbitrary users for
requests that insert XSS sequences.
|
| CVE-2014-3014 |
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM
Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-3013 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Curam
Social Program Management 4.5 SP10 through 6.0.5.4 allow remote
authenticated users to inject arbitrary web script or HTML via crafted
input to a (1) custom JSP or (2) custom renderer.
|
| CVE-2014-3010 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM
WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 before
6.3.0.6, 7.0 before 7.0.0.6, 7.5 before 7.5.0.5, and 8.0 before
8.0.0.3 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL.
|
| CVE-2014-2995 |
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in
the Twitget plugin before 3.3.3 for WordPress allow remote
authenticated administrators to inject arbitrary web script or HTML
via unspecified vectors, as demonstrated by the twitget_consumer_key
parameter to wp-admin/options-general.php.
|
| CVE-2014-2975 |
Cross-site scripting (XSS) vulnerability in php/user_account.php in
Silver Peak VX before 6.2.4 allows remote attackers to inject
arbitrary web script or HTML via the user_id parameter.
|
| CVE-2014-2971 |
Cross-site scripting (XSS) vulnerability in AddStdLetter.jsp in
MicroPact iComplaints before 8.0.2.1.8.8014 allows remote
authenticated users to inject arbitrary web script or HTML via the
description parameter.
|
| CVE-2014-2968 |
Cross-site scripting (XSS) vulnerability in the web interface on the
Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI
11.001.08.00.03 allows remote attackers to inject arbitrary web script
or HTML via an SMS message.
|
| CVE-2014-2966 |
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly
perform Unicode transformations, which allows remote attackers to
bypass intended text restrictions via crafted characters, as
demonstrated by bypassing an XSS protection mechanism.
|
| CVE-2014-2965 |
Cross-site scripting (XSS) vulnerability in auth-settings-x.php in
SpamTitan before 6.04 allows remote attackers to inject arbitrary web
script or HTML via the sortdir parameter.
|
| CVE-2014-2963 |
Multiple cross-site scripting (XSS) vulnerabilities in
group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE,
and 6.2.X EE allow remote attackers to inject arbitrary web script or
HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_middleName
parameter.
|
| CVE-2014-2947 |
Cross-site scripting (XSS) vulnerability in Login.aspx in Bizagi BPM
Suite before 10.3 allows remote attackers to inject arbitrary web
script or HTML via the txtUsername parameter.
|
| CVE-2014-2939 |
Multiple cross-site scripting (XSS) vulnerabilities in Alfresco
Enterprise before 4.1.6.13 allow remote attackers to inject arbitrary
web script or HTML via (1) an XHTML document, (2) a <% tag, or (3) the
taskId parameter to share/page/task-edit.
|
| CVE-2014-2925 |
Cross-site scripting (XSS) vulnerability in
Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series
routers with firmware before 3.0.0.4.374.5047 allows remote attackers
to inject arbitrary web script or HTML via the current_page parameter
to apply.cgi.
|
| CVE-2014-2908 |
Cross-site scripting (XSS) vulnerability in the integrated web server
on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-2890 |
Cross-site scripting (XSS) vulnerability in the wrap_html function in
MyID.php in phpMyID 0.9 allows remote attackers to inject arbitrary
web script or HTML via the openid_error parameter to MyID.config.php
when the openid.mode parameter is set to error, which is not properly
handled in an error message.
|
| CVE-2014-2879 |
Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL
Email Security 7.4.5 and earlier allow remote authenticated
administrators to inject arbitrary web script or HTML via (1) the
uploadPatch parameter to the System/Advanced page
(settings_advanced.html) or (2) the uploadLicenses parameter in the
License management (settings_upload_dlicense.html) page.
|
| CVE-2014-2861 |
Incomplete blacklist vulnerability in PaperThin CommonSpot before
7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct
cross-site scripting (XSS) attacks via a crafted string, as
demonstrated by bypassing a protection mechanism that removes only the
"alert" string.
|
| CVE-2014-2860 |
Multiple cross-site scripting (XSS) vulnerabilities in PaperThin
CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to
inject arbitrary web script or HTML via a crafted HTTP request to a
(1) ColdFusion or (2) JavaScript component.
|
| CVE-2014-2856 |
Cross-site scripting (XSS) vulnerability in scheduler/client.c in
Common Unix Printing System (CUPS) before 1.7.2 allows remote
attackers to inject arbitrary web script or HTML via the URL path,
related to the is_path_absolute function.
|
| CVE-2014-2854 |
Cross-site scripting (XSS) vulnerability in the SemanticTitle
extension before 1.1.0 for MediaWiki allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-2853 |
Cross-site scripting (XSS) vulnerability in
includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x
before 1.22.6 allows remote attackers to inject arbitrary web script
or HTML via the sort key in an info action.
|
| CVE-2014-2844 |
Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure
Gateway 7.5.0 before Patch 1862 allows remote authenticated
administrators to inject arbitrary web script or HTML via the new
parameter in the SysUser module to admin.
|
| CVE-2014-2839 |
SQL injection vulnerability in the GD Star Rating plugin 19.22 for
WordPress allows remote administrators to execute arbitrary SQL
commands via the s parameter in the gd-star-rating-stats page to
wp-admin/admin.php.
|
| CVE-2014-2838 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the GD
Star Rating plugin 19.22 for WordPress allow remote attackers to
hijack the authentication of administrators for requests that conduct
(1) SQL injection attacks via the s parameter in the
gd-star-rating-stats page to wp-admin/admin.php or (2) cross-site
scripting (XSS) attacks via unspecified vectors.
|
| CVE-2014-2729 |
Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS
8.7 before 8.7.0.055 allows remote authenticated users to inject
arbitrary web script or HTML via the category0 parameter, which is not
properly handled when displaying the Subjects tab in the View
Properties menu option.
|
| CVE-2014-2715 |
Multiple cross-site scripting (XSS) vulnerabilities in
vwrooms\templates\logout.tpl.php in the VideoWhisper Webcam plugins
for Drupal 7.x allow remote attackers to inject arbitrary web script
or HTML via the (1) module or (2) message parameter to index.php.
|
| CVE-2014-2712 |
Cross-site scripting (XSS) vulnerability in J-Web in Juniper Junos
before 10.0S25, 10.4 before 10.4R10, 11.4 before 11.4R11, 12.1 before
12.1R9, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20,
12.1X46 before 12.1X46-D10, and 12.2 before 12.2R1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
parameters to index.php.
|
| CVE-2014-2711 |
Cross-site scripting (XSS) vulnerability in J-Web in Juniper Junos
before 11.4R11, 11.4X27 before 11.4X27.62 (BBE), 12.1 before 12.1R9,
12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before
12.1X46-D20, 12.2 before 12.2R7, 12.3 before 12.3R6, 13.1 before
13.1R4, 13.2 before 13.2R3, and 13.3 before 13.3R1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-2710 |
Multiple cross-site scripting (XSS) vulnerabilities in Oliver
(formerly Webshare) 1.3.1 and earlier allow remote attackers to inject
arbitrary web script or HTML via the PATH_INFO to the (1) login page
(index.php) or (2) login form (loginform-inc.php).
|
| CVE-2014-2689 |
Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to installer/index.php.
|
| CVE-2014-2670 |
Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO
ManageEngine OpStor before build 8500 allows remote authenticated
users to inject arbitrary web script or HTML via the name parameter, a
different vulnerability than CVE-2014-0344.
|
| CVE-2014-2647 |
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP
Operations Manager (formerly OpenView Communications Broker) before
11.14 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-2644 |
Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager
(SIM) before 7.4 allows remote attackers to inject arbitrary web
script or HTML via unknown vectors.
|
| CVE-2014-2640 |
Cross-site scripting (XSS) vulnerability in HP System Management
Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-2598 |
Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post
Redirect plugin before 5.0.5 for WordPress allows remote attackers to
hijack the authentication of administrators for requests that conduct
cross-site scripting (XSS) attacks via the
quickppr_redirects[request][] parameter in the redirect-updates page
to wp-admin/admin.php.
|
| CVE-2014-2589 |
Cross-site scripting (XSS) vulnerability in the Dashboard Backend
service (stats/dashboard.jsp) in SonicWall Network Security Appliance
(NSA) 2400 allows remote attackers to inject arbitrary web script or
HTML via the sn parameter.
|
| CVE-2014-2586 |
Cross-site scripting (XSS) vulnerability in the login audit form in
McAfee Cloud Single Sign On (SSO) allows remote attackers to inject
arbitrary web script or HTML via a crafted password.
|
| CVE-2014-2578 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk
before 5.0.8 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-2577 |
Multiple cross-site scripting (XSS) vulnerabilities in the Transform
Content Center in Bottomline Technologies Transform Foundation Server
before 4.3.1 Patch 8 and 5.x before 5.2 Patch 7 allow remote attackers
to inject arbitrary web script or HTML via the (1) pn parameter to
index.fsp/document.pdf, (2) db or (3) referer parameter to
index.fsp/index.fsp, or (4) PATH_INFO to the default URI.
|
| CVE-2014-2571 |
Cross-site scripting (XSS) vulnerability in the quiz_question_tostring
function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x
before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote
authenticated users to inject arbitrary web script or HTML via a quiz
question.
|
| CVE-2014-2570 |
Cross-site scripting (XSS) vulnerability in www/make_subset.php in PHP
Font Lib before 0.3.1 allows remote attackers to inject arbitrary web
script or HTML via the name parameter.
|
| CVE-2014-2559 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
twitget.php in the Twitget plugin before 3.3.3 for WordPress allow
remote attackers to hijack the authentication of administrators for
requests that change unspecified plugin options via a request to
wp-admin/options-general.php.
|
| CVE-2014-2553 |
Cross-site scripting (XSS) vulnerability in Open Ticket Request System
(OTRS) 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before
3.3.6 allows remote authenticated users to inject arbitrary web script
or HTML via vectors related to dynamic fields.
|
| CVE-2014-2542 |
Cross-site scripting (XSS) vulnerability in the Rendezvous Daemon
(rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon
(rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO
Rendezvous before 8.4.2, Messaging Appliance before 8.7.1, and
Substation ES before 2.8.1 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-2538 |
Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the
rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject
arbitrary web script or HTML via a URI, which might not be properly
handled by third-party adapters such as JRuby-Rack.
|
| CVE-2014-2526 |
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive
before 6.7 allow remote attackers to inject arbitrary web script or
HTML via the (1) sForumName or (2) sDescription parameter to
Forum/manage/ForumManager.lsp; (3) sHint, (4) sWord, or (5) nId
parameter to Forum/manage/hangman.lsp; (6) user parameter to
rtl/protected/admin/wizard/setuser.lsp; (7) name or (8) email
parameter to feedback.lsp; (9) lname or (10) url parameter to
private/manage/PageManager.lsp; (11) cmd parameter to fs; (12)
newname, (13) description, (14) firstname, (15) lastname, or (16) id
parameter to rtl/protected/mail/manage/list.lsp; or (17) PATH_INFO to
fs/.
|
| CVE-2014-2512 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum
eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-2511 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum
WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote
attackers to inject arbitrary web script or HTML via the (1) startat
or (2) entryId parameter.
|
| CVE-2014-2502 |
Cross-site scripting (XSS) vulnerability in rsa_fso.swf in EMC RSA
Adaptive Authentication (Hosted) 11.0 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-2393 |
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite
7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote
attackers to inject arbitrary web script or HTML via a Drive filename
that is not properly handled during use of the composer to add an
e-mail attachment.
|
| CVE-2014-2385 |
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in
Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject
arbitrary web script or HTML via the (1)
newListList:ExcludeFileOnExpression, (2)
newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths
parameter to exclusion/configure or (4) text:EmailServer or (5)
newListList:Email parameter to notification/configure.
|
| CVE-2014-2370 |
Cross-site scripting (XSS) vulnerability in the web application on
Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x
allows remote authenticated users to inject arbitrary web script or
HTML via crafted data.
|
| CVE-2014-2353 |
Cross-site scripting (XSS) vulnerability in Cogent DataHub before
7.3.5 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-2336 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web User
Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer
before 5.0.7 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors, a different vulnerability than
CVE-2014-2334 and CVE-2014-2335.
|
| CVE-2014-2335 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web User
Interface in Fortinet FortiManager before 5.0.7 allow remote attackers
to inject arbitrary web script or HTML via unspecified vectors, a
different vulnerability than CVE-2014-2336.
|
| CVE-2014-2334 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web User
Interface in Fortinet FortiAnalyzer before 5.0.7 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, a different vulnerability than CVE-2014-2336.
|
| CVE-2014-2333 |
Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin
before 1.1.21 for WordPress allows remote attackers to inject
arbitrary web script or HTML via an EXIF tag. NOTE: some of these
details are obtained from third party information.
|
| CVE-2014-2329 |
Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before
1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to
inject arbitrary web script or HTML via the (1) agent string for a
check_mk agent, a (2) crafted request to a monitored host, which is
not properly handled by the logwatch module, or other unspecified
vectors.
|
| CVE-2014-2326 |
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g,
0.8.8b, and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-2325 |
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail
Gateway before 3.1-5829 allow remote attackers to inject arbitrary web
script or HTML via the (1) state parameter to objects/who/index.htm or
(2) User email address to quarantine/spam/manage.htm.
|
| CVE-2014-2315 |
Multiple cross-site scripting (XSS) vulnerabilities in the Thank You
Counter Button plugin 1.8.7 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) thanks_caption, (2)
thanks_caption_style, or (3) thanks_style parameter to
wp-admin/options.php.
|
| CVE-2014-2291 |
Cross-site scripting (XSS) vulnerability in the Pulse Collaboration
(Secure Meeting) user pages in Juniper Junos Pulse Secure Access
Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10,
7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-2280 |
Cross-site scripting (XSS) vulnerability in the search feature in
SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote
attackers to inject arbitrary web script or HTML via the query
parameter.
|
| CVE-2014-2260 |
Cross-site scripting (XSS) vulnerability in
plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13
allows remote authenticated users to inject arbitrary web script or
HTML via the command field in the Cron functionality.
|
| CVE-2014-2246 |
Cross-site scripting (XSS) vulnerability in the integrated web server
on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-2244 |
Cross-site scripting (XSS) vulnerability in the formatHTML function in
includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and
1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers
to inject arbitrary web script or HTML via a crafted string located
after http:// in the text parameter to api.php.
|
| CVE-2014-2242 |
includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and
1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of
invalid namespaces in SVG files, which allows remote attackers to
conduct cross-site scripting (XSS) attacks via an SVG upload, as
demonstrated by use of a W3C XHTML namespace in conjunction with an
IFRAME element.
|
| CVE-2014-2236 |
Multiple cross-site scripting (XSS) vulnerabilities in Askbot before
0.7.49 allow remote attackers to inject arbitrary web script or HTML
via vectors related to the (1) tag or (2) user search forms.
|
| CVE-2014-2235 |
Cross-site scripting (XSS) vulnerability in Askbot before 0.7.49
allows remote attackers to inject arbitrary web script or HTML via
vectors related to the question search form.
|
| CVE-2014-2231 |
Cross-site scripting (XSS) vulnerability in the API in synetics i-doit
pro before 1.2.5 allows remote attackers to inject arbitrary web
script or HTML via a property title.
|
| CVE-2014-2219 |
Cross-site scripting (XSS) vulnerability in whizzywig/wb.php in
CMSimple Classic 3.54 and earlier, possibly as downloaded before
February 26, 2014, allows remote attackers to inject arbitrary web
script or HTML via the d parameter.
|
| CVE-2014-2212 |
The remember me feature in portal/scr_authentif.php in POSH (aka Posh
portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username
and MD5 digest of the password in cleartext in a cookie, which allows
attackers to obtain sensitive information by reading this cookie.
|
| CVE-2014-2192 |
Cross-site scripting (XSS) vulnerability in Cisco Unified Web and
E-mail Interaction Manager 9.0(2) allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug ID
CSCuj43033.
|
| CVE-2014-2191 |
Cross-site scripting (XSS) vulnerability in the web framework in Cisco
Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows
remote attackers to inject arbitrary web script or HTML via an
unspecified parameter, aka Bug ID CSCun91113.
|
| CVE-2014-2153 |
Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in
Cisco Prime Infrastructure allow remote attackers to inject arbitrary
web script or HTML via unspecified parameters, aka Bug ID CSCun21869.
|
| CVE-2014-2125 |
Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco
Unity Connection 8.6(2a)SU3 and earlier allows remote attackers to
inject arbitrary web script or HTML via an unspecified parameter, aka
Bug ID CSCui33028.
|
| CVE-2014-2120 |
Cross-site scripting (XSS) vulnerability in the WebVPN login page in
Cisco Adaptive Security Appliance (ASA) Software allows remote
attackers to inject arbitrary web script or HTML via an unspecified
parameter, aka Bug ID CSCun19025.
|
| CVE-2014-2118 |
Multiple cross-site scripting (XSS) vulnerabilities in
dashboard-related HTML documents in Cisco Prime Security Manager (aka
PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary
web script or HTML via unspecified parameters, aka Bug ID CSCun50687.
|
| CVE-2014-2114 |
Cross-site scripting (XSS) vulnerability in UserServlet in Cisco
Emergency Responder (ER) 8.6 and earlier allows remote attackers to
inject arbitrary web script or HTML via an unspecified parameter, aka
Bug ID CSCun24384.
|
| CVE-2014-2104 |
Multiple cross-site scripting (XSS) vulnerabilities in the Business
Voice Services Manager (BVSM) page in Cisco Unified Communications
Domain Manager 9.0(.1) allow remote attackers to inject arbitrary web
script or HTML via unspecified parameters, aka Bug IDs CSCum78536,
CSCum78526, CSCum69809, and CSCum63113.
|
| CVE-2014-2092 |
Cross-site scripting (XSS) vulnerability in
lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple
1.11.10 allows remote attackers to inject arbitrary web script or HTML
via the action parameter, a different issue than CVE-2014-0334. NOTE:
the original disclosure also reported issues that may not cross
privilege boundaries.
|
| CVE-2014-2091 |
Cross-site scripting (XSS) vulnerability in
mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows
remote authenticated administrators to inject arbitrary web script or
HTML via the title parameter in an add_forum action. NOTE: the
original disclosure also reported issues that may not cross privilege
boundaries.
|
| CVE-2014-2090 |
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in
ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web
script or HTML via the (1) tar, (2) tar_val, or (3) title parameter.
|
| CVE-2014-2080 |
Cross-site scripting (XSS) vulnerability in
manager/templates/default/header.tpl in ModX Revolution before 2.2.11
allows remote attackers to inject arbitrary web script or HTML via the
"a" parameter.
|
| CVE-2014-2077 |
Cross-site scripting (XSS) vulnerability in the frontend in
Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before
7.4.2-rev8 allows remote attackers to inject arbitrary web script or
HTML via the subject of an email, involving 'the aria "tags" for
screenreaders at the top bar'.
|
| CVE-2014-2067 |
Cross-site scripting (XSS) vulnerability in
java/hudson/model/Cause.java in Jenkins before 1.551 and LTS before
1.532.2 allows remote authenticated users to inject arbitrary web
script or HTML via a "remote cause note."
|
| CVE-2014-2065 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and
LTS before 1.532.2 allows remote attackers to inject arbitrary web
script or HTML via the iconSize cookie.
|
| CVE-2014-2057 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
6.0.2 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-2045 |
Multiple cross-site scripting (XSS) vulnerabilities in the old and new
interfaces in Viprinet Multichannel VPN Router 300 allow remote
attackers to inject arbitrary web script or HTML via the username when
(1) logging in or (2) creating an account in the old interface, (3)
username when creating an account in the new interface, (4) hostname
in the old interface, (5) inspect parameter in the config module, (6)
commands parameter in the atcommands tool, or (7) host parameter in
the ping tool.
|
| CVE-2014-2040 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1)
callback_multicheck, (2) callback_radio, and (3) callback_wysiwygin
functions in mfrh_class.settings-api.php in the Media File Renamer
plugin 1.7.0 for WordPress allow remote authenticated users with
permissions to add media or edit media to inject arbitrary web script
or HTML via unspecified parameters, as demonstrated by the title of an
uploaded file.
|
| CVE-2014-2035 |
Cross-site scripting (XSS) vulnerability in xhr.php in InterWorx Web
Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP)
before 5.0.13 build 574 allows remote attackers to inject arbitrary
web script or HTML via the i parameter.
|
| CVE-2014-2026 |
Cross-site scripting (XSS) vulnerability in the search functionality
in United Planet Intrexx Professional before 5.2 Online Update 0905
and 6.x before 6.0 Online Update 10 allows remote attackers to inject
arbitrary web script or HTML via the request parameter.
|
| CVE-2014-2024 |
Cross-site scripting (XSS) vulnerability in
classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows
remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to shared-apartments-rooms/.
|
| CVE-2014-2021 |
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in
vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted XMLRPC API request, as demonstrated using the client name.
|
| CVE-2014-2018 |
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x
through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey
before 2.20 allows user-assisted remote attackers to inject arbitrary
web script or HTML via an e-mail message containing a data: URL in a
(1) OBJECT or (2) EMBED element, a related issue to CVE-2013-6674.
|
| CVE-2014-2016 |
Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop
Professional and Community Edition 4.6.8 and earlier, 4.7.x before
4.7.11, and 4.8.x before 4.8.4, and Enterprise Edition 4.6.8 and
earlier, 5.0.x before 5.0.11 and 5.1.x before 5.1.4 allow remote
attackers to inject arbitrary web script or HTML via the searchtag
parameter to the getTag function in (1)
application/controllers/details.php or (2)
application/controllers/tag.php.
|
| CVE-2014-2006 |
Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x
before 3.0.030 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2014-2002 |
Cross-site scripting (XSS) vulnerability in C-BOARD Moyuku 1.01b6 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-1998 |
Cross-site scripting (XSS) vulnerability in Nippon Institute of
Agroinformatics SOY CMS 1.4.0c and earlier allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-1995 |
Cross-site scripting (XSS) vulnerability in the Map search
functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-1994 |
Cross-site scripting (XSS) vulnerability in the Notices portlet in
Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-1992 |
Cross-site scripting (XSS) vulnerability in the Messages functionality
in Cybozu Garoon 3.1.x, 3.5.x, and 3.7.x before 3.7 SP4 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-1980 |
Cross-site scripting (XSS) vulnerability in
include/functions_metadata.inc.php in Piwigo before 2.4.6 allows
remote attackers to inject arbitrary web script or HTML via the Make
field in IPTC Exif metadata within an image uploaded to the Community
plugin.
|
| CVE-2014-1971 |
Cross-site scripting (XSS) vulnerability in Silex before 2.0.0 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-1968 |
Cross-site scripting (XSS) vulnerability in the XooNIps module 3.47
and earlier for XOOPS allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-1965 |
Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the
Integration Repository in the SAP Exchange Infrastructure (BC-XI)
component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP
NetWeaver allows remote attackers to inject arbitrary web script or
HTML via vectors related to PIP.
|
| CVE-2014-1964 |
Cross-site scripting (XSS) vulnerability in the Integration Repository
in the SAP Exchange Infrastructure (BC-XI) component in SAP NetWeaver
allows remote attackers to inject arbitrary web script or HTML via
vectors related to the ESR application and a DIR error.
|
| CVE-2014-1955 |
Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before
5.0.3 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-1944 |
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
text parameter to index.php/guestbook/index/newentry.
|
| CVE-2014-1942 |
Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx
in Pearson eSIS Enterprise Student Information System allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-1914 |
Multiple cross-site scripting (XSS) vulnerabilities in Command School
Student Management System 1.06.01 allow remote attackers to inject
arbitrary web script or HTML via the (1) topic parameter to
sw/add_topic.php or (2) nick parameter to sw/chat/message.php.
|
| CVE-2014-1906 |
Multiple cross-site scripting (XSS) vulnerabilities in the
VideoWhisper Live Streaming Integration plugin before 4.29.5 for
WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) m parameter to lb_status.php; (2) msg parameter to
vc_chatlog.php; n parameter to (3) channel.php, (4) htmlchat.php, (5)
video.php, or (6) videotext.php; (7) message parameter to
lb_logout.php; or ct parameter to (8) lb_status.php or (9)
v_status.php in ls/.
|
| CVE-2014-1904 |
Cross-site scripting (XSS) vulnerability in
web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework
3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to
inject arbitrary web script or HTML via the requested URI in a default
action.
|
| CVE-2014-1902 |
Multiple cross-site scripting (XSS) vulnerabilities in Y-Cam camera
models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004,
YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720
YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam
Original Range YCB001, YCW001, running firmware 4.30 and earlier,
allow remote authenticated users to inject arbitrary web script or
HTML via the (1) SYSCONTACT parameter to form/identityApply, as
triggered using en/identity.asp; (2) PASSWD parameter to form/accAdd,
as triggered using en/account/accedit.asp; (3) NTPSERVER parameter to
form/clockApply, as triggered using en/clock.asp; (4) SERVER parameter
to form/smtpclientApply, as triggered using en/smtpclient.asp; (5)
SERVER parameter to form/ftpApply, as triggered using en/ftp.asp; or
(6) SERVER parameter to form/httpEventApply, as triggered using
en/httpevent.asp.
|
| CVE-2014-1899 |
Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway
(formerly Citrix Access Gateway Enterprise Edition) 9.x before
9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-1888 |
Cross-site scripting (XSS) vulnerability in the BuddyPress plugin
before 1.9.2 for WordPress allows remote authenticated users to inject
arbitrary web script or HTML via the name field to
groups/create/step/group-details. NOTE: this can be exploited without
authentication by leveraging CVE-2014-1889.
|
| CVE-2014-1879 |
Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin
before 4.1.7 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted filename in an import action.
|
| CVE-2014-1877 |
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 2.1.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) Phone, (2) Street, (3) Address line, (4) Zip code, or (5) City
field to main/auth/profile.php; (6) Subject field to
main/social/groups.php; or (7) Message body field to
main/messages/view_message.php.
|
| CVE-2014-1869 |
Multiple cross-site scripting (XSS) vulnerabilities in
ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon
Rohan and James M. Greene, allow remote attackers to inject arbitrary
web script or HTML via vectors related to certain SWF query parameters
(aka loaderInfo.parameters).
|
| CVE-2014-1855 |
Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel
before 3.5.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) capcheck parameter to directories.php or (2) keyword
parameter to proxy.php.
|
| CVE-2014-1840 |
Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB
1.6.12 and earlier allows remote attackers to inject arbitrary web
script or HTML via the keywords parameter in a do_search action, which
is not properly handled in a forced SQL error message.
|
| CVE-2014-1837 |
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento
(com_komento) component before 1.7.4 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via vectors related
to "checking new comments."
|
| CVE-2014-1836 |
Absolute path traversal vulnerability in
htdocs/libraries/image-editor/image-edit.php in ImpressCMS before
1.3.6 allows remote attackers to delete arbitrary files via a full
pathname in the image_path parameter in a cancel action.
|
| CVE-2014-1826 |
Cross-site scripting (XSS) vulnerability in the iThoughtsHD app 4.19
for iOS on iPad devices, when the WiFi Transfer feature is used,
allows remote attackers to inject arbitrary web script or HTML via a
crafted map name.
|
| CVE-2014-1823 |
Cross-site scripting (XSS) vulnerability in the Web Components Server
in Microsoft Lync Server 2010 and 2013 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL containing a
valid meeting ID, aka "Lync Server Content Sanitization
Vulnerability."
|
| CVE-2014-1820 |
Cross-site scripting (XSS) vulnerability in Master Data Services (MDS)
in Microsoft SQL Server 2012 SP1 and 2014 on 64-bit platforms allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka "SQL Master Data Services XSS Vulnerability."
|
| CVE-2014-1754 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1,
Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013
Client Components SDK allows remote attackers to inject arbitrary web
script or HTML via a crafted request, aka "SharePoint XSS
Vulnerability."
|
| CVE-2014-1750 |
Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps
& Places plugin 1.6.6 for WordPress allows remote attackers to
redirect users to arbitrary web sites and conduct phishing attacks via
a URL in the href parameter to page/place.html. NOTE: this was
originally reported as a cross-site scripting (XSS) vulnerability, but
this may be inaccurate.
|
| CVE-2014-1747 |
Cross-site scripting (XSS) vulnerability in the
DocumentLoader::maybeCreateArchive function in
core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome
before 35.0.1916.114, allows remote attackers to inject arbitrary web
script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."
|
| CVE-2014-1716 |
Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype
function in runtime.cc in Google V8, as used in Google Chrome before
34.0.1847.116, allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
|
| CVE-2014-1701 |
The GenerateFunction function in bindings/scripts/code_generator_v8.pm
in Blink, as used in Google Chrome before 33.0.1750.149, does not
implement a certain cross-origin restriction for the
EventTarget::dispatchEvent function, which allows remote attackers to
conduct Universal XSS (UXSS) attacks via vectors involving events.
|
| CVE-2014-1695 |
Cross-site scripting (XSS) vulnerability in Open Ticket Request System
(OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, and 3.3.x before
3.3.5 allows remote attackers to inject arbitrary web script or HTML
via a crafted HTML email.
|
| CVE-2014-1679 |
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite
before 7.2.2-rev31, 7.4.0 before 7.4.0-rev27, and 7.4.1 before
7.4.1-rev17 allows remote attackers to inject arbitrary web script or
HTML via the header in an attached SVG file.
|
| CVE-2014-1652 |
Multiple cross-site scripting (XSS) vulnerabilities in the management
console in Symantec Web Gateway (SWG) before 5.2 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified report parameters.
|
| CVE-2014-1648 |
Cross-site scripting (XSS) vulnerability in
brightmail/setting/compliance/DlpConnectFlow$view.flo in the
management console in Symantec Messaging Gateway 10.x before 10.5.2
allows remote attackers to inject arbitrary web script or HTML via the
displayTab parameter.
|
| CVE-2014-1620 |
Multiple cross-site scripting (XSS) vulnerabilities in add.php in HIOX
Guest Book (HGB) 5.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) name1, (2) email, or (3) cmt parameter.
|
| CVE-2014-1612 |
Cross-site scripting (XSS) vulnerability in login.esp in the Web
Management Interface in Media5 Mediatrix 4402 VoIP Gateway with
firmware Dgw 1.1.13.186 and earlier allows remote attackers to inject
arbitrary web script or HTML via the username parameter.
|
| CVE-2014-1611 |
Cross-site scripting (XSS) vulnerability in the Anonymous Posting
module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to
inject arbitrary web script or HTML via the contact name field.
|
| CVE-2014-1607 |
** DISPUTED ** Cross-site scripting (XSS) vulnerability in the
EventCalendar module for Drupal 7.14 allows remote attackers to inject
arbitrary web script or HTML via the year parameter to eventcalander/.
NOTE: this issue has been disputed by the Drupal Security Team; it may
be site-specific. If so, then this CVE will be REJECTed in the
future.
|
| CVE-2014-1603 |
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS
3.3.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) param parameter to admin/load.php or (2) user, (3) email,
or (4) name parameter in a Save Settings action to admin/settings.php.
|
| CVE-2014-1599 |
Multiple cross-site scripting (XSS) vulnerabilities in the SFR Box
router with firmware NB6-MAIN-R3.3.4 allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters to (1) dns,
(2) dhcp, (3) nat, (4) route, or (5) lan in network/; or (6)
wifi/config.
|
| CVE-2014-1573 |
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before
4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not
ensure that a scalar context is used for certain CGI parameters, which
allows remote attackers to conduct cross-site scripting (XSS) attacks
by sending three values for a single parameter name.
|
| CVE-2014-1530 |
The docshell implementation in Mozilla Firefox before 29.0, Firefox
ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before
2.26 allows remote attackers to trigger the loading of a URL with a
spoofed baseURI property, and conduct cross-site scripting (XSS)
attacks, via a crafted web site that performs history navigation.
|
| CVE-2014-1504 |
The session-restore feature in Mozilla Firefox before 28.0 and
SeaMonkey before 2.25 does not consider the Content Security Policy of
a data: URL, which makes it easier for remote attackers to conduct
cross-site scripting (XSS) attacks via a crafted document that is
accessed after a browser restart.
|
| CVE-2014-1472 |
Multiple cross-site scripting (XSS) vulnerabilities in the Enterprise
Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-1458 |
Cross-site scripting (XSS) vulnerability in the web administration
interface in FortiGuard FortiWeb 5.0.3 and earlier allows remote
authenticated administrators to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-1456 |
Cross-site scripting (XSS) vulnerability in the login page in Open Web
Analytics (OWA) before 1.5.6 allows remote attackers to inject
arbitrary web script or HTML via the owa_user_id parameter to
index.php.
|
| CVE-2014-1408 |
The Conceptronic C54APM access point with runtime code 1.26 has a
default password of admin for the admin account, which makes it easier
for remote attackers to obtain access via an HTTP request, as
demonstrated by stored XSS attacks.
|
| CVE-2014-1407 |
Multiple cross-site scripting (XSS) vulnerabilities on the
Conceptronic C54APM access point with runtime code 1.26 allow remote
attackers to inject arbitrary web script or HTML via (1) the
submit-url parameter in a Refresh action to goform/formWlSiteSurvey or
(2) the wlan-url parameter to goform/formWlanSetup.
|
| CVE-2014-1403 |
Cross-site scripting (XSS) vulnerability in name.html in easyXDM
before 2.4.19 allows remote attackers to inject arbitrary web script
or HTML via the location.hash value.
|
| CVE-2014-1237 |
Cross-site scripting (XSS) vulnerability in synetics i-doit pro before
1.2.4 allows remote attackers to inject arbitrary web script or HTML
via the call parameter.
|
| CVE-2014-1232 |
Cross-site scripting (XSS) vulnerability in the Foliopress WYSIWYG
plugin before 2.6.8.5 for WordPress allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-1224 |
Incomplete blacklist vulnerability in the user registration feature in
rexx Recruitment R6.1 and R7 without "fixes from 2014-01-15" allows
remote attackers to conduct cross-site scripting (XSS) attacks via the
oninput event handler in the fname parameter to the default URI in
/reg.
|
| CVE-2014-1223 |
Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx
in Telligent Evolution before 6.1.19.36103, 7.x before 7.1.12.36162,
7.5.x, and 7.6.x before 7.6.7.36651 allows remote attackers to inject
arbitrary web script or HTML via the msg parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2014-10036 |
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before
8.1 allows remote attackers to inject arbitrary web script or HTML via
the cameFromUrl parameter to feed/generateFeedUrl.html.
|
| CVE-2014-10035 |
Multiple cross-site scripting (XSS) vulnerabilities in the admin area
in couponPHP before 1.2.0 allow remote administrators to inject
arbitrary web script or HTML via the (1) sEcho parameter to
comments_paginate.php or (2) stores_paginate.php or the (3)
affiliate_url, (4) description, (5) domain, (6) seo[description], (7)
seo[heading], (8) seo[title], (9) seo[keywords], (10) setting[logo],
(11) setting[perpage], or (12) setting[sitename] to admin/index.php.
|
| CVE-2014-10028 |
Cross-site scripting (XSS) vulnerability in D-Link DAP-1360 router
with firmware 2.5.4 and later allows remote attackers to inject
arbitrary web script or HTML via the res_buf parameter to index.cgi
when res_config_id is set to 41.
|
| CVE-2014-10027 |
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link
DAP-1360 router with firmware 2.5.4 and earlier allow remote attackers
to hijack the authentication of unspecified users for requests that
(1) change the MAC filter restrict mode, (2) add a MAC address to the
filter, or (3) remove a MAC address from the filter via a crafted
request to index.cgi.
|
| CVE-2014-10018 |
Cross-site scripting (XSS) vulnerability in
webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI
modem allows remote attackers to inject arbitrary web script or HTML
via the essid parameter.
|
| CVE-2014-10016 |
Multiple cross-site scripting (XSS) vulnerabilities in the Welcart
e-Commerce plugin 1.3.12 for WordPress allow remote attackers to
inject arbitrary web script or HTML via (1) unspecified vectors
related to purchase_limit or the (2) name, (3) intl, (4) nocod, or (5)
time parameter in an add_delivery_method action to
wp-admin/admin-ajax.php.
|
| CVE-2014-10014 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack
the authentication of administrators for requests that (1) change the
username and password of the administrator via an update action to the
AdminOptions controller or conduct cross-site scripting (XSS) attacks
via the (2) event_title parameter in a create action to the
AdminEvents controller or (3) category_title parameter in a create
action to the AdminCategories controller.
|
| CVE-2014-10012 |
Cross-site scripting (XSS) vulnerability in the Another WordPress
Classifieds Plugin plugin for WordPress allows remote attackers to
inject arbitrary web script or HTML via the query string to the
default URI.
|
| CVE-2014-10009 |
Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) first_name, (2) last_name, or (3) notes parameter to the client
page; (4) insu_name or (5) price parameter to the add_insurance_cat
page; or (6) status[] parameter to the add_status page.
|
| CVE-2014-10007 |
Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog
4.0 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) name, (2) email, or (3) subject parameter in a
contact action to index.php.
|
| CVE-2014-10006 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Maian
Uploader 4.0 allow remote attackers to hijack the authentication of
unspecified users for requests that conduct cross-site scripting (XSS)
attacks via the width parameter to (1)
uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php.
|
| CVE-2014-100038 |
Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and
earlier allows remote attackers to inject arbitrary web script or HTML
via the search parameter to search/.
|
| CVE-2014-100037 |
Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and
earlier allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to archives/.
|
| CVE-2014-100036 |
Cross-site scripting (XSS) vulnerability in FlatPress 1.0.2 allows
remote attackers to inject arbitrary web script or HTML via the
content parameter to the default URI.
|
| CVE-2014-100034 |
Cross-site scripting (XSS) vulnerability in the frontend interface in
LicensePal ArcticDesk before 1.2.5 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-100032 |
Cross-site scripting (XSS) vulnerability in top.html in the Airties
Air 6372 modem allows remote attackers to inject arbitrary web script
or HTML via the productboardtype parameter.
|
| CVE-2014-100030 |
Cross-site scripting (XSS) vulnerability in module/search/function.php
in Ganesha Digital Library (GDL) 4.2 allows remote attackers to inject
arbitrary web script or HTML via the keyword parameter in a ByEge
action.
|
| CVE-2014-10003 |
Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader
4.0 allow remote attackers to inject arbitrary web script or HTML via
the width parameter to (1) uploader/admin/js/load_flv.js.php or (2)
uploader/js/load_flv.js.php.
|
| CVE-2014-100028 |
Cross-site scripting (XSS) vulnerability in /signup in WEBCrafted
allows remote attackers to inject arbitrary web script or HTML via the
username.
|
| CVE-2014-100027 |
Cross-site scripting (XSS) vulnerability in the WP SlimStat plugin
before 3.5.6 for WordPress allows remote attackers to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2014-100026 |
Cross-site scripting (XSS) vulnerability in readme.php in the April's
Super Functions Pack plugin before 1.4.8 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the page
parameter. NOTE: some of these details are obtained from third party
information.
|
| CVE-2014-100024 |
Cross-site scripting (XSS) vulnerability in Seo Panel before 3.4.0
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-100023 |
Multiple cross-site scripting (XSS) vulnerabilities in question.php in
the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the quiz parameter to
wp-admin/edit.php.
|
| CVE-2014-100021 |
Cross-site scripting (XSS) vulnerability in
symfony/web/index.php/pim/viewEmployeeList in OrangeHRM before 3.1.2
allows remote attackers to inject arbitrary web script or HTML via the
empsearch[employee_name][empId] parameter.
|
| CVE-2014-100018 |
Cross-site scripting (XSS) vulnerability in the Unconfirmed plugin
before 1.2.5 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the s parameter in the unconfirmed page to
wp-admin/network/users.php.
|
| CVE-2014-100017 |
Cross-site scripting (XSS) vulnerability in canned_opr.php in
PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web
script or HTML via the message field.
|
| CVE-2014-100016 |
Cross-site scripting (XSS) vulnerability in
photocrati-gallery/ecomm-sizes.php in the Photocrati theme for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the prod_id parameter.
|
| CVE-2014-100013 |
Multiple cross-site scripting (XSS) vulnerabilities in clientResponse
4.1 allow remote attackers to inject arbitrary web script or HTML via
the (1) Subject or (2) Message field.
|
| CVE-2014-100010 |
Cross-site scripting (XSS) vulnerability in ClanSphere 2011.4 allows
remote attackers to inject arbitrary web script or HTML via the where
parameter in a list action to index.php.
|
| CVE-2014-10001 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack
the authentication of administrators for requests that (1) conduct
cross-site scripting (XSS) attacks via the i18n[1][name] parameter in
a pjActionCreate action to the pjAdminServices controller or (2) add
an administrator via a pjActionCreate action to the pjAdminUsers
controller.
|
| CVE-2014-100008 |
Cross-site scripting (XSS) vulnerability in includes/delete_img.php in
the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel)
plugin 2.2.1 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the path parameter.
|
| CVE-2014-100007 |
Cross-site scripting (XSS) vulnerability in the HK Exif Tags plugin
before 1.12 for WordPress allows remote authenticated users to inject
arbitrary web script or HTML via an EXIF tag. NOTE: some of these
details are obtained from third party information.
|
| CVE-2014-100006 |
Multiple cross-site scripting (XSS) vulnerabilities in
modules_v3/googlemap/wt_v3_street_view.php in webtrees before 1.5.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) map, (2) streetview, or (3) reset parameter.
|
| CVE-2014-100004 |
Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0
Update-4 (rev. 140120) allows remote attackers to inject arbitrary web
script or HTML via the xmlcontrol parameter to the default URI. NOTE:
some of these details are obtained from third party information.
|
| CVE-2014-0977 |
Cross-site scripting (XSS) vulnerability in the Rich Text Editor in
Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x
before 6.0.1 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-0968 |
Cross-site scripting (XSS) vulnerability in the GDS component in IBM
InfoSphere Master Data Management - Collaborative Edition 10.x and
11.x before 11.0 FP4 and InfoSphere Master Data Management Server for
Product Information Management 9.0 and 9.1 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL for an
MHTML document.
|
| CVE-2014-0967 |
Cross-site scripting (XSS) vulnerability in the GDS component in IBM
InfoSphere Master Data Management - Collaborative Edition 10.x and
11.x before 11.0 FP4 and InfoSphere Master Data Management Server for
Product Information Management 9.0 and 9.1 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-0961 |
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity
Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM
Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote
authenticated users to hijack the authentication of arbitrary users
for requests that insert XSS sequences.
|
| CVE-2014-0957 |
Cross-site scripting (XSS) vulnerability in IBM Business Process
Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL that triggers a service failure.
|
| CVE-2014-0956 |
Cross-site scripting (XSS) vulnerability in googlemap.jsp in IBM
WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3
CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0955 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0
before 8.0.0.1 CF12, when Social Rendering in Connections integration
is enabled, allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2014-0953 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal
6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0
through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-0952 |
Cross-site scripting (XSS) vulnerability in boot_config.jsp in IBM
WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3
CF28, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0951 |
Cross-site scripting (XSS) vulnerability in FilterForm.jsp in IBM
WebSphere Portal 7.0 before 7.0.0.2 CF28 and 8.0 before 8.0.0.1 CF12
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0945 |
Cross-site scripting (XSS) vulnerability in the RES Console in Rule
Execution Server in IBM Operational Decision Manager 7.5 before FP3
IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2014-0944 |
Cross-site request forgery (CSRF) vulnerability in the RES Console in
Rule Execution Server in IBM Operational Decision Manager 7.5 before
FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote
authenticated users to hijack the authentication of arbitrary users
for requests that insert XSS sequences.
|
| CVE-2014-0942 |
Cross-site scripting (XSS) vulnerability in
webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM
Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL, a different
vulnerability than CVE-2014-0941.
|
| CVE-2014-0941 |
Cross-site scripting (XSS) vulnerability in
webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM
Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL, a different
vulnerability than CVE-2014-0942.
|
| CVE-2014-0940 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli
Service Automation Manager 7.2.2.2 before 7.2.2.2-TIV-TSAM-LA0041
allow remote attackers to inject arbitrary web script or HTML via
vectors involving the (1) REST API or (2) Self Service UI.
|
| CVE-2014-0932 |
Cross-site scripting (XSS) vulnerability in IBM Sterling Order
Management 8.5 before HF105 and Sterling Selling and Fulfillment
Foundation 9.0 before HF85 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-0917 |
Cross-site scripting (XSS) vulnerability in IBM Eclipse Help System
(IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5
through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1
CF06 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL.
|
| CVE-2014-0915 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo
Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and
7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and
7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset
Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli
Asset Management for IT and certain other products allow remote
authenticated users to inject arbitrary web script or HTML via (1) the
KPI display name field or (2) a portlet field.
|
| CVE-2014-0914 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo
Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for
SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8
for Tivoli IT Asset Management for IT and Maximo Service Desk allows
remote authenticated users to inject arbitrary web script or HTML via
the Query Description Field.
|
| CVE-2014-0913 |
Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino
8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to
inject arbitrary web script or HTML via an e-mail message, aka SPR
BFEY9GXHZE.
|
| CVE-2014-0910 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal
6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0
through 7.0.0.2 CF28 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-0901 |
Cross-site scripting (XSS) vulnerability in the Social Rendering
implementation in the IBM Connections integration in IBM WebSphere
Portal 8.0.0.x before 8.0.0.1 CF11 allows remote authenticated users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-0893 |
Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM
Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud
Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified parameters.
|
| CVE-2014-0889 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite
(aka Atlas Policy Suite), as used in Atlas eDiscovery Process
Management through 6.0.3, Disposal and Governance Management for IT
through 6.0.3, and Global Retention Policy and Schedule Management
through 6.0.3, allow remote attackers to inject arbitrary web script
or HTML via unspecified parameters.
|
| CVE-2014-0884 |
Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM
Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0874 |
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x
before 2.0.2.2-ICN-FP002 allows remote authenticated users to inject
arbitrary web script or HTML via an unspecified parameter.
|
| CVE-2014-0870 |
Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM
Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5
in IBM Algorithmics allow remote attackers to inject arbitrary web
script or HTML via (1) the Message parameter to
rcore6/main/showerror.jsp, (2) the ButtonsetClass parameter to
rcore6/main/buttonset.jsp, (3) the MBName parameter to
rcore6/frameset.jsp, (4) the Init parameter to
algopds/rcore6/main/browse.jsp, or the (5) Name, (6) StoreName, or (7)
STYLESHEET parameter to algopds/rcore6/main/ibrowseheader.jsp.
|
| CVE-2014-0861 |
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos
Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5,
10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows
remote attackers to inject arbitrary web script or HTML via an
unspecified parameter that is not properly handled during use of the
Back button.
|
| CVE-2014-0855 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Connections
Portlets 4.x before 4.5.1 FP1 for IBM WebSphere Portal 7.0.0.2 and
8.0.0.1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-0853 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1)
ForwardController and (2) AttributeEditor scripts in IBM Rational
Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1
allow remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-0850 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data
Management Reference Data Management (RDM) Hub 10.1 and 11.0 before
11.0.0.0-MDM-IF008 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-0846 |
Cross-site scripting (XSS) vulnerability in IBM Rational Requirements
Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational
DOORS Next Generation 4.x before 4.0.6, allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2014-0843 |
Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point
6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote
authenticated users to inject arbitrary web script or HTML by
uploading a file.
|
| CVE-2014-0840 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational
Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1
allow remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2014-0836 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM
7.2 MR1 and earlier allows remote attackers to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2014-0832 |
Multiple cross-site scripting (XSS) vulnerabilities in
configuration-details screens in the OAC component in IBM Financial
Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote
authenticated users to inject arbitrary web script or HTML via a
crafted text value.
|
| CVE-2014-0828 |
Cross-site scripting (XSS) vulnerability in the WCM (Web Content
Manager) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27,
6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF27, and
8.0.0.x before 8.0.0.1 CF11 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-0827 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim
Workload Replay 1.1 allows remote attackers to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2014-0825 |
Cross-site scripting (XSS) vulnerability in openreport.jsp in IBM
Maximo Asset Management 7.x before 7.1.1.12 IFIX.20140321-1336 and
7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before
7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for
IT, Tivoli Service Request Manager, Maximo Service Desk, and Change
and Configuration Management Database (CCMDB) 7.x before 7.1.1.12
IFIX.20140218-1510 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted report parameter.
|
| CVE-2014-0824 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.x before 7.1.1.8 LAFIX.20140319-0839 and 7.1.1.12 before
IFIX.20140321-1336 and Tivoli IT Asset Management for IT, Tivoli
Service Request Manager, Maximo Service Desk, and Change and
Configuration Management Database (CCMDB) 7.x before 7.1.1.8
LAFIX.20140319-0839 and 7.1.1.12 before IFIX.20140218-1510 allows
remote authenticated users to inject arbitrary web script or HTML via
an attachment URL.
|
| CVE-2014-0814 |
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.8.6
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0812 |
Cross-site scripting (XSS) vulnerability in KENT-WEB Joyful Note 2.8
and earlier, when Internet Explorer 7 or earlier is used, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0811 |
Cross-site scripting (XSS) vulnerability in Blackboard Vista/CE 8.0
SP6 and earlier allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2014-0793 |
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas
Komento (com_komento) component before 1.7.3 for Joomla! allow remote
attackers to inject arbitrary web script or HTML via the (1) website
or (2) latitude parameter in a comment to the default URI.
|
| CVE-2014-0735 |
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant
(IPMA) interface in Cisco Unified Communications Manager (Unified CM)
10.0(1) and earlier allows remote attackers to inject arbitrary web
script or HTML via a crafted URL, aka Bug ID CSCum46470.
|
| CVE-2014-0723 |
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant
(IPMA) interface in Cisco Unified Communications Manager (UCM) allows
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka Bug ID CSCum05343.
|
| CVE-2014-0681 |
Cross-site scripting (XSS) vulnerability in Cisco Identity Services
Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject
arbitrary web script or HTML via a report containing a crafted URL
that is not properly handled during generation of report-output pages,
aka Bug ID CSCui15064.
|
| CVE-2014-0680 |
Cross-site scripting (XSS) vulnerability in the HTTP control interface
in the NAC Web Agent component in Cisco Identity Services Engine (ISE)
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL, aka Bug ID CSCui15038.
|
| CVE-2014-0673 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow
remote attackers to inject arbitrary web script or HTML via a crafted
URL, aka Bug IDs CSCud10943 and CSCud10950.
|
| CVE-2014-0670 |
Cross-site scripting (XSS) vulnerability in the Search and Play
interface in Cisco MediaSense allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug ID
CSCum16686.
|
| CVE-2014-0668 |
Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure
Access Control System (ACS) allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug ID
CSCue65949.
|
| CVE-2014-0663 |
Cross-site scripting (XSS) vulnerability in the web framework in Cisco
Secure Access Control System (ACS) allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug ID
CSCum03625.
|
| CVE-2014-0652 |
Cross-site scripting (XSS) vulnerability in the Mappings page in Cisco
Context Directory Agent (CDA) allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuj45358.
|
| CVE-2014-0639 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer
5.x before GRC 5.4 SP1 P3 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-0638 |
Cross-site scripting (XSS) vulnerability in RSA Adaptive
Authentication (On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows
remote attackers to inject arbitrary web script or HTML via vectors
involving FRAME elements, related to a "cross-frame scripting" issue.
|
| CVE-2014-0637 |
Cross-site scripting (XSS) vulnerability in the back-office
case-management application in RSA Adaptive Authentication
(On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-0623 |
Cross-site scripting (XSS) vulnerability in the Self-Service Console
in EMC RSA Authentication Manager 7.1 before SP4 P32 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, related to a "cross frame scripting" issue.
|
| CVE-2014-0620 |
Multiple cross-site scripting (XSS) vulnerabilities in Technicolor
(formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject
arbitrary web script or HTML via the (1) ADDNewDomain parameter to
parental/website-filters.asp or (2) VmTracerouteHost parameter to
goform/status/diagnostics-route.
|
| CVE-2014-0611 |
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in
Novell GroupWise 2012 before Support Pack 4 and 2014 before Support
Pack 2 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2014-0599 |
Cross-site scripting (XSS) vulnerability in iPrint in Novell Open
Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0571 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0
before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10
before Update 14, and 11 before Update 2 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-0562 |
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat
10.x before 10.1.12 and 11.x before 11.0.09 on OS X allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka "Universal XSS (UXSS)."
|
| CVE-2014-0533 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before
13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before
11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK
before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2014-0531 and
CVE-2014-0532.
|
| CVE-2014-0532 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before
13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before
11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK
before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2014-0531 and
CVE-2014-0533.
|
| CVE-2014-0531 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before
13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before
11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK
before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2014-0532 and
CVE-2014-0533.
|
| CVE-2014-0509 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before
11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows
and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83
on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK &
Compiler before 13.0.0.83 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2014-0362 |
Cross-site scripting (XSS) vulnerability on Google Search Appliance
(GSA) devices before 7.0.14.G.216 and 7.2 before 7.2.0.G.114, when
dynamic navigation is configured, allows remote attackers to inject
arbitrary web script or HTML via input included in a SCRIPT element.
|
| CVE-2014-0341 |
Multiple cross-site scripting (XSS) vulnerabilities in PivotX before
2.3.9 allow remote authenticated users to inject arbitrary web script
or HTML via the title field to (1) templates_internal/pages.tpl, (2)
templates_internal/home.tpl, or (3) templates_internal/entries.tpl;
(4) an event field to objects.php; or the (5) email or (6) nickname
field to pages.php, related to templates_internal/users.tpl.
|
| CVE-2014-0339 |
Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before
1.680 allows remote attackers to inject arbitrary web script or HTML
via the search parameter.
|
| CVE-2014-0338 |
Multiple cross-site scripting (XSS) vulnerabilities in the firewall
policy management pages in WatchGuard Fireware XTM before 11.8.3 allow
remote attackers to inject arbitrary web script or HTML via the
pol_name parameter.
|
| CVE-2014-0337 |
Cross-site scripting (XSS) vulnerability in the web interface on
Huawei Echo Life HG8247 routers with software before V100R006C00SPC127
allows remote attackers to inject arbitrary web script or HTML via an
invalid TELNET connection attempt with a crafted username that is not
properly handled during construction of the "failed log-in attempts
over telnet" log view.
|
| CVE-2014-0335 |
Multiple cross-site scripting (XSS) vulnerabilities in the web client
in Serena Dimensions CM 12.2 build 7.199.0 allow remote attackers to
inject arbitrary web script or HTML via the (1) DB_CONN, (2) DB_NAME,
(3) DM_HOST, (4) MAN_DB_NAME, (5) framecmd, (6) identifier, (7)
merant.adm.adapters.AdmDialogPropertyMgr, (8) nav_frame, (9) nav_jsp,
(10) target_frame, (11) id, or (12) type parameter to the dimensions/
URI.
|
| CVE-2014-0334 |
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple
allow remote authenticated users to inject arbitrary web script or
HTML via (1) the group parameter to admin/addgroup.php, (2) the
htmlblob parameter to admin/addhtmlblob.php, the (3) title or (4) url
parameter to admin/addbookmark.php, (5) the stylesheet_name parameter
to admin/copystylesheet.php, (6) the template_name parameter to
admin/copytemplate.php, the (7) title or (8) url parameter to
admin/editbookmark.php, (9) the template parameter to
admin/listtemplates.php, or (10) the css_name parameter to
admin/listcss.php, a different issue than CVE-2014-2092.
|
| CVE-2014-0332 |
Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL
GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL
UMA E5000 before 7.1 SP2 might allow remote attackers to inject
arbitrary web script or HTML via the node_id parameter in a
ScreenDisplayManager genNetwork action.
|
| CVE-2014-0331 |
Cross-site scripting (XSS) vulnerability in the web administration
interface in FortiADC with firmware before 3.2.1 allows remote
attackers to inject arbitrary web script or HTML via the locale
parameter to gui_partA/.
|
| CVE-2014-0330 |
Cross-site scripting (XSS) vulnerability in adminui/user_list.php on
the Dell KACE K1000 management appliance 5.5.90545 allows remote
attackers to inject arbitrary web script or HTML via the LABEL_ID
parameter.
|
| CVE-2014-0232 |
Multiple cross-site scripting (XSS) vulnerabilities in
framework/common/webcommon/includes/messages.ftl in Apache OFBiz
11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, which are not properly handled in a (1) result or (2) error
message.
|
| CVE-2014-0218 |
Cross-site scripting (XSS) vulnerability in the URL downloader
repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x
before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0208 |
Cross-site scripting (XSS) vulnerability in the search auto-completion
functionality in Foreman before 1.4.4 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted key name.
|
| CVE-2014-0176 |
Cross-site scripting (XSS) vulnerability in application/panel_control
in CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-0157 |
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration
dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4
and icehouse before icehouse-rc2 allows remote attackers to inject
arbitrary web script or HTML via the description field of a Heat
template.
|
| CVE-2014-0149 |
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss
Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web
script or HTML via a (1) parameter or (2) id name.
|
| CVE-2014-0141 |
Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.
|
| CVE-2014-0089 |
Cross-site scripting (XSS) vulnerability in
app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows
remote authenticated users to inject arbitrary web script or HTML via
the bookmark name when adding a bookmark.
|
| CVE-2014-0081 |
Multiple cross-site scripting (XSS) vulnerabilities in
actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails
before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow
remote attackers to inject arbitrary web script or HTML via the (1)
format, (2) negative_format, or (3) units parameter to the (a)
number_to_currency, (b) number_to_percentage, or (c) number_to_human
helper.
|
| CVE-2014-0046 |
Cross-site scripting (XSS) vulnerability in the link-to helper in
Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before
1.4.0-beta.6, when used in non-block form, allows remote attackers to
inject arbitrary web script or HTML via the title attribute.
|
| CVE-2014-0029 |
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web
application in Red Hat katello-headpin allow remote attackers to
inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2013-7454 |
The validator module before 1.1.0 for Node.js allows remote attackers
to bypass the cross-site scripting (XSS) filter via nested forbidden
strings.
|
| CVE-2013-7453 |
The validator module before 1.1.0 for Node.js allows remote attackers
to bypass the cross-site scripting (XSS) filter via vectors related to
UI redressing.
|
| CVE-2013-7452 |
The validator module before 1.1.0 for Node.js allows remote attackers
to bypass the cross-site scripting (XSS) filter via a crafted
javascript URI.
|
| CVE-2013-7451 |
The validator module before 1.1.0 for Node.js allows remote attackers
to bypass the XSS filter via a nested tag.
|
| CVE-2013-7433 |
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin
before 3.1 for Joomla!.
|
| CVE-2013-7430 |
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin
before 3.1 for Joomla! allows remote attackers to inject arbitrary
web script or HTML via the xmlns parameter.
|
| CVE-2013-7419 |
Cross-site scripting (XSS) vulnerability in includes/refreshDate.php
in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and
Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the roomid parameter.
|
| CVE-2013-7418 |
cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5
allows remote authenticated users to execute arbitrary code via shell
metacharacters in the TABLE parameter. NOTE: this can be exploited
remotely by leveraging a separate cross-site scripting (XSS)
vulnerability.
|
| CVE-2013-7417 |
Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in
IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to
inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this
can be used to bypass the cross-site request forgery (CSRF) protection
mechanism by setting the Referer.
|
| CVE-2013-7389 |
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645
Router (Rev. A1) with firmware before 1.04B11 allow remote attackers
to inject arbitrary web script or HTML via the (1) deviceid parameter
to parentalcontrols/bind.php, (2) RESULT parameter to info.php, or (3)
receiver parameter to bsc_sms_send.php.
|
| CVE-2013-7385 |
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator
password in plaintext in Javascript code that is generated by
lz/mobile/chat.php, which allows remote attackers to obtain sensitive
information and gain privileges by accessing the loginName and
loginPassword variables using an independent cross-site scripting
(XSS) attack. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2013-7033.
|
| CVE-2013-7368 |
Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1
allow remote attackers to inject arbitrary web script or HTML via the
gnew_template parameter to (1) users/profile.php, (2)
articles/index.php, or (3) admin/polls.php; (4) category_id parameter
to news/submit.php; news_id parameter to (5) news/send.php or (6)
comments/add.php; or (7) post_subject or (8) thread_id parameter to
posts/edit.php.
|
| CVE-2013-7365 |
Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal
allows remote attackers to inject arbitrary web script or HTML via
unspecified parameters.
|
| CVE-2013-7343 |
Cross-site scripting (XSS) vulnerability in flowplayer.swf in the
Flash fallback feature in Flowplayer HTML5 5.4.3 allows remote
attackers to inject arbitrary web script or HTML by using URL encoding
within the callback parameter name. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2013-7342.
|
| CVE-2013-7342 |
Cross-site scripting (XSS) vulnerability in flowplayer.swf in the
Flash fallback feature in Flowplayer HTML5 5.4.1 allows remote
attackers to inject arbitrary web script or HTML via the callback
parameter, a related issue to CVE-2013-7341.
|
| CVE-2013-7341 |
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer
Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before
2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote
attackers to inject arbitrary web script or HTML by (1) providing a
crafted playerId or (2) referencing an external domain, a related
issue to CVE-2013-7342.
|
| CVE-2013-7326 |
Cross-site scripting (XSS) vulnerability in vTiger CRM 5.4.0 allows
remote attackers to inject arbitrary web script or HTML via the (1)
return_url parameter to modules\com_vtiger_workflow\savetemplate.php,
or unspecified vectors to (2) deletetask.php, (3) edittask.php, (4)
savetask.php, or (5) saveworkflow.php.
|
| CVE-2013-7321 |
Cross-site scripting (XSS) vulnerability in D-Link DAP-2253 Access
Point (Rev. A1) with firmware before 1.30 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-7319 |
Cross-site scripting (XSS) vulnerability in the Download Manager
plugin before 2.5.9 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the title field.
|
| CVE-2013-7318 |
Cross-site scripting (XSS) vulnerability in BusinessFlow/login in
AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject
arbitrary web script or HTML via the message parameter.
|
| CVE-2013-7317 |
Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before
4.1.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) settings_file or (2) data_file parameter to (a) ampie.swf,
(b) amline.swf, or (c) amcolumn.swf.
|
| CVE-2013-7316 |
Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other
versions before 6.5.0 allows remote attackers to inject arbitrary web
script or HTML via a crafted HTML file, as demonstrated by
README.html.
|
| CVE-2013-7303 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
squelettes-dist/formulaires/inscription.php and (2)
prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before
3.0.13 allow remote attackers to inject arbitrary web script or HTML
via the author name field.
|
| CVE-2013-7289 |
Multiple cross-site scripting (XSS) vulnerabilities in register.php in
Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers
to inject arbitrary web script or HTML via the (1) first_name, (2)
last_name, (3) email, or (4) username parameter.
|
| CVE-2013-7288 |
Cross-site scripting (XSS) vulnerability in the mycode_parse_video
function in inc/class_parser.php in MyBB (aka MyBulletinBoard) before
1.6.12 allows remote attackers to inject arbitrary web script or HTML
via vectors related to Yahoo video URLs.
|
| CVE-2013-7279 |
Cross-site scripting (XSS) vulnerability in
views/video-management/preview_video.php in the S3 Video plugin before
0.983 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the base parameter.
|
| CVE-2013-7277 |
Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP
Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject
arbitrary web script or HTML via the (1) HTTP Referer header to
saa.php, (2) username parameter to login.php, or (3) keyword_list
parameter to keysearch.php.
|
| CVE-2013-7276 |
Cross-site scripting (XSS) vulnerability in inc/raf_form.php in the
Recommend to a friend plugin 2.0.2 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the current_url
parameter.
|
| CVE-2013-7275 |
Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka
MyBulletinBoard) before 1.6.12 allows remote attackers to inject
arbitrary web script or HTML via the editor parameter in a smilie list
popup.
|
| CVE-2013-7274 |
Cross-site scripting (XSS) vulnerability in Wallpaper Script 3.5.0082
allows remote authenticated users to inject arbitrary web script or
HTML via the title field in a wallpaper file upload.
|
| CVE-2013-7258 |
Cross-site scripting (XSS) vulnerability in web2ldap 1.1.x before
1.1.49 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to "displaying group DN and entry data
in group administration UI."
|
| CVE-2013-7257 |
Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote
attackers to inject arbitrary web script or HTML via the Project Name
field.
|
| CVE-2013-7254 |
Cross-site scripting (XSS) vulnerability in Opsview before 4.4.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-7250 |
Cross-site scripting (XSS) vulnerability in the JsonBuilder
implementation in ProjectForge before 5.3 allows remote authenticated
users to inject arbitrary web script or HTML via an autocompletion
string, related to web/core/JsonBuilder.java and
web/wicket/autocompletion/PFAutoCompleteBehavior.java.
|
| CVE-2013-7243 |
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS
3.1.2 and 3.2.3 allow remote attackers to inject arbitrary web script
or HTML via the (1) post-menu field to edit.php or (2) Display name
field to settings.php. NOTE: The Custom Permalink Structure and Email
Address fields are already covered by CVE-2012-6621.
|
| CVE-2013-7241 |
Cross-site scripting (XSS) vulnerability in the export function in
zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows
remote attackers to inject arbitrary web script or HTML via the URI.
|
| CVE-2013-7231 |
Cross-site scripting (XSS) vulnerability in the Mobile Content Server
in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors,
a different vulnerability than CVE-2013-5222.
|
| CVE-2013-7194 |
Multiple cross-site scripting (XSS) vulnerabilities in
www/administrator.php in eFront 3.6.14 (build 18012) allow remote
authenticated administrators to inject arbitrary web script or HTML
via the (1) Last name, (2) Lesson name, or (3) Course name field.
|
| CVE-2013-7191 |
Cross-site scripting (XSS) vulnerability in Tenmiles Helpdesk Pilot
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to the default URI for a ticket.
|
| CVE-2013-7188 |
Cross-site scripting (XSS) vulnerability in KBKP Software HostBill
before 2013-12-14 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-7182 |
Cross-site scripting (XSS) vulnerability in
firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote
attackers to inject arbitrary web script or HTML via the mkey
parameter.
|
| CVE-2013-7181 |
Cross-site scripting (XSS) vulnerability in user/ldap_user/add in
Fortinet FortiOS 5.0.3 allows remote attackers to inject arbitrary web
script or HTML via the filter parameter.
|
| CVE-2013-7143 |
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite
7.4.1 allows remote attackers to inject arbitrary web script or HTML
via the title in a mail filter rule.
|
| CVE-2013-7142 |
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite
7.4.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified oAuth API functions.
|
| CVE-2013-7141 |
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite
7.4.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors related to crafted "<%" tags.
|
| CVE-2013-7129 |
Cross-site scripting (XSS) vulnerability in ThemeBeans Blooog theme
1.1 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the jQuery parameter to assets/js/jplayer.swf.
|
| CVE-2013-7082 |
Cross-site scripting (XSS) vulnerability in the errorAction method in
the ActionController base class in TYPO3 Flow (formerly FLOW3) 1.1.x
before 1.1.1 and 2.0.x before 2.0.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified input, which is
returned in an error message.
|
| CVE-2013-7078 |
Cross-site scripting (XSS) vulnerability in the errorAction method in
the ActionController base class in the Extbase Framework in TYPO3
4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and
6.1.0 through 6.1.6, when the Rewritten Property Mapper is enabled,
allows remote attackers to inject arbitrary web script or HTML via
unspecified input, which is returned in an error message. NOTE: this
might be the same vulnerability as CVE-2013-7072.
|
| CVE-2013-7077 |
Cross-site scripting (XSS) vulnerability in the Backend User
Administration Module in TYPO3 6.0.x before 6.0.12 and 6.1.x before
6.1.7 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2013-7076 |
Cross-site scripting (XSS) vulnerability in Extension Manager in TYPO3
4.5.x before 4.5.32 and 4.7.x before 4.7.17 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-7074 |
Multiple cross-site scripting (XSS) vulnerabilities in Content Editing
Wizards in TYPO3 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x
before 6.0.12, 6.1.x before 6.1.7, and the development versions of 6.2
allow remote authenticated users to inject arbitrary web script or
HTML via unspecified parameters.
|
| CVE-2013-7064 |
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance
module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated
administrators with the "Administer EU Cookie Compliance popup"
permission to inject arbitrary web script or HTML via unspecified
configuration values.
|
| CVE-2013-7033 |
LiveZilla before 5.1.2.1 includes the operator password in plaintext
in Javascript code that is generated by lz/mobile/chat.php, which
might allow remote attackers to obtain sensitive information and gain
privileges by accessing the loginName and loginPassword variables
using an independent cross-site scripting (XSS) attack.
|
| CVE-2013-7032 |
Multiple cross-site scripting (XSS) vulnerabilities in the web based
operator client in LiveZilla before 5.1.2.1 allow remote attackers to
inject arbitrary web script or HTML via the (1) name of an uploaded
file or (2) customer name in a resource created from an uploaded file,
a different vulnerability than CVE-2013-7003.
|
| CVE-2013-7025 |
Multiple cross-site scripting (XSS) vulnerabilities in
ematStaticAlertTypes.jsp in the Alert Settings section in Dell
SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1
SP1 before Hotfix 134235 allow remote authenticated users to inject
arbitrary web script or HTML via the (1) valfield_1 or (2) value_1
parameter to createNewThreshold.jsp.
|
| CVE-2013-7003 |
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla
before 5.1.2.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) full name field, (2) company field, or (3)
filename to chat.php.
|
| CVE-2013-7002 |
Cross-site scripting (XSS) vulnerability in
mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows
remote attackers to inject arbitrary web script or HTML via the
g_language parameter.
|
| CVE-2013-6997 |
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange
(OX) AppSuite 7.4.0 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) an HTML email with crafted CSS
code containing wildcards or (2) office documents containing "crafted
hyperlinks with script URL handlers."
|
| CVE-2013-6993 |
Cross-site scripting (XSS) vulnerability in the Ad-minister plugin 0.6
and earlier for WordPress allows remote attackers to inject arbitrary
web script or HTML via the key parameter in a delete action to
wp-admin/tools.php.
|
| CVE-2013-6992 |
Cross-site request forgery (CSRF) vulnerability in
askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin
3.0 and earlier for WordPress allows remote attackers to hijack the
authentication of administrators for requests that conduct cross-site
scripting (XSS) attacks via the aafireadcode parameter to
wp-admin/options-general.php.
|
| CVE-2013-6991 |
Cross-site scripting (XSS) vulnerability in the WP-Cron Dashboard
plugin 1.1.5 and earlier for WordPress allows remote attackers to
inject arbitrary web script or HTML via the procname parameter to
wp-admin/tools.php.
|
| CVE-2013-6974 |
Cross-site scripting (XSS) vulnerability in the web interface in Cisco
Secure Access Control System (ACS) allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug ID
CSCud89431.
|
| CVE-2013-6963 |
Cross-site scripting (XSS) vulnerability in the registration component
in Cisco WebEx Training Center allows remote attackers to inject
arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36207.
|
| CVE-2013-6962 |
Cross-site scripting (XSS) vulnerability in the mobile-browser
subsystem in Cisco WebEx Meeting Center allows remote attackers to
inject arbitrary web script or HTML via a crafted URL, aka Bug ID
CSCul36228.
|
| CVE-2013-6961 |
Cross-site scripting (XSS) vulnerability in the Collaboration Partner
Access Console (CPAC) in Cisco WebEx Meeting Center allows remote
attackers to inject arbitrary web script or HTML via a crafted URL,
aka Bug ID CSCul36237.
|
| CVE-2013-6960 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx
Meeting Center allow remote attackers to inject arbitrary web script
or HTML via a crafted URL, aka Bug ID CSCul36248.
|
| CVE-2013-6957 |
Cross-site scripting (XSS) vulnerability in the web administrative
component in Juniper IDP allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors to the ACM web server.
|
| CVE-2013-6956 |
Cross-site scripting (XSS) vulnerability in the Secure Access Service
Web rewriting feature in Juniper Junos Pulse Secure Access Service
(aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4 before
7.4r6, and 8.0 before 8.0r1, when web rewrite is enabled, allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-6944 |
Cross-site scripting (XSS) vulnerability in the user interface in the
AAA TM vServer in Citrix NetScaler Application Delivery Controller
(ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before
10.1-118.7 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-6923 |
Multiple cross-site scripting (XSS) vulnerabilities in Seagate
BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote
attackers to inject arbitrary web script or HTML via the (1) fullname
parameter to admin/access_control_user_edit.php or (2) workname
parameter to admin/network_workgroup_domain.php.
|
| CVE-2013-6916 |
Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface
Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10
or Chrome is used, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-6915 |
Cross-site scripting (XSS) vulnerability in the system-administration
component in Cybozu Garoon before 3.7.2 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6914 |
Cross-site scripting (XSS) vulnerability in a calendar component in
Cybozu Garoon before 3.7.2 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6913 |
Cross-site scripting (XSS) vulnerability in a search component in
Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-6912 |
Cross-site scripting (XSS) vulnerability in a calendar component in
Cybozu Garoon before 3.7.2, when Internet Explorer 6 through 9 is
used, allows remote authenticated users to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-6911 |
Cross-site scripting (XSS) vulnerability in the bulletin-board
component in Cybozu Garoon before 3.7.2, when Internet Explorer or
Firefox is used, allows remote authenticated users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-6910 |
Cross-site scripting (XSS) vulnerability in Ajax components in Cybozu
Garoon before 3.7.0 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-6909 |
Cross-site scripting (XSS) vulnerability in a report component in
Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-6908 |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu
Garoon 3.x before 3.7.0 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-6907 |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu
Garoon 2.x and 3.x before 3.7.0 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6906 |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu
Garoon before 3.7.0, when Internet Explorer 6 through 8 is used,
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-6905 |
Cross-site scripting (XSS) vulnerability in a phone component in
Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used,
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-6904 |
Cross-site scripting (XSS) vulnerability in a note component in Cybozu
Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-6903 |
Cross-site scripting (XSS) vulnerability in a schedule component in
Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used,
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-6902 |
Cross-site scripting (XSS) vulnerability in the Space function in
Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-6901 |
Cross-site scripting (XSS) vulnerability in the Space function in
Cybozu Garoon before 3.7.0, when Firefox is used, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-6900 |
Cross-site scripting (XSS) vulnerability in the system-administration
component in Cybozu Garoon before 3.7.0 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6882 |
Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto
Forensic FieldStation with firmware 2013Oct15a and earlier allow (1)
remote attackers to inject arbitrary web script or HTML via the
username parameter in a login or (2) remote authenticated users to
inject arbitrary web script or HTML via unspecified form fields.
|
| CVE-2013-6870 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk
before 5.0.6 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-6858 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack
Dashboard (Horizon) 2013.2 and earlier allow local users to inject
arbitrary web script or HTML via an instance name to (1) "Volumes" or
(2) "Network Topology" page.
|
| CVE-2013-6853 |
Cross-site scripting (XSS) vulnerability in clickstream.js in Y!
Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and
2.5.9.2013418100420 for Windows, allows remote attackers to inject
arbitrary web script or HTML via a crafted URL that is stored by the
victim.
|
| CVE-2013-6837 |
Cross-site scripting (XSS) vulnerability in the setTimeout function in
js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows
remote attackers to inject arbitrary web script or HTML via a crafted
PATH_INTO to the default URI.
|
| CVE-2013-6819 |
Cross-site scripting (XSS) vulnerability in Performance Provider in
SAP NetWeaver allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-6816 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1)
JavaDumpService and (2) DataCollector servlets in SAP NetWeaver allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-6808 |
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in
ZendTo before 4.11-13 allows remote attackers to inject arbitrary web
script or HTML via a modified emailAddr field to pickup.php.
|
| CVE-2013-6804 |
Cross-site scripting (XSS) vulnerability in the Search module before
1.1.1 for Jamroom allows remote attackers to inject arbitrary web
script or HTML via the search_string parameter to
search/results/all/1/4.
|
| CVE-2013-6797 |
Cross-site request forgery (CSRF) vulnerability in
bluewrench-video-widget.php in the Blue Wrench Video Widget plugin
before 2.0.0 for WordPress allows remote attackers to hijack the
authentication of administrators for requests that embed arbitrary
URLs via the bw_url parameter in the bw-videos page to
wp-admin/admin.php, as demonstrated by embedding a URL to a JavaScript
file.
|
| CVE-2013-6794 |
Cross-site scripting (XSS) vulnerability in the Calendar module in
Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject
arbitrary web script or HTML via the Location field. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2013-6793 |
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar
module in Olat 7.8.0.1 (b20130821 N1) allow remote attackers to inject
arbitrary web script or HTML via the (1) event name or (2) date field.
|
| CVE-2013-6786 |
Cross-site scripting (XSS) vulnerability in Allegro RomPager before
4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174,
TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the
"forbidden author header" protection mechanism is bypassed, allows
remote attackers to inject arbitrary web script or HTML by requesting
a nonexistent URI in conjunction with a crafted HTTP Referer header
that is not properly handled in a 404 page. NOTE: there is no CVE for
a "URL redirection" issue that some sources list separately.
|
| CVE-2013-6780 |
Cross-site scripting (XSS) vulnerability in uploader.swf in the
Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote
attackers to inject arbitrary web script or HTML via the allowedDomain
parameter.
|
| CVE-2013-6746 |
Cross-site scripting (XSS) vulnerability in FileNet P8 Platform
Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM
FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content
Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-6745 |
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix
6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM
ESSO) 8.2 allows remote authenticated users to inject arbitrary web
script or HTML via crafted input to an unspecified dynamic web form.
|
| CVE-2013-6743 |
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM
Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote
authenticated users to inject arbitrary web script or HTML via vectors
involving an IMG element.
|
| CVE-2013-6738 |
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics
Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote
attackers to inject arbitrary web script or HTML via an invalid query
parameter in a response from an OAuth authorization endpoint.
|
| CVE-2013-6733 |
Cross-site scripting (XSS) vulnerability in the Web Application in the
Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-6732 |
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos
Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5,
10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows
remote attackers to inject arbitrary web script or HTML via an
unspecified parameter.
|
| CVE-2013-6729 |
Cross-site scripting (XSS) vulnerability in IBM QuickFile 1.0.0.0
before iFix 4 and 1.1.0.1 before iFix 3 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-6726 |
Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv
in IBM TRIRIGA Application Platform 3.2.x and 3.3.x before 3.3.1.2
allow remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-6725 |
Cross-site scripting (XSS) vulnerability in the Administrative Console
in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before
8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated
administrators to inject arbitrary web script or HTML via a crafted
URL.
|
| CVE-2013-6721 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Service
Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through
8.0.0.2 allows remote authenticated users to inject arbitrary web
script or HTML via vectors involving widgets.
|
| CVE-2013-6711 |
Cross-site scripting (XSS) vulnerability in the product-creation
administrative page in Cisco WebEx Sales Center allows remote
attackers to inject arbitrary web script or HTML via a crafted URL,
aka Bug ID CSCul25540.
|
| CVE-2013-6690 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface in the Assurance component in Cisco Prime Collaboration
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors, aka Bug IDs CSCui92643, CSCui94038, and
CSCui94161.
|
| CVE-2013-6674 |
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x
through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey
before 2.20 allows user-assisted remote attackers to inject arbitrary
web script or HTML via an e-mail message containing a data: URL in an
IFRAME element, a related issue to CVE-2014-2018.
|
| CVE-2013-6657 |
core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used
in Google Chrome before 33.0.1750.117, inserts the about:blank URL
during certain blocking of FORM elements within HTTP requests, which
allows remote attackers to bypass the Same Origin Policy and obtain
sensitive information via unspecified vectors.
|
| CVE-2013-6656 |
The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in
the XSS auditor in Blink, as used in Google Chrome before
33.0.1750.117, processes POST requests by using the body of a
redirecting page instead of the body of a redirect target, which
allows remote attackers to obtain sensitive information via
unspecified vectors.
|
| CVE-2013-6465 |
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE
Workbench 6.0.x allow remote authenticated users to inject arbitrary
web script or HTML via vectors related to task name html inputs.
|
| CVE-2013-6459 |
Cross-site scripting (XSS) vulnerability in the will_paginate gem
before 3.0.5 for Ruby allows remote attackers to inject arbitrary web
script or HTML via vectors involving generated pagination links.
|
| CVE-2013-6454 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10,
1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers
to inject arbitrary web script or HTML via a -o-link attribute.
|
| CVE-2013-6452 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10,
1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers
to inject arbitrary web script or HTML via crafted XSL in an SVG file.
|
| CVE-2013-6416 |
Cross-site scripting (XSS) vulnerability in the simple_format helper
in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails
4.x before 4.0.2 allows remote attackers to inject arbitrary web
script or HTML via a crafted HTML attribute.
|
| CVE-2013-6415 |
Cross-site scripting (XSS) vulnerability in the number_to_currency
helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby
on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to
inject arbitrary web script or HTML via the unit parameter.
|
| CVE-2013-6395 |
Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web
3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web
script or HTML via the host_regex parameter to the default URI, which
is processed by get_context.php.
|
| CVE-2013-6388 |
Cross-site scripting (XSS) vulnerability in the Color module in Drupal
7.x before 7.24 allows remote attackers to inject arbitrary web script
or HTML via vectors related to CSS.
|
| CVE-2013-6387 |
Cross-site scripting (XSS) vulnerability in the Image module in Drupal
7.x before 7.24 allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via the description
field.
|
| CVE-2013-6374 |
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer
plugin before 1.5.1 for Jenkins allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6348 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts
2.3.15.3 allow remote attackers to inject arbitrary web script or HTML
via the namespace parameter to (1) actionNames.action and (2)
showConfig.action in config-browser/.
|
| CVE-2013-6342 |
Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin
before 4.0.2 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the tb_tab_index parameter to
wp-admin/options-general.php.
|
| CVE-2013-6333 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in
MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo
Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in
AlgoWebApps 5.0.0, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6301, and
CVE-2013-6320.
|
| CVE-2013-6328 |
Cross-site scripting (XSS) vulnerability in the Web Content Manager
(WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x
through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before
8.0.0.1 CF09 allows remote attackers to inject arbitrary web script or
HTML via vectors involving IFRAME elements.
|
| CVE-2013-6327 |
Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM
Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before
1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, related to a "cross-frame scripting"
issue.
|
| CVE-2013-6323 |
Cross-site scripting (XSS) vulnerability in the Administration Console
in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x
before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual
Enterprise 7.x before 7.0.0.5, allows remote authenticated users to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-6322 |
Cross-site scripting (XSS) vulnerability in Sterling Order Management
in IBM Sterling Selling and Fulfillment Suite 8.0 before HF128 and 8.5
before HF93 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-6320 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in
MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo
Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in
AlgoWebApps 5.0.0, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6301, and
CVE-2013-6333.
|
| CVE-2013-6318 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in
MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo
Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in
AlgoWebApps 5.0.0, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-6314 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Enterprise
Records 4.5.1 before 4.5.1.7-IER-IF001 and Enterprise Records 5.1.1
before 5.1.1.1-IER-IF003 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6310 |
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1
before FP2 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-6307 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM
7.0 allows remote authenticated users to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-6301 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in
MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo
Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in
AlgoWebApps 5.0.0, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6320, and
CVE-2013-6333.
|
| CVE-2013-6300 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in
MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo
Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in
AlgoWebApps 5.0.0, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2013-6299, CVE-2013-6301, CVE-2013-6320, and
CVE-2013-6333.
|
| CVE-2013-6299 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in
MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo
Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in
AlgoWebApps 5.0.0, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2013-6300, CVE-2013-6301, CVE-2013-6320, and
CVE-2013-6333.
|
| CVE-2013-6289 |
Cross-site scripting (XSS) vulnerability in the Apache Solr for TYPO3
(solr) extension before 2.8.3 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6281 |
Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php
in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows
remote attackers to inject arbitrary web script or HTML via the "page"
parameter.
|
| CVE-2013-6280 |
Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit
plugin before 2.1.2 for WordPress allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6267 |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline
before 1.11.9 allow remote attackers to inject arbitrary web script or
HTML via the (1) box parameter to messaging/messagebox.php, cidToEdit
parameter to (2) adminregisteruser.php or (3)
admin_user_course_settings.php in admin/, (4) module_id parameter to
admin/module/module.php, or (5) offset parameter to
admin/right/profile_list.php.
|
| CVE-2013-6235 |
Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java
Application Monitor) 2.7 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) listenertype or (2)
currentlistener parameter to mondetail.jsp or ArraySQL parameter to
(3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6)
exceptions.jsp.
|
| CVE-2013-6233 |
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows
remote authenticated users to inject arbitrary web script or HTML via
the Description field in the "Short document metadata."
|
| CVE-2013-6232 |
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows
remote authenticated users to inject arbitrary web script or HTML via
a document note in the execution page.
|
| CVE-2013-6229 |
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail
Server 7.0.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) filter parameter to
index.php/mail/mail/listfoldermessages/searching/true/selectFolder/INBOX/resultContext/searchResultsTab5
or (2) mailId[] parameter to
index.php/mail/mail/movetofolder/fromFolder/INBOX/toFolder/INBOX.Trash.
NOTE: the view attachment message process vector is already covered by
CVE-2013-2585.
|
| CVE-2013-6224 |
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla
before 5.1.1.0 allow remote attackers to inject arbitrary web script
or HTML via (1) a name in the call administrator feature, (2)
unspecified vectors to the admins visitor information panel, or (3) a
text message in a chat session, which is saved in the archive section.
|
| CVE-2013-6222 |
Cross-site scripting (XSS) vulnerability in the Mobility Web Client
and Service Request Catalog (SRC) components in HP Service Manager
(SM) 7.21 and 9.x before 9.34 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6220 |
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i
(NNMi) 9.0, 9.10, and 9.20 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-6202 |
Multiple cross-site request forgery (CSRF) vulnerabilities in HP
Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote attackers to
hijack the authentication of unspecified victims for requests that (1)
insert XSS sequences or (2) execute arbitrary code.
|
| CVE-2013-6198 |
Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier
and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-6196 |
Cross-site scripting (XSS) vulnerability in HP Autonomy Ultraseek 5
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-6191 |
Cross-site scripting (XSS) vulnerability in HP Operations
Orchestration before 9 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-6178 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer
GRC 5.x before 5.4 SP1 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-6175 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC Document
Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and
4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition
Publish Engine, and Enterprise Edition Compuset Engine, allow remote
attackers to inject arbitrary web script or HTML via unspecified input
to a (1) xAdmin or (2) xDashboard form.
|
| CVE-2013-6168 |
Cross-site scripting (XSS) vulnerability in Zikula Application
Framework before 1.3.6 allows remote attackers to inject arbitrary web
script or HTML via the returnpage parameter to index.php.
|
| CVE-2013-6163 |
Multiple cross-site scripting (XSS) vulnerabilities in ProjeQtOr
(formerly Project'Or RIA) before 4.0.0 allow remote attackers to
inject arbitrary web script or HTML via the (1) type parameter to
view/parameter.php, (2) p1value parameter to view/main.php, or (3)
objectClass parameter to view/objectDetail.php.
|
| CVE-2013-6162 |
Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail
Server 3.1.1 allows remote attackers to inject arbitrary web script or
HTML via the body of an email.
|
| CVE-2013-6111 |
Cross-site scripting (XSS) vulnerability in the mod_pagespeed module
0.x, 1.0.22.7, 1.1.x, 1.24.1, 1.3.25.1 through 1.3.25.4, 1.4.26.1
through 1.4.26.4, 1.5.27.1 through 1.5.27.3, and 1.6.29.1 through
1.6.29.6 for the Apache HTTP Server allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-6074 |
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite
7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14 allows remote
attackers to inject arbitrary web script or HTML via an attached SVG
file.
|
| CVE-2013-6047 |
Multiple cross-site scripting (XSS) vulnerabilities in the site
creation interface in ikiwiki-hosting before 0.20131025 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-6044 |
The is_safe_url function in utils/http.py in Django 1.4.x before
1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme
as safe even if it is not HTTP or HTTPS, which might introduce
cross-site scripting (XSS) or other vulnerabilities into Django
applications that use this function, as demonstrated by "the login
view in django.contrib.auth.views" and the javascript: scheme.
|
| CVE-2013-6042 |
Cross-site scripting (XSS) vulnerability in filemanager/login.php in
the File Manager module in Softaculous Webuzo before 2.1.4 allows
remote attackers to inject arbitrary web script or HTML via the user
parameter.
|
| CVE-2013-6039 |
Multiple cross-site scripting (XSS) vulnerabilities in NagiosQL 3.2
SP2 allow remote attackers to inject arbitrary web script or HTML via
the txtSearch parameter to (1) admin/hostdependencies.php, (2)
admin/hosts.php, or other unspecified pages that allow search input,
related to the search functionality in functions/content_class.php.
|
| CVE-2013-6037 |
Cross-site scripting (XSS) vulnerability in index.php in Aker Secure
Mail Gateway 2.5.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the msg_id parameter.
|
| CVE-2013-6033 |
Multiple cross-site scripting (XSS) vulnerabilities on Lexmark W840
through LS.HA.P252, T64x before LS.ST.P344, C935dn through LC.JO.P091,
C920 through LS.TA.P152, C53x through LS.SW.P069, C52x through
LS.FA.P150, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250
through LE.PM.P126 printers allow remote authenticated users to inject
arbitrary web script or HTML by using (1) SNMP or (2) the Embedded Web
Server (EWS) to set the (a) Contact or (b) Location field.
|
| CVE-2013-6019 |
Cross-site scripting (XSS) vulnerability in Tyler Technologies TaxWeb
3.13.3.1 allows remote attackers to inject arbitrary web script or
HTML via the accountNum parameter to an unspecified component.
|
| CVE-2013-6017 |
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server
before 7.2 allows remote attackers to inject arbitrary web script or
HTML via the body of an e-mail message, as demonstrated by the SRC
attribute of an IFRAME element.
|
| CVE-2013-6010 |
Cross-site scripting (XSS) vulnerability in the Comment Attachment
plugin 1.0 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the "Attachment field title."
|
| CVE-2013-6005 |
Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0
allows remote attackers to inject arbitrary web script or HTML via
vectors related to the Cancel button.
|
| CVE-2013-5996 |
Multiple cross-site scripting (XSS) vulnerabilities in
shopping/payment.tpl components in LOCKON EC-CUBE 2.11.0 through
2.13.0 allow remote attackers to inject arbitrary web script or HTML
via crafted values.
|
| CVE-2013-5992 |
Cross-site scripting (XSS) vulnerability in the displaySystemError
function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through
2.11.5 allows remote attackers to inject arbitrary web script or HTML
by leveraging incorrect handling of error-message output.
|
| CVE-2013-5983 |
Multiple cross-site scripting (XSS) vulnerabilities in GuppY before
4.6.28 allow remote attackers to inject arbitrary web script or HTML
via the (1) "an" parameter to agenda.php or (2) cat parameter to
mobile/thread.php.
|
| CVE-2013-5977 |
Cross-site request forgery (CSRF) vulnerability in Cart66Product.php
in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote
attackers to hijack the authentication of administrators for requests
that (1) create or modify products or conduct cross-site scripting
(XSS) attacks via the (2) Product name or (3) Price description field
in a product save action via a request to wp-admin/admin.php.
|
| CVE-2013-5976 |
Cross-site scripting (XSS) vulnerability in the access policy logout
page (logout.inc) in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.1.0
through 11.3.0 allows remote attackers to inject arbitrary web script
or HTML via the LastMRH_Session cookie.
|
| CVE-2013-5968 |
Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through
12.51, and SiteMinder 6 Web Agents, allows remote attackers to inject
arbitrary web script or HTML via vectors involving a " (double quote)
character.
|
| CVE-2013-5966 |
Cross-site scripting (XSS) vulnerability in ZK Framework before 5.0.13
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-5964 |
Cross-site scripting (XSS) vulnerability in the administration page in
the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote
authenticated users with the "Administer flags" permission to inject
arbitrary web script or HTML via the flag title.
|
| CVE-2013-5956 |
Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php
in the Youtube Gallery (com_youtubegallery) component 3.4.0 for
Joomla! allows remote attackers to inject arbitrary web script or HTML
via the videofile parameter.
|
| CVE-2013-5955 |
Cross-site scripting (XSS) vulnerability in manage.php in the
PBBooking (com_pbbooking) component 2.4 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via the an arbitrary
parameter in an edit action to administrator/index.php.
|
| CVE-2013-5953 |
Multiple cross-site scripting (XSS) vulnerabilities in
tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar)
component 4.0.2, and possibly 4.8.5 and earlier, for Joomla! allow
remote attackers to inject arbitrary web script or HTML via the (1)
calid or (2) paletteDefault parameter in an editevent action to
index.php.
|
| CVE-2013-5952 |
Multiple cross-site scripting (XSS) vulnerabilities in the Freichat
(com_freichat) component, possibly 9.4 and earlier, for Joomla! allow
remote attackers to inject arbitrary web script or HTML via the (1) id
or (2) xhash parameter to client/chat.php or (3) toname parameter to
client/plugins/upload/upload.php.
|
| CVE-2013-5951 |
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer
2.1.3, when used as a component for Joomla!, allow remote attackers to
inject arbitrary web script or HTML via the PATH_INFO to (1)
application.js.php in scripts/ or (2) admin.php, (3) copy_move.php,
(4) functions.php, (5) header.php, or (6) upload.php in include/.
|
| CVE-2013-5943 |
Multiple cross-site scripting (XSS) vulnerabilities in Graphite before
0.9.11 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2013-5939 |
Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook
module for PHPCMS allow remote attackers to inject arbitrary web
script or HTML via the (1) list or (2) introduce parameter to
index.php.
|
| CVE-2013-5938 |
Cross-site scripting (XSS) vulnerability in the Click2Sell Suite
module 6.x-1.x for Drupal allows remote attackers to inject arbitrary
web script or HTML via a confirmation form.
|
| CVE-2013-5937 |
Cross-site request forgery (CSRF) vulnerability in the Click2Sell
Suite module 6.x-1.x for Drupal allows remote attackers to hijack the
authentication of administrators for requests that delete database
information via vectors involving the Drupal Form API.
|
| CVE-2013-5930 |
Cross-site scripting (XSS) vulnerability in search_residential.php in
Real Estate PHP Script allows remote attackers to inject arbitrary web
script or HTML via the bos parameter.
|
| CVE-2013-5918 |
Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in
the Platinum SEO plugin before 1.3.8 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the s parameter.
|
| CVE-2013-5916 |
Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco
Gateway plugin 2.0 for Wordpress, as used in the WP e-Commerce plugin,
allows remote attackers to inject arbitrary web script or HTML via the
QUERY_STRING.
|
| CVE-2013-5913 |
Cross-site scripting (XSS) vulnerability in the getRecommSearch
function in recommlist.php in OXID eShop before 4.6.7, Professional
and Community Edition 4.7.x before 4.7.8, and Enterprise Edition 5.x
before 5.0.8 allows remote attackers to inject arbitrary web script or
HTML via the searchrecomm parameter.
|
| CVE-2013-5911 |
Cross-site scripting (XSS) vulnerability in devform.php in Tenable
SecurityCenter 4.6 through 4.7 allows remote attackers to inject
arbitrary web script or HTML via the message parameter.
|
| CVE-2013-5855 |
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not
perform appropriate encoding when a (1) <h:outputText> tag or (2) EL
expression is used after a scriptor style block, which allows remote
attackers to conduct cross-site scripting (XSS) attacks via
application-specific vectors.
|
| CVE-2013-5749 |
Cross-site scripting (XSS) vulnerability in
management/prioritize_planning.php in SimpleRisk before 20130916-001
allows remote attackers to inject arbitrary web script or HTML via the
new_project parameter.
|
| CVE-2013-5744 |
Cross-site scripting (XSS) vulnerability in Feng Office 2.3.2-rc and
earlier allows remote attackers to inject arbitrary web script or HTML
via an arbitrary ref_XXX parameter.
|
| CVE-2013-5739 |
The default configuration of WordPress before 3.6.1 does not prevent
uploads of .swf and .exe files, which might make it easier for remote
authenticated users to conduct cross-site scripting (XSS) attacks via
a crafted file, related to the get_allowed_mime_types function in
wp-includes/functions.php.
|
| CVE-2013-5738 |
The get_allowed_mime_types function in wp-includes/functions.php in
WordPress before 3.6.1 does not require the unfiltered_html capability
for uploads of .htm and .html files, which might make it easier for
remote authenticated users to conduct cross-site scripting (XSS)
attacks via a crafted file.
|
| CVE-2013-5714 |
Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php
in the VideoWhisper Live Streaming Integration plugin 4.25.3 and
possibly earlier for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) name or (2) message
parameter. NOTE: some of these details are obtained from third party
information.
|
| CVE-2013-5711 |
Cross-site scripting (XSS) vulnerability in
admin/walkthrough/walkthrough.php in the Design Approval System plugin
before 3.7 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the step parameter.
|
| CVE-2013-5707 |
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill
Learning Management System (LMS) 6.8 allow remote attackers to inject
arbitrary web script or HTML via crafted input containing a %22
sequence, a different issue than CVE-2013-3604.
|
| CVE-2013-5706 |
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill
Learning Management System (LMS) 6.8 allow remote attackers to inject
arbitrary web script or HTML via vectors related to error messages and
(1) crafted event attributes or (2) > (greater than) characters that
are optional within a browser's HTML implementation, a different issue
than CVE-2013-3603.
|
| CVE-2013-5702 |
Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in
WatchGuard WSM and Fireware before 11.8 allow remote attackers to
inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2013-5698 |
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and
Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7,
7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated
users to inject arbitrary web script or HTML via a delivery=view
action, aka Bug ID 26373, a different vulnerability than
CVE-2013-3106.
|
| CVE-2013-5695 |
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before
4.4.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) id parameter to admin/auditlog/, (2) PATH_INFO to
info/host/ or (3) viewport/, (4) back parameter to login, or (5)
"from" parameter to status/service/recheck.
|
| CVE-2013-5693 |
Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5
allows remote attackers to inject arbitrary web script or HTML via the
model parameter to index.php/admin/editor.
|
| CVE-2013-5690 |
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange
AppSuite before 7.2.2 allow remote authenticated users to inject
arbitrary web script or HTML via (1) content with the text/xml MIME
type or (2) the Status comment field of an appointment.
|
| CVE-2013-5672 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers
to hijack the authentication of administrators for requests that (1)
add a testimonial via an iNIC_testimonial_save action; (2) add a
listing template via an iNIC_testimonial_save_listing_template action;
(3) add a widget template via an iNIC_testimonial_save_widget action;
insert cross-site scripting (XSS) sequences via the (4) project_name,
(5) project_url, (6) client_name, (7) client_city, (8) client_state,
(9) description, (10) tags, (11) video_url, or (12) is_featured, (13)
title, (14) widget_title, (15) no_of_testimonials, (16)
filter_by_country, (17) filter_by_tags, or (18) widget_template
parameter to wp-admin/admin-ajax.php.
|
| CVE-2013-5670 |
Cross-site scripting (XSS) vulnerability in spell-check-savedicts.php
in the htmlarea SpellChecker module, as used in Serendipity before
1.7.3 and possibly other products, allows remote attackers to inject
arbitrary web script or HTML via the to_r_list parameter.
|
| CVE-2013-5664 |
Cross-site scripting (XSS) vulnerability in the web-based
device-management API browser in Palo Alto Networks PAN-OS before
4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject
arbitrary web script or HTML via crafted data, aka Ref ID 50908.
|
| CVE-2013-5649 |
Multiple cross-site scripting (XSS) vulnerabilities in Juniper Junos
Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.1 before
7.1r15, 7.2 before 7.2r11, 7.3 before 7.3r6, and 7.4 before 7.4r3
allow (1) remote attackers to inject arbitrary web script or HTML via
vectors involving login pages, and allow (2) remote authenticated
users to inject arbitrary web script or HTML via vectors involving a
support page.
|
| CVE-2013-5646 |
Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git
allows remote authenticated users to inject arbitrary web script or
HTML via the Name field of an addressbook group.
|
| CVE-2013-5645 |
Multiple cross-site scripting (XSS) vulnerabilities in Roundcube
webmail before 0.9.3 allow user-assisted remote attackers to inject
arbitrary web script or HTML via the body of a message visited in (1)
new or (2) draft mode, related to compose.inc; and (3) might allow
remote authenticated users to inject arbitrary web script or HTML via
an HTML signature, related to save_identity.inc.
|
| CVE-2013-5612 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before
26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to
inject arbitrary web script or HTML by leveraging a Same Origin Policy
violation triggered by lack of a charset parameter in a Content-Type
HTTP header.
|
| CVE-2013-5588 |
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the step parameter to install/index.php or (2) the id
parameter to cacti/host.php.
|
| CVE-2013-5587 |
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x
before 4.0.13, when MakeClicky is configured, allows remote attackers
to inject arbitrary web script or HTML via a URL in a ticket. NOTE:
this issue has been SPLIT from CVE-2013-3371 due to different affected
versions.
|
| CVE-2013-5586 |
Cross-site scripting (XSS) vulnerability in wikka.php in WikkaWiki
before 1.3.4-p1 allows remote attackers to inject arbitrary web script
or HTML via the wakka parameter to sql/.
|
| CVE-2013-5583 |
Cross-site scripting (XSS) vulnerability in
libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote
attackers to inject arbitrary web script or HTML via the lang
parameter.
|
| CVE-2013-5573 |
Cross-site scripting (XSS) vulnerability in the default markup
formatter in Jenkins 1.523 allows remote attackers to inject arbitrary
web script or HTML via the Description field in the user
configuration.
|
| CVE-2013-5570 |
Cross-site scripting (XSS) vulnerability in the Javascript and CSS
Optimizer extension before 1.1.14 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-5563 |
Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp
in Cisco Security Monitoring, Analysis and Response System (CS-MARS)
allows remote attackers to inject arbitrary web script or HTML via the
isnowLatency parameter, aka Bug ID CSCul16173.
|
| CVE-2013-5541 |
Cross-site scripting (XSS) vulnerability in the file-upload interface
in Cisco Identity Services Engine (ISE) allows remote authenticated
users to inject arbitrary web script or HTML via a crafted filename,
aka Bug ID CSCui67495.
|
| CVE-2013-5524 |
Cross-site scripting (XSS) vulnerability in the troubleshooting page
in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote
attackers to inject arbitrary web script or HTML via an unspecified
parameter, aka Bug ID CSCug77655.
|
| CVE-2013-5523 |
The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and
earlier does not properly restrict use of IFRAME elements, which makes
it easier for remote attackers to conduct clickjacking attacks and
unspecified other attacks via a crafted web site, related to a
"cross-frame scripting (XFS)" issue, aka Bug ID CSCui82666.
|
| CVE-2013-5519 |
Cross-site scripting (XSS) vulnerability in the management interface
on Cisco Wireless LAN Controller (WLC) devices allows remote attackers
to inject arbitrary web script or HTML via a crafted URL, aka Bug ID
CSCuf77810.
|
| CVE-2013-5505 |
Cross-site scripting (XSS) vulnerability in an administration page in
Cisco Identity Services Engine (ISE) allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug ID
CSCui30275.
|
| CVE-2013-5504 |
Cross-site scripting (XSS) vulnerability in the Mobile Device
Management (MDM) portal in Cisco Identity Services Engine (ISE) allows
remote attackers to inject arbitrary web script or HTML via an
unspecified parameter, aka Bug ID CSCui30266.
|
| CVE-2013-5501 |
Cross-site scripting (XSS) vulnerability in the oraservice page in
Cisco MediaSense allows remote attackers to inject arbitrary web
script or HTML via an unspecified parameter, aka Bug ID CSCuj23328.
|
| CVE-2013-5500 |
Multiple cross-site scripting (XSS) vulnerabilities in the oraadmin
service page in Cisco MediaSense allow remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka Bug IDs
CSCuj23320, CSCuj23324, CSCuj23333, and CSCuj23338.
|
| CVE-2013-5495 |
Cross-site scripting (XSS) vulnerability in the web framework in the
Application Server in Cisco Unified MeetingPlace allows remote
attackers to inject arbitrary web script or HTML via an unspecified
parameter, aka Bug ID CSCui44681.
|
| CVE-2013-5483 |
Cross-site scripting (XSS) vulnerability in bookmarklet.jsp in Cisco
SocialMiner allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, aka Bug ID CSCuh73868.
|
| CVE-2013-5449 |
Cross-site scripting (XSS) vulnerability in workingSet.jsp in IBM
Eclipse Help System (IEHS), as used in the installable InfoCenter
component in IBM FileNet Content Manager 4.5.1, 5.0.0, 5.1.0, and
5.2.0, allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2013-5448 |
Cross-site scripting (XSS) vulnerability in the Right Click Plugin
context menus in IBM Security QRadar SIEM 7.1 and 7.2 before 7.2 MR1
Patch 1 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-5442 |
Cross-site scripting (XSS) vulnerability in the Local Management
Interface (LMI) in IBM Security Network Protection on XGS 5100 devices
with firmware 5.1 before 5.1.0.6 and 5.1.1 before 5.1.1.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-5438 |
Cross-site scripting (XSS) vulnerability in the web server in IBM Flex
System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-5425 |
Cross-site scripting (XSS) vulnerability in the Administration Console
in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before
7.0.0.4 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2013-5421 |
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix
6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM
ESSO) 8.2 allows remote attackers to inject arbitrary web script or
HTML via crafted input to an unspecified dynamic web form.
|
| CVE-2013-5418 |
Cross-site scripting (XSS) vulnerability in the Administrative console
in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0
before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-5417 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application
Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before
8.5.5.1 allows remote attackers to inject arbitrary web script or HTML
via HTTP response data.
|
| CVE-2013-5406 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling
B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified parameters, leading to improper interaction with the
Windows MHTML protocol handler.
|
| CVE-2013-5405 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling
B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified parameters.
|
| CVE-2013-5404 |
Cross-site scripting (XSS) vulnerability in the search implementation
in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before
3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team
Concert, Rational Requirements Composer, and other products, allows
remote authenticated users to inject arbitrary web script or HTML via
vectors involving an IFRAME element.
|
| CVE-2013-5402 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management, Maximo Asset Management Essentials, Maximo for Government,
Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life
Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x
through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5
before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3
IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for
IT, Tivoli Service Request Manager, Maximo Service Desk, and Change
and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12,
7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-5390 |
Cross-site scripting (XSS) vulnerability in the monitoring console in
IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-5389 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3
before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, aka SPR
PTHN9AYK2X.
|
| CVE-2013-5388 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3
before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, aka SPR
PTHN9AYK5F.
|
| CVE-2013-5379 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x
before 7.0.0.2 CF25 and 8.x before 8.0.0.1 CF8 allows remote
authenticated users to inject arbitrary web script or HTML by
leveraging improper tagging functionality.
|
| CVE-2013-5378 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.x
before 8.0.0.1 CF8 allows remote authenticated users to inject
arbitrary web script or HTML by leveraging incorrect IBM Connections
integration.
|
| CVE-2013-5376 |
Cross-site scripting (XSS) vulnerability in IBM Storwize V7000 Unified
1.3.x and 1.4.x before 1.4.2.0 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors, related
to a "cross frame scripting" attack against an administrative user.
|
| CVE-2013-5326 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0
before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and
10 before Update 12, when the CFIDE directory is available, allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors related to the logviewer directory.
|
| CVE-2013-5323 |
Cross-site scripting (XSS) vulnerability in the Static Info Tables
(static_info_tables) extension before 2.3.1 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-5320 |
Cross-site scripting (XSS) vulnerability in Forums/EditPost.aspx in
mojoPortal before 2.3.9.8 allows remote attackers to inject arbitrary
web script or HTML via the txtSubject parameter.
|
| CVE-2013-5319 |
Cross-site scripting (XSS) vulnerability in
secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in
Atlassian JIRA before 6.0.5 allows remote attackers to inject
arbitrary web script or HTML via the name parameter to
secure/admin/user/DeleteUser!default.jspa.
|
| CVE-2013-5317 |
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows
remote authenticated users to inject arbitrary web script or HTML via
the mode parameter to cms/index.php.
|
| CVE-2013-5315 |
Cross-site scripting (XSS) vulnerability in the Resource Manager in
the MEE submodule (mee.module) in the Scald module 6.x-1.x before
6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote
attackers to inject arbitrary web script or HTML via the atom title, a
different vector than CVE-2013-4174.
|
| CVE-2013-5314 |
Cross-site scripting (XSS) vulnerability in
serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
serendipity[htmltarget] parameter.
|
| CVE-2013-5312 |
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech
phpVID 1.2.3 allow remote attackers to inject arbitrary web script or
HTML via the (1) n parameter to browse_videos.php or the (2) cat
parameter to groups.php.
|
| CVE-2013-5309 |
Cross-site scripting (XSS) vulnerability in
install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and
earlier, when registering a new user, allows remote attackers to
inject arbitrary web script or HTML via a custom profile field to
index.php. NOTE: some of these details are obtained from third party
information.
|
| CVE-2013-5308 |
Cross-site scripting (XSS) vulnerability in the RealURL Management
(realurlmanagement) extension 0.3.4 and earlier for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-5307 |
Cross-site scripting (XSS) vulnerability in the Faceted Search
(ke_search) extension before 1.4.1 for TYPO3 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-5305 |
Cross-site scripting (XSS) vulnerability in the Store Locator
(locator) extension before 3.1.5 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-5300 |
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open
Source Security Information Management (OSSIM) before 4.3.0 allow
remote attackers to inject arbitrary web script or HTML via the
withoutmenu parameter to (1) vulnmeter/index.php or (2)
vulnmeter/sched.php; the (3) section parameter to
av_inventory/task_edit.php; the (4) profile parameter to
nfsen/rrdgraph.php; or the (5) scan_server or (6) targets parameter to
vulnmeter/simulate.php.
|
| CVE-2013-5223 |
Multiple cross-site scripting (XSS) vulnerabilities in D-Link
DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject
arbitrary web script or HTML via the (1) ntpServer1 parameter to
sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3)
todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName
parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst
parameter in a remove action to scoutflt.cmd, (8) groupName parameter
to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi,
(10) fltName parameter to scinflt.cmd, (11) PolicyName in an add
action or (12) rmLst parameter in a remove action to prmngr.cmd, (13)
ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15)
smbDirName parameter to samba.cgi, or (16) wlSsid parameter to
wlcfg.wl.
|
| CVE-2013-5222 |
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for
Server 10.1 allow remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-5218 |
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with
software 2.1.11 allows remote attackers to inject arbitrary web script
or HTML via a crafted DHCP Host Name option, which is not properly
handled during rendering of the DHCP table in wlanAccess.asp.
|
| CVE-2013-5215 |
Cross-site scripting (XSS) vulnerability in the web interface "WiFi
scan" option in FOSCAM Wireless IP Cameras allows remote attackers to
inject arbitrary web script or HTML via the SSID.
|
| CVE-2013-5210 |
Cross-site scripting (XSS) vulnerability in the GUI login page in
ADTRAN AOS before R10.8.1 on the NetVanta 7100 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-5151 |
Mobile Safari in Apple iOS before 7 does not prevent HTML
interpretation of a document served with a text/plain content type,
which allows remote attackers to conduct cross-site scripting (XSS)
attacks by uploading a file.
|
| CVE-2013-5131 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before
7 allows remote attackers to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2013-5129 |
Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple
iOS before 7 allow user-assisted remote attackers to inject arbitrary
web script or HTML via vectors involving a (1) drag-and-drop or (2)
copy-and-paste operation.
|
| CVE-2013-5118 |
Cross-site scripting (XSS) vulnerability in the Good for Enterprise
app before 2.2.4.1659 for iOS allows remote attackers to inject
arbitrary web script or HTML via an HTML e-mail message.
|
| CVE-2013-5108 |
Multiple cross-site scripting (XSS) vulnerabilities in the xn function
in RockMongo 1.1.5 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) db parameter on the login
page or (2) username parameter in a login.index action to index.php
and other unspecified parameters.
|
| CVE-2013-5100 |
Cross-site scripting (XSS) vulnerability in the Static Methods since
2007 (div2007) extension before 0.10.2 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, related to the t3lib_div::quoteJSvalue function.
|
| CVE-2013-5099 |
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS
0.9.1, when comments are enabled, allows remote attackers to inject
arbitrary web script or HTML via the Name field. NOTE: some sources
have reported that comments.php is vulnerable, but certain functions
from comments.php are used by article.php.
|
| CVE-2013-5098 |
Cross-site scripting (XSS) vulnerability in admin/admin.php in the
Download Monitor plugin before 3.3.6.2 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the sort
parameter, a different vulnerability than CVE-2013-3262.
|
| CVE-2013-5095 |
Cross-site scripting (XSS) vulnerability in the web-based interface in
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance
and in other contexts, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, aka PR 884469.
|
| CVE-2013-5094 |
Cross-site scripting (XSS) vulnerability in index.exp in McAfee
Vulnerability Manager 7.5 allows remote attackers to inject arbitrary
web script or HTML via the cert_cn cookie parameter.
|
| CVE-2013-5092 |
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in
AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2013-5072 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access in
Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update
2 and 3 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL, aka "OWA XSS Vulnerability."
|
| CVE-2013-5042 |
Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR
1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team
Foundation Server 2013, allows remote attackers to inject arbitrary
web script or HTML via crafted Forever Frame transport protocol data,
aka "SignalR XSS Vulnerability."
|
| CVE-2013-5020 |
Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in
MiniBB before 3.0.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) forum_name, (2) forum_group, (3)
forum_icon, or (4) forum_desc parameter. NOTE: the whatus vector is
already covered by CVE-2008-2066.
|
| CVE-2013-5013 |
Multiple cross-site scripting (XSS) vulnerabilities in the management
console on the Symantec Web Gateway (SWG) appliance before 5.2 allow
remote attackers to inject arbitrary web script or HTML via (1)
vectors involving PHP scripts and (2) unspecified other vectors.
|
| CVE-2013-5005 |
Multiple cross-site scripting (XSS) vulnerabilities in
ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow
remote attackers to inject arbitrary web script or HTML via the (1)
m_target_class_name, (2) m_target_method_name, or (3)
m_request_context_params parameters.
|
| CVE-2013-5002 |
Cross-site scripting (XSS) vulnerability in
libraries/schema/Export_Relation_Schema.class.php in phpMyAdmin 3.5.x
before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted pageNumber
value to schema_export.php.
|
| CVE-2013-5001 |
Cross-site scripting (XSS) vulnerability in
libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php
in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users
to inject arbitrary web script or HTML via a crafted object name
associated with a TextLinkTransformationPlugin link.
|
| CVE-2013-4997 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
3.5.x before 3.5.8.2 allow remote attackers to inject arbitrary web
script or HTML via vectors involving a JavaScript event in (1) an
anchor identifier to setup/index.php or (2) a chartTitle (aka chart
title) value.
|
| CVE-2013-4996 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers
to inject arbitrary web script or HTML via vectors involving (1) a
crafted database name, (2) a crafted user name, (3) a crafted logo URL
in the navigation panel, (4) a crafted entry in a certain proxy list,
or (5) crafted content in a version.json file.
|
| CVE-2013-4995 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before
3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to
inject arbitrary web script or HTML via a crafted SQL query that is
not properly handled during the display of row information.
|
| CVE-2013-4954 |
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in
the Genetech Solutions Pie-Register plugin before 1.31 for WordPress,
when "Allow New Registrations to set their own Password" is enabled,
allow remote attackers to inject arbitrary web script or HTML via the
(1) pass1 or (2) pass2 parameter in a register action. NOTE: some of
these details are obtained from third party information.
|
| CVE-2013-4951 |
Multiple cross-site scripting (XSS) vulnerabilities in Mintboard 0.3
allow remote attackers to inject arbitrary web script or HTML via the
(1) name or (2) pass parameter in views/login.php or (3) name or (4)
pass parameter in views/signup.php.
|
| CVE-2013-4950 |
Cross-site scripting (XSS) vulnerability in view.php in Machform 2
allows remote attackers to inject arbitrary web script or HTML via the
element_2 parameter.
|
| CVE-2013-4946 |
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service
Desk Express (SDE) 10.2.1.95 allow remote attackers to inject
arbitrary web script or HTML via the (1) SelTab parameter to
QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3)
HelpPage parameter to commonhelp.aspx.
|
| CVE-2013-4944 |
Cross-site scripting (XSS) vulnerability in the BuddyPress Extended
Friendship Request plugin before 1.0.2 for WordPress, when the "Friend
Connections" component is enabled, allows remote attackers to inject
arbitrary web script or HTML via the friendship_request_message
parameter to wp-admin/admin-ajax.php. NOTE: some of these details are
obtained from third party information.
|
| CVE-2013-4942 |
Cross-site scripting (XSS) vulnerability in flashuploader.swf in the
Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in
Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x
before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote
attackers to inject arbitrary web script or HTML via a crafted string
in a URL.
|
| CVE-2013-4941 |
Cross-site scripting (XSS) vulnerability in uploader.swf in the
Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in
Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x
before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote
attackers to inject arbitrary web script or HTML via a crafted string
in a URL.
|
| CVE-2013-4940 |
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility
component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10,
2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x
before 2.5.1, and other products, allows remote attackers to inject
arbitrary web script or HTML via a crafted string in a URL. NOTE: this
vulnerability exists because of a CVE-2013-4939 regression.
|
| CVE-2013-4939 |
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility
component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through
2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5,
2.5.x before 2.5.1, and other products, allows remote attackers to
inject arbitrary web script or HTML via a crafted string in a URL.
|
| CVE-2013-4899 |
Cross-site scripting (XSS) vulnerability in Twilight CMS 5.17 and
possibly earlier allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO to the gallery/ page.
|
| CVE-2013-4889 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
index.php in Digital Signage Xibo 1.4.2 allow remote attackers to
hijack the authentication of administrators for requests that (1) add
a new administrator via the AddUser action or (2) conduct cross-site
scripting (XSS) attacks, as demonstrated by CVE-2013-4888.
|
| CVE-2013-4888 |
Cross-site scripting (XSS) vulnerability in index.php in Digital
Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web
script or HTML via the layout parameter in the layout page.
|
| CVE-2013-4884 |
Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0
allows remote attackers to inject arbitrary web script or HTML via
UTF-7 encoded sequences in a server response, which is not properly
handled in the SuperScan HTML report.
|
| CVE-2013-4883 |
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy
Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee
Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary
web script or HTML via the (1) instanceId parameter
core/loadDisplayType.do; (2) instanceId or (3) monitorUrl parameter to
console/createDashboardContainer.do; uid parameter to (4)
ComputerMgmt/sysDetPanelBoolPie.do or (5)
ComputerMgmt/sysDetPanelSummary.do; (6) uid, (7)
orion.user.security.token, or (8) ajaxMode parameter to
ComputerMgmt/sysDetPanelQry.do; or (9) uid, (10)
orion.user.security.token, or (11) ajaxMode parameter to
ComputerMgmt/sysDetPanelSummary.do.
|
| CVE-2013-4880 |
Cross-site scripting (XSS) vulnerability in
core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0
RC2 and earlier allows remote attackers to inject arbitrary web script
or HTML via the module parameter.
|
| CVE-2013-4845 |
Cross-site scripting (XSS) vulnerability on HP Officejet Pro 8500 (aka
A909) All-in-One printers allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-4842 |
Cross-site scripting (XSS) vulnerability in HP Integrated Lights-Out 4
(iLO4) with firmware before 1.32 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4833 |
Cross-site scripting (XSS) vulnerability in HP Service Manager 9.30
through 9.32 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-4815 |
Cross-site scripting (XSS) vulnerability in the web interface in HP
ArcSight Enterprise Security Manager (ESM) before 5.5 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-4814 |
Cross-site scripting (XSS) vulnerability in HP XP P9000 Command View
Advanced Edition Suite Software 7.x before 7.5.0-02 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-4802 |
Cross-site scripting (XSS) vulnerability in HP Application Lifecycle
Management (ALM) Quality Center before 11.51 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors, aka
ZDI-CAN-1565.
|
| CVE-2013-4795 |
Cross-site scripting (XSS) vulnerability in the Submitters list in
Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7.12 allows remote
attackers to inject arbitrary web script or HTML via a user full name.
|
| CVE-2013-4779 |
Cross-site scripting (XSS) vulnerability in core/handleTw.php on the
Siemens Enterprise OpenScape Branch appliance and OpenScape Session
Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0,
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-4759 |
Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia
Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS
allow remote attackers to inject arbitrary web script or HTML via the
(1) username, (2) fullname, or (3) email parameter to
magnoliaPublic/demo-project/members-area/registration.html.
|
| CVE-2013-4754 |
Multiple cross-site scripting (XSS) vulnerabilities in Owl Intranet
Knowledgebase 1.10 allow remote authenticated users to inject
arbitrary web script or HTML via (1) the Search field to browse.php or
(2) the Title field to prefs.php.
|
| CVE-2013-4753 |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline
1.11.9 and earlier allow remote authenticated users to inject
arbitrary web script or HTML via (1) the Search field in an inbox
action to messaging/messagebox.php, (2) the "First name" field to
auth/profile.php, or (3) the Speakers field in an rqAdd action to
calendar/agenda.php.
|
| CVE-2013-4749 |
Cross-site scripting (XSS) vulnerability in the UserTask Center,
Messaging (sys_messages) extension 1.1.0 and earlier for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-4747 |
Cross-site scripting (XSS) vulnerability in the Accessible browse
results for indexed search (accessible_is_browse_results) extension
1.2.1 and earlier for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4746 |
Cross-site scripting (XSS) vulnerability in the My quiz and poll
(myquizpoll) extension before 2.0.6 for TYPO3 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4744 |
Cross-site scripting (XSS) vulnerability in the PHPUnit extension
before 3.5.15 for TYPO3 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-4722 |
Multiple cross-site scripting (XSS) vulnerabilities in
Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a,
6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allow
remote attackers to inject arbitrary web script or HTML via the (1)
username, (2) url, (3) qstr parameter.
|
| CVE-2013-4716 |
Cross-site scripting (XSS) vulnerability in Tattyan HP TOWN 5_9_3 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the query string.
|
| CVE-2013-4714 |
Cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware 6
LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x
before 11.1 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-4713 |
Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk
with firmware before 1.05e1-2.0.5 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4711 |
Cross-site scripting (XSS) vulnerability in Accela BizSearch 3.2 on
Linux and Solaris allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-4705 |
Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows
remote attackers to inject arbitrary web script or HTML by leveraging
UTF-8 encoding.
|
| CVE-2013-4704 |
Cross-site scripting (XSS) vulnerability in ChamaNet ChamaCargo 7.0000
and earlier allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-4703 |
Cross-site scripting (XSS) vulnerability in the top-page customization
feature in Cybozu Office before 9.3.1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4676 |
Multiple cross-site scripting (XSS) vulnerabilities in Symantec Backup
Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allow remote
attackers to inject arbitrary web script or HTML via vectors involving
a (1) custom-reports generation page, (2) Storage Devices creation
page, or (3) jobs creation page in the management console; or (4) a
Backup Exec server-management page in the beutility console.
|
| CVE-2013-4674 |
Cross-site scripting (XSS) vulnerability in the Web Email Protection
component in Symantec Encryption Management Server (formerly Symantec
PGP Universal Server) before 3.3.0 MP2 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted encrypted
e-mail attachment.
|
| CVE-2013-4670 |
Multiple cross-site scripting (XSS) vulnerabilities in the management
console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-4653 |
Multiple cross-site scripting (XSS) vulnerabilities in the signin
functionality of ics in MyTeamwork services in Alcatel-Lucent
Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated
Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced
Communication Server before 9.1, and OmniTouch 8400 Instant
Communications Suite before 6.7.3 (1) allow remote attackers to inject
arbitrary web script or HTML via a crafted URL that results in a
reflected XSS or (2) allow user-assisted remote attackers to inject
arbitrary web script or HTML via a user's personal bookmark entry that
results in a stored XSS via unspecified vectors.
|
| CVE-2013-4649 |
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before
6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary
web script or HTML via the __dnnVariable parameter to the default URI.
|
| CVE-2013-4626 |
Cross-site scripting (XSS) vulnerability in the BackWPup plugin before
3.0.13 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the tab parameter to wp-admin/admin.php.
|
| CVE-2013-4625 |
Cross-site scripting (XSS) vulnerability in
files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the package parameter.
|
| CVE-2013-4624 |
Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM
6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web
script or HTML via (1) the site parameter to engines/manager.jsp, (2)
the searchString parameter to administration/ in a search action, or
the (3) username, (4) firstName, (5) lastName, (6) email, or (7)
organization field to administration/ in a users action.
|
| CVE-2013-4620 |
Cross-site scripting (XSS) vulnerability in
interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows
remote attackers to inject arbitrary web script or HTML via the note
parameter.
|
| CVE-2013-4612 |
Multiple cross-site scripting (XSS) vulnerabilities in REDCap before
5.1.0 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors involving different modules.
|
| CVE-2013-4608 |
Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows
remote attackers to inject arbitrary web script or HTML via vectors
involving the Graphical Data View & Descriptive Stats page.
|
| CVE-2013-4600 |
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms
before 8.5.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) title parameter to
system/workplace/views/admin/admin-main.jsp or the (2)
requestedResource parameter to system/login/index.html.
|
| CVE-2013-4590 |
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before
8.0.0-RC10 allows attackers to obtain "Tomcat internals" information
by leveraging the presence of an untrusted web application with a
context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing
an external entity declaration in conjunction with an entity
reference, related to an XML External Entity (XXE) issue.
|
| CVE-2013-4574 |
Cross-site scripting (XSS) vulnerability in the TimeMediaHandler
extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x
before 1.22.1 allows remote attackers to inject arbitrary web script
or HTML via vectors related to videos.
|
| CVE-2013-4573 |
Cross-site scripting (XSS) vulnerability in the ZeroRatedMobileAccess
extension for MediaWiki 1.19.x before 1.19.9, 1.20.x before 1.20.8,
and 1.21.x before 1.21.3 allows remote attackers to inject arbitrary
web script or HTML via the "to" parameter to index.php.
|
| CVE-2013-4568 |
Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki
before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows
remote attackers to conduct cross-site scripting (XSS) attacks via
certain non-ASCII characters in CSS, as demonstrated using variations
of "expression" containing (1) full width characters or (2) IPA
extensions, which are converted and rendered by Internet Explorer.
|
| CVE-2013-4567 |
Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki
before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows
remote attackers to conduct cross-site scripting (XSS) attacks via a
\b (backspace) character in CSS.
|
| CVE-2013-4556 |
Cross-site scripting (XSS) vulnerability in the author page
(prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x
before 3.0.12 allows remote attackers to inject arbitrary web script
or HTML via the url_site parameter.
|
| CVE-2013-4525 |
Cross-site scripting (XSS) vulnerability in
mod/quiz/report/responses/responses_table.php in Moodle through
2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before
2.5.3 allows remote authenticated users to inject arbitrary web script
or HTML via an answer to a text-based quiz question.
|
| CVE-2013-4523 |
Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle
through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x
before 2.5.3 allows remote authenticated users to inject arbitrary web
script or HTML via a crafted message.
|
| CVE-2013-4519 |
Multiple cross-site scripting (XSS) vulnerabilities in Review Board
1.6.x before 1.6.21 and 1.7.x before 1.7.17 allow remote attackers to
inject arbitrary web script or HTML via the (1) Branch field or (2)
caption of an uploaded file.
|
| CVE-2013-4507 |
Cross-site scripting (XSS) vulnerability in CollectiveAccess
Providence and Pawtucket before 1.3.1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4503 |
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper
module for Drupal allows remote authenticated users with the
"administer taxonomy" permission to inject arbitrary web script or
HTML via vectors related to options.
|
| CVE-2013-4499 |
Cross-site scripting (XSS) vulnerability in the Bean module 7.x-1.x
before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary
web script or HTML via the bean title.
|
| CVE-2013-4492 |
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n
gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary
web script or HTML via a crafted I18n::MissingTranslationData.new
call.
|
| CVE-2013-4491 |
Cross-site scripting (XSS) vulnerability in
actionpack/lib/action_view/helpers/translation_helper.rb in the
internationalization component in Ruby on Rails 3.x before 3.2.16 and
4.x before 4.0.2 allows remote attackers to inject arbitrary web
script or HTML via a crafted string that triggers generation of a
fallback string by the i18n gem.
|
| CVE-2013-4460 |
Cross-site scripting (XSS) vulnerability in account_sponsor_page.php
in MantisBT 1.0.0 through 1.2.15 allows remote authenticated users to
inject arbitrary web script or HTML via a project name.
|
| CVE-2013-4453 |
Cross-site scripting (XSS) vulnerability in templates/login.php in
LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to
inject arbitrary web script or HTML via the language parameter.
|
| CVE-2013-4447 |
Cross-site scripting (XSS) vulnerability in the API in the Simplenews
module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal
allows remote attackers to inject arbitrary web script or HTML via an
email address.
|
| CVE-2013-4433 |
Cross-site scripting (XSS) vulnerability in XHProf before 0.9.4 allows
remote attackers to inject arbitrary web script or HTML via the run
parameter.
|
| CVE-2013-4430 |
Cross-site scripting (XSS) vulnerability in Mahara before 1.5.12,
1.6.x before 1.6.7, and 1.7.x before 1.7.3 allows remote attackers to
inject arbitrary web script or HTML via the Host header to
lib/web.php.
|
| CVE-2013-4424 |
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn
Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4415 |
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and
Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject
arbitrary web script or HTML via the (1) whereCriteria variable in a
software channels search; (2) end_year, (3) start_hour, (4) end_am_pm,
(5) end_day, (6) end_hour, (7) end_minute, (8) end_month, (9)
end_year, (10) optionScanDateSearch, (11) result_filter, (12)
search_string, (13) show_as, (14) start_am_pm, (15) start_day, (16)
start_hour, (17) start_minute, (18) start_month, (19) start_year, or
(20) whereToSearch variable in an scap audit results search; (21)
end_minute, (22) end_month, (23) end_year, (24) errata_type_bug, (25)
errata_type_enhancement, (26) errata_type_security, (27) fineGrained,
(28) list_1892635924_sortdir, (29) optionIssueDateSearch, (30)
start_am_pm, (31) start_day, (32) start_hour, (33) start_minute, (34)
start_month, (35) start_year, or (36) view_mode variable in an errata
search; or (37) fineGrained variable in a systems search, related to
PAGE_SIZE_LABEL_SELECTED.
|
| CVE-2013-4414 |
Cross-site scripting (XSS) vulnerability in the web interface for
cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to
inject arbitrary web script or HTML via the "Max allowance" field in
the "Set limit" form.
|
| CVE-2013-4390 |
Open redirect vulnerability in the AbstractAuthenticationFormServlet
in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in
Apache Sling allows remote attackers to redirect users to arbitrary
web sites and conduct phishing attacks via a URL in the resource
parameter, related to "a custom login form and XSS."
|
| CVE-2013-4384 |
Cross-site scripting (XSS) vulnerability in Google Site Search module
6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.10 for Drupal allows
remote attackers to inject arbitrary web script or HTML by causing
crafted data to be returned by the Google API.
|
| CVE-2013-4383 |
Cross-site scripting (XSS) vulnerability in the jQuery Countdown
module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated
users with the "access administration pages" permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4380 |
Cross-site scripting (XSS) vulnerability in the MediaFront module
6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before
7.x-2.1 for Drupal allows remote authenticated users with the
"administer mediafront" permission to inject arbitrary web script or
HTML via the preset settings.
|
| CVE-2013-4378 |
Cross-site scripting (XSS) vulnerability in
HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
crafted X-Forwarded-For header.
|
| CVE-2013-4372 |
Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management
Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ
6.0.0 before patch 3 allow remote attackers to inject arbitrary web
script or HTML via the (1) user field in the create user page or (2)
profile version to the create profile page.
|
| CVE-2013-4341 |
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through
2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2
allow remote attackers to inject arbitrary web script or HTML via a
crafted blog link within an RSS feed.
|
| CVE-2013-4339 |
WordPress before 3.6.1 does not properly validate URLs before use in
an HTTP redirect, which allows remote attackers to bypass intended
redirection restrictions via a crafted string.
|
| CVE-2013-4308 |
Cross-site scripting (XSS) vulnerability in
pages/TalkpageHistoryView.php in the LiquidThreads (LQT) extension 2.x
and possibly 3.x for MediaWiki 1.19.x before 1.19.8, 1.20.x before
1.20.7, and 1.21.x before 1.21.2 allows remote attackers to inject
arbitrary web script or HTML via a thread subject.
|
| CVE-2013-4307 |
Multiple cross-site scripting (XSS) vulnerabilities in
repo/includes/EntityView.php in the Wikibase extension for MediaWiki
1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2
allow (1) remote attackers to inject arbitrary web script or HTML via
a label in the "In other languages" section or (2) remote
administrators to inject arbitrary web script or HTML via a
description.
|
| CVE-2013-4305 |
Cross-site scripting (XSS) vulnerability in contrib/example.php in the
SyntaxHighlight GeSHi extension for MediaWiki, possibly as downloaded
before September 2013, allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO.
|
| CVE-2013-4286 |
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before
8.0.0-RC3, when an HTTP connector or AJP connector is used, does not
properly handle certain inconsistent HTTP request headers, which
allows remote attackers to trigger incorrect identification of a
request's length and conduct request-smuggling attacks via (1)
multiple Content-Length headers or (2) a Content-Length header and a
"Transfer-Encoding: chunked" header. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2005-2090.
|
| CVE-2013-4274 |
Cross-site scripting (XSS) vulnerability in the
password_policy_admin_view function in password_policy.admin.inc in
the Password Policy module 6.x-1.x before 6.x-1.6 and 7.x-1.x before
7.x-1.5 for Drupal allows remote authenticated users with the
"Administer policies" permission to inject arbitrary web script or
HTML via the "Password Expiration Warning" field to the
admin/config/people/password_policy/add page.
|
| CVE-2013-4249 |
Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget
widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and
1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary
web script or HTML via a URLField.
|
| CVE-2013-4229 |
Cross-site scripting (XSS) vulnerability in the Monster Menus module
7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users
with permissions to add pages to inject arbitrary web script or HTML
via a title in the page settings.
|
| CVE-2013-4204 |
Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files
in the GWTTestCase in Google Web Toolkit (GWT) before 2.5.1 RC1 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-4190 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
spamProtect.py, (2) pts.py, and (3) request.py in Plone 2.1 through
4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-4181 |
Cross-site scripting (XSS) vulnerability in the addAlert function in
the RedirectServlet servlet in oVirt Engine and Red Hat Enterprise
Virtualization Manager (RHEV-M), as used in Red Hat Enterprise
Virtualization 3 and 3.2, allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-4174 |
Multiple cross-site scripting (XSS) vulnerabilities in the Scald
module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to
inject arbitrary web script or HTML via the (1) flash_uri, (2)
flash_width, or (3) flash_height in the scald_flash_scald_prerender
function in providers/scald_flash/scald_flash.module; or the (4)
caption in the scald_image_scald_prerender function in
providers/scald_image/scald_image.module.
|
| CVE-2013-4171 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller
before 5.0.2 allow remote attackers to inject arbitrary web script or
HTML via vectors related to the search results in the (1) RSS and (2)
Atom feed templates.
|
| CVE-2013-4167 |
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS)
before 1.11.7 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-4140 |
Cross-site scripting (XSS) vulnerability in the TinyBox (Simple
Splash) module before 7.x-2.2 for Drupal allows remote authenticated
users with the "administer tinybox" permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-4138 |
Cross-site scripting (XSS) vulnerability in the Hatch theme 7.x-1.x
before 7.x-1.4 for Drupal allows remote authenticated users with the
"Administer content," "Create new article," or "Edit any article type
content" permission to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-4117 |
Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php
in the Category Grid View Gallery plugin 2.3.1 for WordPress allows
remote attackers to inject arbitrary web script or HTML via the ID
parameter.
|
| CVE-2013-4065 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x
before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is
enabled, allows remote attackers to inject arbitrary web script or
HTML via active content in an e-mail message, aka SPR TCLE98ZKRP.
|
| CVE-2013-4064 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x
before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is
enabled, allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors, aka SPR PTHN9ARMFA.
|
| CVE-2013-4063 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x
before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to
inject arbitrary web script or HTML via active content in an e-mail
message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP.
|
| CVE-2013-4059 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere
Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and
9.1.x through 9.1.2.0 allow remote attackers to inject arbitrary web
script or HTML via unspecified interfaces.
|
| CVE-2013-4055 |
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web
Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors,
a different vulnerability than CVE-2013-4051.
|
| CVE-2013-4052 |
Cross-site scripting (XSS) vulnerability in the UDDI Administrative
console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47,
7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-4051 |
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web
Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors,
a different vulnerability than CVE-2013-4055.
|
| CVE-2013-4048 |
Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical
Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1
IF6 allows remote authenticated users to inject arbitrary web script
or HTML via vectors involving addition of script to a page.
|
| CVE-2013-4047 |
Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical
Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1
IF6 allows remote attackers to inject arbitrary web script or HTML via
a crafted link.
|
| CVE-2013-4045 |
Cross-site scripting (XSS) vulnerability in the Portal application in
IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3
IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-4036 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data
Management Server for Product Information Management 9.x before 9.1
FP13, and IBM InfoSphere Master Data Management - Collaborative
Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-4019 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 6.2 through 6.2.8 and 7.1 before 7.1.1.12 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-4014 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before
7.5.0.5 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2013-4007 |
Cross-site scripting (XSS) vulnerability in adv_sw.php in the Advanced
Management Module (AMM) with firmware BBET before BBET64G and BPET
before BPET64G for IBM BladeCenter systems allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4005 |
Cross-site scripting (XSS) vulnerability in the Administrative console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0
before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified fields.
|
| CVE-2013-4004 |
Cross-site scripting (XSS) vulnerability in the Administrative console
in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.7 and 8.5
before 8.5.5.1 allows remote authenticated users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-4003 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA
Application Platform 2.x and 3.x before 3.3.1.1, and 8, allow remote
authenticated users to inject arbitrary web script or HTML via (1)
unspecified input to WebProcess.srv, (2) unspecified input to
html/en/default/actionHandler/queryHandler.jsp, or (3) unspecified
input in a portalSectionId action to
html/en/default/reportTemplate/hGridTopQuery.jsp.
|
| CVE-2013-3999 |
Cross-site scripting (XSS) vulnerability in IBM Social Media Analytics
1.2 before FP1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-3995 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere BigInsights
1.1 through 2.1 allows remote authenticated users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-3990 |
Cross-site scripting (XSS) vulnerability in the MIME e-mail
functionality in iNotes in IBM Domino 9.0 before IF3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka SPR PTHN98FLQ2.
|
| CVE-2013-3979 |
Multiple cross-site scripting (XSS) vulnerabilities in the help pages
in Web\Content\Help\ in the Web Client in IBM Cognos Command Center
(aka Star Command Center or Star Analytics) before 10.1, when Internet
Explorer is used, allow remote authenticated users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-3964 |
Cross-site scripting (XSS) vulnerability in Samsung SHR-5162,
SHR-5082, and possibly other models, allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2013-3962 |
Cross-site scripting (XSS) vulnerability in Grandstream GXV3501,
GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD,
GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models
before firmware 1.0.4.44, allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO.
|
| CVE-2013-3943 |
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before
6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject
arbitrary web script or HTML via vectors related to the Display Name
field in the Manage Profile.
|
| CVE-2013-3933 |
Cross-site scripting (XSS) vulnerability in the JoomShopping
(com_joomshopping) component before 4.3.1 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via the user_name
parameter to index.php.
|
| CVE-2013-3929 |
Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS
Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the
"Modify Events" permission to inject arbitrary web script or HTML via
the handler parameter.
|
| CVE-2013-3920 |
Cross-site scripting (XSS) vulnerability in Jahia xCM before 6.6.2
allows remote authenticated users to inject arbitrary web script or
HTML via the "about me" field.
|
| CVE-2013-3895 |
Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows
remote attackers to conduct clickjacking attacks via a crafted web
page, aka "Parameter Injection Vulnerability."
|
| CVE-2013-3742 |
Cross-site scripting (XSS) vulnerability in view_create.php (aka the
Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote
authenticated users to inject arbitrary web script or HTML via an
invalid SQL CREATE VIEW statement with a crafted name that triggers an
error message.
|
| CVE-2013-3736 |
Cross-site scripting (XSS) vulnerability in the MobileUI (aka
RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT)
4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web
script or HTML via the name of an attached file.
|
| CVE-2013-3728 |
Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2
r1232 allows remote authenticated users with permissions to create
categories to inject arbitrary web script or HTML via the cat
parameter in an admin_new_category action to admin.php.
|
| CVE-2013-3720 |
Cross-site scripting (XSS) vulnerability in widget_remove.php in the
Feedweb plugin before 1.9 for WordPress allows remote authenticated
administrators to inject arbitrary web script or HTML via the
wp_post_id parameter.
|
| CVE-2013-3719 |
Cross-site scripting (XSS) vulnerability in the aiContactSafe
component before 2.0.21 for Joomla! allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-3653 |
Multiple cross-site scripting (XSS) vulnerabilities in the
RecommendSearch feature in the management screen in LOCKON EC-CUBE
before 2.12.5 allow remote attackers to inject arbitrary web script or
HTML via vectors involving the rank parameter, a different
vulnerability than CVE-2013-3652.
|
| CVE-2013-3652 |
Cross-site scripting (XSS) vulnerability in
data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE
2.11.0 through 2.12.4 allows remote attackers to inject arbitrary web
script or HTML via vectors involving the classcategory_id2 field, a
different vulnerability than CVE-2013-3653.
|
| CVE-2013-3649 |
Cross-site scripting (XSS) vulnerability in KENT-WEB CLIP-MAIL before
3.4, when Internet Explorer 7 or earlier is used, allows remote
attackers to inject arbitrary web script or HTML via an unspecified
form field.
|
| CVE-2013-3648 |
Cross-site scripting (XSS) vulnerability in KENT-WEB POST-MAIL before
6.7, when Internet Explorer 7 or earlier is used, allows remote
attackers to inject arbitrary web script or HTML via an unspecified
form field.
|
| CVE-2013-3645 |
Cross-site scripting (XSS) vulnerability in the Orchard.Comments
module in Orchard before 1.6.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-3640 |
Cross-site scripting (XSS) vulnerability in the Instant Web Publish
function in FileMaker Pro before 12 and Pro Advanced before 12 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-3639 |
Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) id, (2) interface, (3) name, or (4) tabmodule
parameter to index.php.
|
| CVE-2013-3616 |
Cross-site scripting (XSS) vulnerability in the KnowledgeView
Editorial and Management application allows remote attackers to inject
arbitrary web script or HTML via the username parameter.
|
| CVE-2013-3604 |
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill
Learning Management System (LMS) 6.6 allow remote attackers to inject
arbitrary web script or HTML via crafted input.
|
| CVE-2013-3603 |
Cross-site scripting (XSS) vulnerability in Coursemill Learning
Management System (LMS) 6.6 allows remote attackers to inject
arbitrary web script or HTML via vectors related to error messages.
|
| CVE-2013-3589 |
Cross-site scripting (XSS) vulnerability in the login page in the
Administrative Web Interface on Dell iDRAC6 monolithic devices with
firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45
allows remote attackers to inject arbitrary web script or HTML via the
ErrorMsg parameter.
|
| CVE-2013-3584 |
Cross-site scripting (XSS) vulnerability in Corporater EPM Suite
allows remote attackers to inject arbitrary web script or HTML via the
customerId parameter to an unspecified component.
|
| CVE-2013-3572 |
Cross-site scripting (XSS) vulnerability in the administer interface
in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
crafted client hostname.
|
| CVE-2013-3538 |
Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php
in Todoo Forum 2.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) id_post or (2) pg parameter.
|
| CVE-2013-3535 |
Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0
and 1.2.1 allow remote attackers to inject arbitrary web script or
HTML via the (1) admin_email, (2) header_title, (3) site_title
parameter to admin/settings; (4) recaptcha_private or (5)
recaptcha_public parameter to admin/captcha_settings; (6) fb_appid,
(7) fp_secret, (8) tw_consumer_key, or (9) tw_consumer_secret
parameter to admin/social_settings; (10) slug parameter to
admin/gallery/save_item_settings; or (11) item_link parameter to
admin/edit_menu_item_ajax. NOTE: this issue might be resultant from
CSRF.
|
| CVE-2013-3534 |
Cross-site scripting (XSS) vulnerability in the aiContactSafe
component before 2.0.21 for Joomla! allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-3529 |
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php
in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) message,
(2) photo-message, or (3) youtube-message parameter.
|
| CVE-2013-3526 |
Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the
Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
aoid parameter.
|
| CVE-2013-3515 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source
2.8.10 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) package parameter to
www/admin/plugin-index.php or the (2) group parameter to
www/admin/plugin-settings.php.
|
| CVE-2013-3513 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Noma
component in GroundWork Monitor Enterprise 6.7.0 allow remote
attackers to hijack the authentication of unspecified victims for
requests that (1) store XSS sequences or (2) delete entries.
|
| CVE-2013-3501 |
Multiple cross-site scripting (XSS) vulnerabilities in GroundWork
Monitor Enterprise 6.7.0 allow remote attackers to inject arbitrary
web script or HTML via vectors related to (1) the
foundation-webapp/admin/ directory, (2) the NeDi component, or (3) the
Noma component.
|
| CVE-2013-3498 |
Cross-site scripting (XSS) vulnerability in Juniper SmartPass WLAN
Security Management before 7.7 MR3 and 8.0 before MR2 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-3491 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Sharebar plugin 1.2.5 for WordPress allow remote attackers to hijack
the authentication of administrators for requests that (1) add or (2)
modify buttons, or (3) insert cross-site scripting (XSS) sequences.
|
| CVE-2013-3487 |
Multiple cross-site scripting (XSS) vulnerabilities in the security
log in the BulletProof Security plugin before .49 for WordPress allow
remote attackers to inject arbitrary web script or HTML via
unspecified HTML header fields to (1) 400.php, (2) 403.php, or (3)
403.php.
|
| CVE-2013-3484 |
Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before
2.3.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) _loginUserName parameter to application/login/login.html,
(2) my_account_login parameter to c/portal_public/login, or (3) email
parameter to forgotPassword.
|
| CVE-2013-3471 |
The captive portal application in Cisco Identity Services Engine (ISE)
allows remote attackers to discover cleartext usernames and passwords
by leveraging unspecified use of hidden form fields in an HTML
document, aka Bug ID CSCug02515.
|
| CVE-2013-3440 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative web interface in Cisco Unified Operations Manager allow
remote attackers to inject arbitrary web script or HTML, and obtain
improperly secured cookies, via unspecified vectors, aka Bug ID
CSCud80186.
|
| CVE-2013-3439 |
Cross-site scripting (XSS) vulnerability in Cisco Unified Operations
Manager allows remote attackers to inject arbitrary web script or HTML
via a crafted URL in an unspecified HTTP header field, aka Bug ID
CSCud80182.
|
| CVE-2013-3423 |
Cross-site scripting (XSS) vulnerability in the web interface in Cisco
Secure Access Control System (ACS) allows remote attackers to inject
arbitrary web script or HTML via an unspecified field, aka Bug ID
CSCud75174.
|
| CVE-2013-3422 |
Cross-site scripting (XSS) vulnerability in Administration pages in
Cisco Secure Access Control System (ACS) allows remote attackers to
inject arbitrary web script or HTML via an unspecified parameter, aka
Bug ID CSCud75165.
|
| CVE-2013-3421 |
Cross-site scripting (XSS) vulnerability in the Help index page in
Cisco Secure Access Control System (ACS) allows remote attackers to
inject arbitrary web script or HTML via an unspecified parameter, aka
Bug ID CSCud75170.
|
| CVE-2013-3419 |
Cross-site scripting (XSS) vulnerability in Cisco Unified MeetingPlace
Web Conferencing allows remote attackers to inject arbitrary web
script or HTML via an unspecified parameter, aka Bug ID CSCuh74981.
|
| CVE-2013-3416 |
Cross-site scripting (XSS) vulnerability in the web framework in the
unified-communications management implementation in Cisco Unified
Operations Manager and Unified Service Monitor allows remote attackers
to inject arbitrary web script or HTML via an unspecified parameter,
aka Bug IDs CSCuh47574 and CSCuh95997.
|
| CVE-2013-3414 |
Cross-site scripting (XSS) vulnerability in the WebVPN portal login
page on Cisco Adaptive Security Appliances (ASA) devices allows remote
attackers to inject arbitrary web script or HTML via a crafted URL,
aka Bug ID CSCug83080.
|
| CVE-2013-3413 |
Cross-site scripting (XSS) vulnerability in the search form in the
administration/monitoring panel on the Cisco Identity Services Engine
(ISE) allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, aka Bug ID CSCuh87036.
|
| CVE-2013-3396 |
Cross-site scripting (XSS) vulnerability in the web framework in Cisco
Content Security Management on Security Management Appliance (SMA)
devices allows remote attackers to inject arbitrary web script or HTML
via an unspecified parameter, aka Bug ID CSCuh24749.
|
| CVE-2013-3394 |
Cross-site scripting (XSS) vulnerability in the web interface in Cisco
Prime Network Registrar 8.1 and earlier allows remote attackers to
inject arbitrary web script or HTML via a crafted field, aka Bug ID
CSCuh41429.
|
| CVE-2013-3375 |
Cross-site scripting (XSS) vulnerability in the portal page in Cisco
Prime Central for Hosted Collaboration Solution allows remote
attackers to inject arbitrary web script or HTML via a crafted URL,
aka Bug ID CSCue23798.
|
| CVE-2013-3372 |
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13
allows remote attackers to inject multiple Content-Disposition HTTP
headers and possibly conduct cross-site scripting (XSS) attacks via
unspecified vectors.
|
| CVE-2013-3371 |
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3
through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to
inject arbitrary web script or HTML via the filename of an attachment.
|
| CVE-2013-3300 |
The JsonParser class in json/JsonParser.scala in Lift before 2.5
interprets a certain end-index value as a length value, which allows
remote authenticated users to obtain sensitive information from other
users' sessions via invalid input data containing a < (less than)
character.
|
| CVE-2013-3288 |
Cross-site scripting (XSS) vulnerability on the EMC RSA Data
Protection Manager (DPM) appliance 3.2.x before 3.2.4.2 and 3.5.x
before 3.5.1 allows remote attackers to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2013-3286 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum
eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2013-3281 |
Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop
before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum
Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7
SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital
Asset Manager before 6.5 SP6, Documentum Administrator before 6.7 SP2
P07, and Documentum Capital Projects before 1.8 P01 allows remote
attackers to inject arbitrary web script or HTML via a crafted
parameter in a URL.
|
| CVE-2013-3267 |
Cross-site scripting (XSS) vulnerability in the highlighter plugin in
Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-3263 |
Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate
Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow
remote attackers to inject arbitrary web script or HTML via the (1)
siteurl parameter to campaign/campaignone.php; the (2) action, (3)
campaignname, (4) campaignformat, or (5) emailtemplate parameter to
campaign/campaigntwo.php; the (6) listid parameter to list/edit.php;
the (7) campaignid or (8) siteurl parameter to
campaign/editcampaign.php; the (9) campaignid parameter to
campaign/selectlistb4send.php; the (10) campaignid, (11) campaignname,
(12) campaignsubject, or (13) selectedcampaigns parameter to
campaign/sendCampaign.php; or the (14) campaignid, (15) campaignname,
(16) campaignformat, or (17) action parameter to
campaign/updatecampaign.php.
|
| CVE-2013-3262 |
Cross-site scripting (XSS) vulnerability in admin/admin.php in the
Download Monitor plugin before 3.3.6.2 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the p parameter.
|
| CVE-2013-3261 |
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the
GRAND FlAGallery plugin before 2.72 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the s parameter
in a flag-manage-gallery action.
|
| CVE-2013-3254 |
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the
WP Photo Album Plus plugin before 5.0.3 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the commentid
parameter in a wppa_manage_comments edit action.
|
| CVE-2013-3242 |
plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10
and 3.0.x before 3.0.4 does not properly handle an object obtained by
unserializing a cookie, which allows remote authenticated users to
conduct PHP object injection attacks and cause a denial of service via
unspecified vectors.
|
| CVE-2013-3192 |
Cross-site scripting (XSS) vulnerability in Microsoft Internet
Explorer 6 through 10 allows remote attackers to inject arbitrary web
script or HTML via crafted character sequences with EUC-JP encoding,
aka "EUC-JP Character Encoding Vulnerability."
|
| CVE-2013-3180 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject
arbitrary web script or HTML via a crafted POST request, aka "POST XSS
Vulnerability."
|
| CVE-2013-3179 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to
inject arbitrary web script or HTML via a crafted request, aka
"SharePoint XSS Vulnerability."
|
| CVE-2013-3166 |
Cross-site scripting (XSS) vulnerability in Microsoft Internet
Explorer 6 through 10 allows remote attackers to inject arbitrary web
script or HTML via vectors involving incorrect auto-selection of the
Shift JIS encoding, leading to cross-domain scrolling events, aka
"Shift JIS Character Encoding Vulnerability," a different
vulnerability than CVE-2013-0015.
|
| CVE-2013-3106 |
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange
AppSuite and Server before 6.20.7 rev18, 6.22.0 before rev16, 6.22.1
before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before
rev8 allow remote attackers to inject arbitrary web script or HTML via
(1) embedded VBScript, (2) object/data Base64 content, (3) a
Content-Type header, or (4) UTF-16 encoding, aka Bug IDs 25957, 26237,
26243, and 26244.
|
| CVE-2013-3090 |
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N300
router allow remote attackers to inject arbitrary web script or HTML
via the Guest Access PSK field to wireless_guest2_print.stm or other
unspecified vectors.
|
| CVE-2013-3087 |
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900
router allow remote attackers to inject arbitrary web script or HTML
via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk
parameter to wl_guest.html.
|
| CVE-2013-3084 |
Multiple cross-site scripting (XSS) vulnerabilities in Belkin Model
F5D8236-4 v2 router allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-3082 |
Cross-site scripting (XSS) vulnerability in
plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows
remote attackers to inject arbitrary web script or HTML via the search
parameter to forgot-password/.
|
| CVE-2013-3069 |
Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR
WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to
inject arbitrary web script or HTML via the (1) UserName or (2)
Password to the NAS User Setup page, (3) deviceName to
USB_advanced.htm, or (4) Network Key to the Wireless Setup page.
|
| CVE-2013-3065 |
Cross-site scripting (XSS) vulnerability in the Parental Controls
section in Linksys EA6500 with firmware 1.1.28.147876 allows remote
authenticated users to inject arbitrary web script or HTML via vectors
related to the Blocked Specific Sites section.
|
| CVE-2013-3059 |
Cross-site scripting (XSS) vulnerability in the Voting plugin in
Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-3058 |
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before
2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-3048 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before
7.5.0.3 allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-3034 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information
Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote
authenticated users to inject arbitrary web script or HTML via vectors
related to the web console.
|
| CVE-2013-3032 |
Cross-site scripting (XSS) vulnerability in the MIME e-mail
functionality in iNotes in IBM Domino 9.0 before IF3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka SPR PTHN986NAA.
|
| CVE-2013-3029 |
Cross-site request forgery (CSRF) vulnerability in the Administrative
console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47,
7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows
remote attackers to hijack the authentication of arbitrary users for
requests that insert cross-site scripting (XSS) sequences.
|
| CVE-2013-3025 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational
Focal Point 6.5.x and 6.6.x before 6.6.0.1 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-2983 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling
File Gateway 2.2 and Sterling B2B Integrator allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different issue than CVE-2013-0468.
|
| CVE-2013-2969 |
Cross-site scripting (XSS) vulnerability in IBM Sterling Control
Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through
5.4.0.1 allows remote authenticated users to inject arbitrary web
script or HTML via vectors involving invalid characters.
|
| CVE-2013-2967 |
Cross-site scripting (XSS) vulnerability in the Administrative console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0
before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-2957 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data
Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2013-2955 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data
Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted URL, related to a stored XSS issue.
|
| CVE-2013-2849 |
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome
before 27.0.1453.93 allow user-assisted remote attackers to inject
arbitrary web script or HTML via vectors involving a (1) drag-and-drop
or (2) copy-and-paste operation.
|
| CVE-2013-2848 |
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow
remote attackers to obtain sensitive information via unspecified
vectors.
|
| CVE-2013-2766 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 4.3.0
through 4.3.5 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-2750 |
Cross-site scripting (XSS) vulnerability in
e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3
allows remote attackers to inject arbitrary web script or HTML via the
query string.
|
| CVE-2013-2715 |
Cross-site scripting (XSS) vulnerability in the admin view in the
Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal
allows remote authenticated users with certain permissions to inject
arbitrary web script or HTML via a crafted field name.
|
| CVE-2013-2712 |
Cross-site scripting (XSS) vulnerability in services/get_article.php
in KrisonAV CMS before 3.0.2 allows remote attackers to inject
arbitrary web script or HTML via the content parameter.
|
| CVE-2013-2710 |
Cross-site request forgery (CSRF) vulnerability in the Contextual
Related Posts plugin before 1.8.7 for WordPress allows remote
attackers to hijack the authentication of administrators for requests
that conduct cross-site scripting (XSS) attacks via unspecified
vectors.
|
| CVE-2013-2709 |
Cross-site request forgery (CSRF) vulnerability in the FourSquare
Checkins plugin before 1.3 for WordPress allows remote attackers to
hijack the authentication of arbitrary users for requests that insert
XSS sequences.
|
| CVE-2013-2704 |
Cross-site request forgery (CSRF) vulnerability in the Dropdown Menu
Widget plugin 1.9.1 for WordPress allows remote attackers to hijack
the authentication of arbitrary users for requests that insert
cross-site scripting (XSS) sequences.
|
| CVE-2013-2703 |
Cross-site request forgery (CSRF) vulnerability in the Facebook
Members plugin before 5.0.5 for WordPress allows remote attackers to
hijack the authentication of administrators for requests that modify
this plugin's settings.
|
| CVE-2013-2697 |
Cross-site request forgery (CSRF) vulnerability in the
WP-DownloadManager plugin before 1.61 for WordPress allows remote
attackers to hijack the authentication of arbitrary users for requests
that insert XSS sequences.
|
| CVE-2013-2696 |
Cross-site request forgery (CSRF) vulnerability in the All in One
Webmaster plugin before 8.2.4 for WordPress allows remote attackers to
hijack the authentication of arbitrary users for requests that insert
XSS sequences.
|
| CVE-2013-2695 |
Cross-site scripting (XSS) vulnerability in invite.php in the WP
Symposium plugin before 13.04 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the u parameter.
|
| CVE-2013-2671 |
Multiple cross-site scripting (XSS) vulnerabilities in the Brother
MFC-9970CDW printer with firmware L (1.10) allow remote attackers to
inject arbitrary web script or HTML via the (1) id or (2) val
parameter to admin/admin_main.html; (3) id, (4) val, or (5) arbitrary
parameter name (QUERY_STRING) to admin/profile_settings_net.html; or
(6) kind or (7) arbitrary parameter name (QUERY_STRING) to
fax/general_setup.html, a different vulnerability than CVE-2013-2507
and CVE-2013-2670.
|
| CVE-2013-2670 |
Cross-site scripting (XSS) vulnerability in the Brother MFC-9970CDW
printer with firmware G (1.03) and L (1.10) allows remote attackers to
inject arbitrary web script or HTML via an arbitrary parameter name
(QUERY_STRING) to admin/admin_main.html, a different vulnerability
than CVE-2013-2507 and CVE-2013-2671.
|
| CVE-2013-2651 |
Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) "p" or (2) content parameter to index.php.
|
| CVE-2013-2643 |
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web
Appliance before 3.7.8.2 allow remote attackers to inject arbitrary
web script or HTML via the (1) xss parameter in an allow action to
rss.php, (2) msg parameter to end-user/errdoc.php, (3) h parameter to
end-user/ftp_redirect.php, or (4) threat parameter to the Blocked
component.
|
| CVE-2013-2640 |
ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress
does not properly restrict access to unspecified Ajax functions, which
allows remote attackers to modify plugin settings and conduct
cross-site scripting (XSS) attacks via unspecified vectors related to
"formData=save" requests, a different version than CVE-2013-0731.
|
| CVE-2013-2639 |
Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS
before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to
inject arbitrary web script or HTML via the description in a project
folder.
|
| CVE-2013-2630 |
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager
12.5 through 12.7 allows remote attackers to inject arbitrary web
script or HTML via unspecified parameters.
|
| CVE-2013-2618 |
Cross-site scripting (XSS) vulnerability in editor.php in Network
Weathermap before 0.97b allows remote attackers to inject arbitrary
web script or HTML via the map_title parameter.
|
| CVE-2013-2586 |
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which
allows remote attackers to modify xampp/lang.tmp and execute
cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.
|
| CVE-2013-2585 |
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server
6.6.x before 6.6.3 and 7.0.x before 7.0.3 allows remote attackers to
inject arbitrary web script or HTML via the PATH_INFO to
index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId/<MessageID>/filenameOriginal/.
|
| CVE-2013-2583 |
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange
AppSuite and Server before 6.20.7 rev16, 6.22.0 before rev15, 6.22.1
before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allow remote
attackers to inject arbitrary web script or HTML via (1) a javascript:
URL, (2) malformed nested SCRIPT elements, (3) a mail signature, or
(4) JavaScript code within an image file.
|
| CVE-2013-2507 |
Multiple cross-site scripting (XSS) vulnerabilities in the Brother
MFC-9970CDW printer with firmware G (1.03) allow remote attackers to
inject arbitrary web script or HTML via the (1) id parameter to
admin/log_to_net.html or (2) kind parameter to fax/copy_settings.html,
a different vulnerability than CVE-2013-2670 and CVE-2013-2671.
|
| CVE-2013-2504 |
Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in
Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows
remote attackers to inject arbitrary web script or HTML via the query
string.
|
| CVE-2013-2501 |
Cross-site scripting (XSS) vulnerability in the Terillion Reviews
plugin before 1.2 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the ProfileId field.
|
| CVE-2013-2372 |
Cross-site scripting (XSS) vulnerability in the Engine in TIBCO
Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x
before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-2364 |
Cross-site scripting (XSS) vulnerability in HP System Management
Homepage (SMH) before 7.2.1 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-2361 |
Cross-site scripting (XSS) vulnerability in HP System Management
Homepage (SMH) before 7.2.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-2337 |
Cross-site scripting (XSS) vulnerability in HP Service Manager 7.11,
9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-2321 |
Cross-site scripting (XSS) vulnerability in HP Service Manager Web
Tier 9.31 before 9.31.2004 p2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-2314 |
Cross-site scripting (XSS) vulnerability in the adminAuthorization
function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE
2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary
web script or HTML via a crafted URL associated with the management
screen.
|
| CVE-2013-2312 |
Cross-site scripting (XSS) vulnerability in the shopping-cart screen
in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-2311 |
Cross-site scripting (XSS) vulnerability in static/js/share.js (aka
the social bookmarking widget) in Web2py before 2.3.1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-2309 |
Cross-site scripting (XSS) vulnerability in the management screen in
OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before
3.8.5.1 allows remote attackers to inject arbitrary web script or HTML
via vectors involving the "mobile version color scheme."
|
| CVE-2013-2299 |
Cross-site scripting (XSS) vulnerability in Advantech WebAccess
(formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-2290 |
Cross-site scripting (XSS) vulnerability in the dashboard of the
ArubaOS Administration WebUI in Aruba Networks ArubaOS 6.2.x before
6.2.0.3, 6.1.3.x before 6.1.3.7, 6.1.x-FIPS before 6.1.4.3-FIPS, and
6.1.x-AirGroup before 6.1.3.6-AirGroup, as used by Mobility
Controller, allows remote wireless access points to inject arbitrary
web script or HTML via a crafted SSID.
|
| CVE-2013-2289 |
Cross-site scripting (XSS) vulnerability in
admin/templates/default.php in Batavi 1.2.2 allows remote attackers to
inject arbitrary web script or HTML via the QUERY_STRING to
admin/index.php.
|
| CVE-2013-2287 |
Multiple cross-site scripting (XSS) vulnerabilities in
views/notify.php in the Uploader plugin 1.0.4 for WordPress allow
remote attackers to inject arbitrary web script or HTML via the (1)
notify or (2) blog parameter.
|
| CVE-2013-2270 |
Cross-site scripting (XSS) vulnerability in the administration page in
Airvana HubBub C1-600-RT and Sprint AIRAVE 2.5 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-2244 |
Multiple cross-site scripting (XSS) vulnerabilities in
lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before
2.5.1 allow remote attackers to inject arbitrary web script or HTML
via the conditional access rule value of a user field.
|
| CVE-2013-2209 |
Cross-site scripting (XSS) vulnerability in the auto-complete widget
in htdocs/media/rb/js/reviews.js in Review Board 1.6.x before 1.6.17
and 1.7.x before 1.7.10 allows remote attackers to inject arbitrary
web script or HTML via a full name.
|
| CVE-2013-2205 |
The default configuration of SWFUpload in WordPress before 3.5.2 has
an unrestrictive security.allowDomain setting, which allows remote
attackers to bypass the Same Origin Policy and conduct cross-site
scripting (XSS) attacks via a crafted web site.
|
| CVE-2013-2201 |
Multiple cross-site scripting (XSS) vulnerabilities in WordPress
before 3.5.2 allow remote attackers to inject arbitrary web script or
HTML via vectors involving (1) uploads of media files, (2) editing of
media files, (3) installation of plugins, (4) updates to plugins, (5)
installation of themes, or (6) updates to themes.
|
| CVE-2013-2187 |
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through
1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary
web script or HTML via unspecified parameters, related to the home
page.
|
| CVE-2013-2181 |
Cross-site scripting (XSS) vulnerability in the Directory Listing
plugin in Monkey HTTP Daemon (monkeyd) 1.2.2 allows attackers to
inject arbitrary web script or HTML via a file name.
|
| CVE-2013-2177 |
Cross-site scripting (XSS) vulnerability in the Display Suite module
7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via an entity bundle label.
|
| CVE-2013-2150 |
Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in
ownCloud before 4.5.12 and 5.x before 5.0.7 allow remote attackers to
inject arbitrary web script or HTML via vectors related to shared
files.
|
| CVE-2013-2149 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
4.0.16 and 5.x before 5.0.7 allow remote authenticated users to inject
arbitrary web script or HTML via vectors related to shared files.
|
| CVE-2013-2137 |
Cross-site scripting (XSS) vulnerability in the "View Log" screen in
the Webtools application in Apache Open For Business Project (aka
OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and
12.04.01 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-2136 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache
CloudStack before 4.1.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) Physical network name to the Zone wizard;
(2) New network name, (3) instance name, or (4) group to the Instance
wizard; (5) unspecified "multi-edit fields;" and (6) unspecified "list
view" edit fields related to global settings.
|
| CVE-2013-2129 |
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x
before 6.x-3.19 for Drupal allows remote authenticated users with the
"edit own webform content" or "edit all webform content" permissions
to inject arbitrary web script or HTML via a component label.
|
| CVE-2013-2087 |
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3
before 3.0.7 allow remote attackers to inject arbitrary web script or
HTML via the (1) movie title to modules/gallery/controllers/movies.php
or (2) key variable to modules/gallery/views/error_admin.html.php.
|
| CVE-2013-2042 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote
authenticated users to inject arbitrary web script or HTML via the url
parameter to (1) apps/bookmarks/ajax/addBookmark.php or (2)
apps/bookmarks/ajax/editBookmark.php.
|
| CVE-2013-2041 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 5.0.x
before 5.0.6 allow remote authenticated users to inject arbitrary web
script or HTML via the (1) tag parameter to
apps/bookmarks/ajax/addBookmark.php or (2) dir parameter to
apps/files/ajax/newfile.php, which is passed to
apps/files/js/files.js.
|
| CVE-2013-2040 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-2036 |
Cross-site scripting (XSS) vulnerability in the Filebrowser module
6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to
"lists of files."
|
| CVE-2013-2033 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS
before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x
before 1.480.4.1 allows remote authenticated users with write
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-2031 |
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote
attackers to conduct cross-site scripting (XSS) attacks, as
demonstrated by a CDATA section containing valid UTF-7 encoded
sequences in a SVG file, which is then incorrectly interpreted as
UTF-8 by Chrome and Firefox.
|
| CVE-2013-2025 |
Cross-site scripting (XSS) vulnerability in Ushahidi Platform 2.5.x
through 2.6.1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-2023 |
Cross-site scripting (XSS) vulnerability in actionscript/Jplayer.as in
the Flash SWF component (jplayer.swf) in jPlayer before 2.3.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, possibly related to incomplete blacklists, a
different vulnerability than CVE-2013-1942 and CVE-2013-2022.
|
| CVE-2013-2022 |
Multiple cross-site scripting (XSS) vulnerabilities in
actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in
jPlayer before 2.2.23 allow remote attackers to inject arbitrary web
script or HTML via the (1) jQuery or (2) id parameters, a different
vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by
using the alert function in the jQuery parameter. NOTE: these are the
same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a
blacklist for the jQuery parameter.
|
| CVE-2013-1971 |
Cross-site scripting (XSS) vulnerability in the MP3 Player module for
Drupal 6.x allows remote authenticated users with certain permissions
to inject arbitrary web script or HTML via the file name of a MP3
file.
|
| CVE-2013-1967 |
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in
MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before
5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject
arbitrary web script or HTML via the file parameter.
|
| CVE-2013-1955 |
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php
and (2) datePicker.php in Easy PHP Calendar 6.x and 7.x before 7.0.13
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-1942 |
Multiple cross-site scripting (XSS) vulnerabilities in
actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in
jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and
other products, allow remote attackers to inject arbitrary web script
or HTML via the (1) jQuery or (2) id parameters, as demonstrated using
document.write in the jQuery parameter, a different vulnerability than
CVE-2013-2022 and CVE-2013-2023.
|
| CVE-2013-1937 |
Multiple cross-site scripting (XSS) vulnerabilities in
tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow
remote attackers to inject arbitrary web script or HTML via the (1)
visualizationSettings[width] or (2) visualizationSettings[height]
parameter.
|
| CVE-2013-1906 |
Cross-site scripting (XSS) vulnerability in the Rules module 7.x-2.x
before 7.x-2.3 for Drupal allows remote authenticated users with the
"administer rules" permission to inject arbitrary web script or HTML
via a rule tag.
|
| CVE-2013-1905 |
Cross-site scripting (XSS) vulnerability in the Zero Point theme
7.x-1.x before 7.x-1.9 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1890 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server
before 5.0.1 allow remote attackers to inject arbitrary web script or
HTML via the (1) new_name parameter to
apps/bookmarks/ajax/renameTag.php or (2) multiple unspecified
parameters to unknown files in apps/contacts/ajax/.
|
| CVE-2013-1887 |
Multiple cross-site scripting (XSS) vulnerabilities in the Views
module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via certain view configuration fields.
|
| CVE-2013-1885 |
Multiple cross-site scripting (XSS) vulnerabilities in the token
processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1
and possibly Dogtag Certificate System 9 and 10 allow remote attackers
to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/
or (2) tus/tus/.
|
| CVE-2013-1880 |
Cross-site scripting (XSS) vulnerability in the Portfolio publisher
servlet in the demo web application in Apache ActiveMQ before 5.9.0
allows remote attackers to inject arbitrary web script or HTML via the
refresh parameter to demo/portfolioPublish, a different vulnerability
than CVE-2012-6092.
|
| CVE-2013-1879 |
Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache
ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via vectors involving the "cron of a message."
|
| CVE-2013-1871 |
Cross-site scripting (XSS) vulnerability in account/EditAddress.do in
Spacewalk and Red Hat Network (RHN) Satellite 5.6 allows remote
attackers to inject arbitrary web script or HTML via the type
parameter.
|
| CVE-2013-1869 |
CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and
Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject
arbitrary HTTP headers, and conduct HTTP response splitting attacks
and cross-site scripting (XSS) attacks, via the return_url parameter.
|
| CVE-2013-1857 |
The sanitize helper in
lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the
Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x
before 3.1.12, and 3.2.x before 3.2.13 does not properly handle
encoded : (colon) characters in URLs, which makes it easier for remote
attackers to conduct cross-site scripting (XSS) attacks via a crafted
scheme name, as demonstrated by including a : sequence.
|
| CVE-2013-1855 |
The sanitize_css method in
lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the
Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x
before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n
(newline) characters, which makes it easier for remote attackers to
conduct cross-site scripting (XSS) attacks via crafted Cascading Style
Sheets (CSS) token sequences.
|
| CVE-2013-1844 |
Cross-site scripting (XSS) vulnerability in Piwik before 1.11 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-1833 |
Multiple cross-site scripting (XSS) vulnerabilities in the File Picker
module in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before
2.3.5, and 2.4.x before 2.4.2 allow remote authenticated users to
inject arbitrary web script or HTML via a crafted filename.
|
| CVE-2013-1823 |
Cross-site scripting (XSS) vulnerability in the Notifications form in
Red Hat Subscription Asset Manager before 1.2.1 allows remote
attackers to inject arbitrary web script or HTML via the username
field.
|
| CVE-2013-1822 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x
before 4.5.8 allow remote authenticated users with administrator
privileges to inject arbitrary web script or HTML via the (1) quota
parameter to /core/settings/ajax/setquota.php, or remote authenticated
users with group admin privileges to inject arbitrary web script or
HTML via the (2) group field to settings.php or (3) "share with"
field.
|
| CVE-2013-1810 |
Multiple cross-site scripting (XSS) vulnerabilities in
core/summary_api.php in MantisBT 1.2.12 allow remote authenticated
users with manager or administrator permissions to inject arbitrary
web script or HTML via a (1) category name in the
summary_print_by_category function or (2) project name in the
summary_print_by_project function.
|
| CVE-2013-1808 |
Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and
ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in
em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other
products, allows remote attackers to inject arbitrary web script or
HTML via the id parameter. NOTE: this is might be the same
vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463
will be REJECTed.
|
| CVE-2013-1804 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion
before 7.02.06 allow remote attackers to inject arbitrary web script
or HTML via the (1) highlight parameter to forum/viewthread.php; or
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via the (2) user_list or (3) user_types
parameter to messages.php; (4) message parameter to
infusions/shoutbox_panel/shoutbox_admin.php; (5) message parameter to
administration/news.php; (6) panel_list parameter to
administration/panel_editor.php; (7) HTTP User Agent string to
administration/phpinfo.php; (8) "__BBCODE__" parameter to
administration/bbcodes.php; errorMessage parameter to (9)
article_cats.php, (10) download_cats.php, (11) news_cats.php, or (12)
weblink_cats.php in administration/, when error is 3; or (13) body or
(14) body2 parameter to administration/articles.php.
|
| CVE-2013-1787 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Simple Corporate theme before 7.x-1.4 for Drupal allows remote
authenticated users with the administer themes permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1786 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Company theme before 7.x-1.4 for Drupal allows remote authenticated
users with the administer themes permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-1785 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Premium Responsive theme before 7.x-1.6 for Drupal allows remote
authenticated users with the administer themes permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1784 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Clean Theme before 7.x-1.3 for Drupal allows remote authenticated
users with the administer themes permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-1783 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in
page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal
allows remote authenticated users with the administer themes
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-1782 |
Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme
7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users
with the administer themes permission to inject arbitrary web script
or HTML via vectors related to social icons.
|
| CVE-2013-1781 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Professional theme before 7.x-1.4 for Drupal allows remote
authenticated users with the administer themes permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1780 |
Cross-site scripting (XSS) vulnerability in the Best Responsive Theme
7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users
with the administer themes permission to inject arbitrary web script
or HTML via vectors related to social icons.
|
| CVE-2013-1779 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Fresh theme before 7.x-1.4 for Drupal allows remote authenticated
users with the administer themes permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-1778 |
Cross-site scripting (XSS) vulnerability in the Creative Theme 7.x-1.x
before 7.x-1.2 for Drupal allows remote authenticated users with the
administer themes permission to inject arbitrary web script or HTML
via vectors related to social icons.
|
| CVE-2013-1770 |
Cross-site scripting (XSS) vulnerability in views_view.php in Ganglia
Web 3.5.7 allows remote attackers to inject arbitrary web script or
HTML via the view_name parameter.
|
| CVE-2013-1765 |
Multiple cross-site scripting (XSS) vulnerabilities in jwplayer.swf in
the smart-flv plugin for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) link or (2) playerready
parameter.
|
| CVE-2013-1759 |
Cross-site scripting (XSS) vulnerability in the Responsive Logo
Slideshow plugin for WordPress allows remote attackers to inject
arbitrary web script or HTML via the "URL and Image" field.
|
| CVE-2013-1758 |
Cross-site scripting (XSS) vulnerability in the Marekkis Watermark
plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the pfad parameter to
wp-admin/options-general.php. NOTE: some of these details are obtained
from third party information.
|
| CVE-2013-1749 |
Cross-site scripting (XSS) vulnerability in edit.php in PHP Address
Book 8.2.5 allows user-assisted remote attackers to inject arbitrary
web script or HTML via the Address field.
|
| CVE-2013-1743 |
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in
Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1
allow remote attackers to inject arbitrary web script or HTML via a
field value that is not properly handled during construction of a
tabular report, as demonstrated by the (1) summary or (2) real name
field. NOTE: this issue exists because of an incomplete fix for
CVE-2012-4189.
|
| CVE-2013-1742 |
Multiple cross-site scripting (XSS) vulnerabilities in
editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x
and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote
attackers to inject arbitrary web script or HTML via the (1) id or (2)
sortkey parameter.
|
| CVE-2013-1727 |
Mozilla Firefox before 24.0 on Android allows attackers to bypass the
Same Origin Policy, and consequently conduct cross-site scripting
(XSS) attacks or obtain password or cookie information, by using a
symlink in conjunction with a file: URL for a local file.
|
| CVE-2013-1714 |
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox
ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR
17.x before 17.0.8, and SeaMonkey before 2.20 does not properly
restrict XMLHttpRequest calls, which allows remote attackers to bypass
the Same Origin Policy and conduct cross-site scripting (XSS) attacks
via unspecified vectors.
|
| CVE-2013-1713 |
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8,
Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and
SeaMonkey before 2.20 use an incorrect URI within unspecified
comparisons during enforcement of the Same Origin Policy, which allows
remote attackers to conduct cross-site scripting (XSS) attacks or
install arbitrary add-ons via a crafted web site.
|
| CVE-2013-1711 |
The XrayWrapper implementation in Mozilla Firefox before 23.0 and
SeaMonkey before 2.20 does not properly address the possibility of an
XBL scope bypass resulting from non-native arguments in XBL function
calls, which makes it easier for remote attackers to conduct
cross-site scripting (XSS) attacks by leveraging access to an
unprivileged object.
|
| CVE-2013-1710 |
The crypto.generateCRMFRequest function in Mozilla Firefox before
23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8,
Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows
remote attackers to execute arbitrary JavaScript code or conduct
cross-site scripting (XSS) attacks via vectors related to Certificate
Request Message Format (CRMF) request generation.
|
| CVE-2013-1709 |
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8,
Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and
SeaMonkey before 2.20 do not properly handle the interaction between
FRAME elements and history, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via vectors involving spoofing a
relative location in a previously visited document.
|
| CVE-2013-1687 |
The System Only Wrapper (SOW) and Chrome Object Wrapper (COW)
implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x
before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x
before 17.0.7 do not properly restrict XBL user-defined functions,
which allows remote attackers to execute arbitrary JavaScript code
with chrome privileges, or conduct cross-site scripting (XSS) attacks,
via a crafted web site.
|
| CVE-2013-1670 |
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox
before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before
17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent
acquisition of chrome privileges during calls to content level
constructors, which allows remote attackers to bypass certain
read-only restrictions and conduct cross-site scripting (XSS) attacks
via a crafted web site.
|
| CVE-2013-1646 |
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange
Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before
rev14 allow remote attackers to inject arbitrary web script or HTML
via (1) invalid JSON data in a mail-sending POST request, (2) an
arbitrary parameter to servlet/TestServlet, (3) a javascript: URL in a
standalone-mode action to a UWA module, (4) an infostore attachment,
(5) JavaScript code in a contact image, (6) an RSS feed, or (7) a
signature.
|
| CVE-2013-1636 |
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in
Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link
Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component
8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through
4.3.3, allows remote attackers to inject arbitrary web script or HTML
via the get-data parameter.
|
| CVE-2013-1614 |
Multiple cross-site scripting (XSS) vulnerabilities in the management
console (aka Java console) on the Symantec Security Information
Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-1611 |
Multiple cross-site scripting (XSS) vulnerabilities in
administrative-interface pages in the management console in Symantec
Brightmail Gateway 9.5.x allow remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1471 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail
Identity-Based Encryption (IBE) appliances allow user-assisted remote
attackers to inject arbitrary web script or HTML via (1) the Add field
for the Black List under Antispam Management User Preferences or (2)
the User name field for the Personal Black/White List in the AntiSpam
section.
|
| CVE-2013-1470 |
Cross-site scripting (XSS) vulnerability in calendar/index.php in the
Calendar plugin in Geeklog before 1.8.2sr1 and 2.0.0 before 2.0.0rc2
allows remote attackers to inject arbitrary web script or HTML via the
calendar_type parameter to submit.php.
|
| CVE-2013-1466 |
Multiple cross-site scripting (XSS) vulnerabilities in glFusion before
1.2.2.pl4 allow remote attackers to inject arbitrary web script or
HTML via the (1) subject parameter to profiles.php; (2) address1, (3)
address2, (4) calendar_type, (5) city, (6) state, (7) title, (8) url,
or (9) zipcode parameter to calendar/index.php; (10) title or (11) url
parameter to links/index.php; or (12) PATH_INFO to
admin/plugins/mediagallery/xppubwiz.php/.
|
| CVE-2013-1464 |
Cross-site scripting (XSS) vulnerability in assets/player.swf in the
Audio Player plugin before 2.0.4.6 for Wordpress allows remote
attackers to inject arbitrary web script or HTML via the playerID
parameter.
|
| CVE-2013-1463 |
Cross-site scripting (XSS) vulnerability in
js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before
1.9.4 for Wordpress allows remote attackers to inject arbitrary web
script or HTML via the id parameter. NOTE: this might be the same
vulnerability as CVE-2013-1808. If so, it is likely that
CVE-2013-1463 will be REJECTed.
|
| CVE-2013-1421 |
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar
before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote
attackers to inject arbitrary web script or HTML via the Category Name
field to category.php.
|
| CVE-2013-1413 |
Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit
open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.0.2 when
the 'sanitize user input' flag is not enabled, allow remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1409 |
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin
before 2.92.4 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the _ajax_nonce parameter to
wp-admin/admin-ajax.php.
|
| CVE-2013-1407 |
Multiple cross-site scripting (XSS) vulnerabilities in the Events
Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9
for WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) scope parameter to index.php; (2) user_name, (3)
dbem_phone, (4) user_email, or (5) booking_comment parameter to an
event with registration enabled; or the (6) _wpnonce parameter to
wp-admin/edit.php.
|
| CVE-2013-1393 |
Cross-site scripting (XSS) vulnerability in the CurvyCorners module
6.x-1.x and 7.x-1.x for Drupal allows remote authenticated users with
the "administer curvycorners" permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-1289 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010
SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject
arbitrary web script or HTML via a crafted string, aka "HTML
Sanitization Vulnerability."
|
| CVE-2013-1247 |
Cross-site scripting (XSS) vulnerability in the wireless configuration
module in Cisco Prime Infrastructure allows remote attackers to inject
arbitrary web script or HTML via an SSID that is not properly handled
during display of the XML windowing table, aka Bug ID CSCuf04356.
|
| CVE-2013-1244 |
Cross-site scripting (XSS) vulnerability in the portal module in Cisco
WebEx Social allows remote authenticated users to inject arbitrary web
script or HTML via a javascript: URL in the link field in a post, aka
Bug ID CSCue67199.
|
| CVE-2013-1227 |
Cross-site scripting (XSS) vulnerability in the web framework in Cisco
Unified Communications Domain Manager allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka Bug
ID CSCug37902.
|
| CVE-2013-1198 |
Cross-site scripting (XSS) vulnerability in a Flash component in Cisco
Unified Computing System (UCS) Central allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka Bug
ID CSCud15430.
|
| CVE-2013-1171 |
Multiple cross-site scripting (XSS) vulnerabilities in the
element-list implementation in Cisco Connected Grid Network Management
System (CG-NMS) allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors, aka Bug IDs CSCue14517, CSCue38914,
CSCue38884, CSCue38882, CSCue38881, CSCue38872, CSCue38868,
CSCue38866, CSCue38853, and CSCue14540.
|
| CVE-2013-1160 |
Cross-site scripting (XSS) vulnerability in the OpenView web menus in
Cisco Prime Central for Hosted Collaboration Solution allows remote
attackers to inject arbitrary web script or HTML via an unspecified
parameter, aka Bug ID CSCud56743.
|
| CVE-2013-1159 |
Cross-site scripting (XSS) vulnerability in the Netcool Impact (NCI)
web menus in Cisco Prime Central for Hosted Collaboration Solution
allows remote attackers to inject arbitrary web script or HTML via an
unspecified parameter, aka Bug ID CSCud56706.
|
| CVE-2013-1158 |
Cross-site scripting (XSS) vulnerability in the IBM Tivoli Monitoring
(ITM) help menus in Cisco Prime Central for Hosted Collaboration
Solution allows remote attackers to inject arbitrary web script or
HTML via an unspecified parameter, aka Bug ID CSCud54397.
|
| CVE-2013-1157 |
Cross-site scripting (XSS) vulnerability in the IBM Tivoli Monitoring
(ITM) Java servlet container in Cisco Prime Central for Hosted
Collaboration Solution allows remote attackers to inject arbitrary web
script or HTML via an unspecified parameter, aka Bug ID CSCud51068.
|
| CVE-2013-1132 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified
Communications Domain Manager allow remote attackers to inject
arbitrary web script or HTML via vectors involving the (1)
IptAccountMgmt, (2) IptFeatureConfigTemplateMgmt, (3)
IptFeatureDisplayPolicyMgmt, or (4) IptProviderMgmt page, aka Bug IDs
CSCud69972, CSCud70193, and CSCud70261.
|
| CVE-2013-1123 |
Multiple cross-site scripting (XSS) vulnerabilities in the server in
Cisco Unified MeetingPlace 7.0 allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters, aka Bug IDs
CSCuc65411 and CSCue18706.
|
| CVE-2013-1114 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity
Express before 8.0 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors, aka Bug ID CSCud87527.
|
| CVE-2013-1113 |
Cross-site scripting (XSS) vulnerability in Cisco Unified
Communications Domain Manager allows remote attackers to inject
arbitrary web script or HTML via a crafted parameter value, aka Bug ID
CSCue21042.
|
| CVE-2013-1097 |
Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in
Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a
Monthly Update 1 allows remote attackers to inject arbitrary web
script or HTML via vectors involving an onload event.
|
| CVE-2013-1096 |
Cross-site scripting (XSS) vulnerability in the Roles Based
Provisioning Module 4.0.2 before Field Patch D for Novell Identity
Manager (aka IDM) allows remote attackers to inject arbitrary web
script or HTML via a taskDetail taskId.
|
| CVE-2013-1095 |
Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in
Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a
Monthly Update 1 allows remote attackers to inject arbitrary web
script or HTML via vectors involving an onError event.
|
| CVE-2013-1094 |
Cross-site scripting (XSS) vulnerability in a ZCC page in
zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2
before 11.2.3a Monthly Update 1 allows remote attackers to inject
arbitrary web script or HTML via an invalid locale.
|
| CVE-2013-1088 |
Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7
before SP6 Patch 1 allows remote attackers to hijack the
authentication of arbitrary users by leveraging improper request
validation by iManager code deployed within an Apache Tomcat
container.
|
| CVE-2013-1087 |
Cross-site scripting (XSS) vulnerability in the client in Novell
GroupWise through 8.0.3 HP3, and 2012 through SP2, on Windows allows
user-assisted remote attackers to inject arbitrary web script or HTML
via the body of an e-mail message.
|
| CVE-2013-1086 |
Cross-site scripting (XSS) vulnerability in WebAccess in Novell
GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote
attackers to inject arbitrary web script or HTML via vectors involving
an onError attribute.
|
| CVE-2013-1070 |
Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as
a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject
arbitrary web script or HTML via the op parameter to nodes/.
|
| CVE-2013-1034 |
Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in
Apple Mac OS X Server before 2.2.2 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1013 |
XSS Auditor in WebKit in Apple Safari before 6.0.5 does not properly
rewrite URLs, which allows remote attackers to trigger unintended form
submissions via unspecified vectors.
|
| CVE-2013-1012 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 6.0.5 allows remote attackers to inject arbitrary web script or
HTML via vectors involving IFRAME elements.
|
| CVE-2013-0962 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before
6.1 allows user-assisted remote attackers to inject arbitrary web
script or HTML via crafted content that is not properly handled during
a copy-and-paste operation.
|
| CVE-2013-0942 |
Cross-site scripting (XSS) vulnerability in EMC RSA Authentication
Agent 7.1 before 7.1.1 for Web for Internet Information Services, and
7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0938 |
Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop
before 6.7 SP2, Documentum WDK before 6.7 SP2, Documentum Taskspace
before 6.7 SP2, and Documentum Records Manager before 6.7 SP2 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-0936 |
Cross-site scripting (XSS) vulnerability in EMC Smarts IP Manager,
Smarts Service Assurance Manager, Smarts Server Manager, Smarts VoIP
Availability Manager, Smarts Network Protocol Manager, and Smarts MPLS
Manager before 9.2 allows remote attackers to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2013-0933 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer
5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-0909 |
The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote
attackers to obtain sensitive HTTP Referer information via unspecified
vectors.
|
| CVE-2013-0807 |
Cross-site scripting (XSS) vulnerability in the NewSectionPrompt
function in include/tool/editing_page.php in gpEasy CMS 3.5.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the section parameter in a new_section action to index.php.
|
| CVE-2013-0805 |
Multiple cross-site scripting (XSS) vulnerabilities in the search
feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) text parameter to pages/UI.php or (2) expression parameter
to pages/run_query.php. NOTE: some of these details are obtained from
third party information.
|
| CVE-2013-0793 |
Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5,
Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and
SeaMonkey before 2.17 do not ensure the correctness of the address bar
during history navigation, which allows remote attackers to conduct
cross-site scripting (XSS) attacks or phishing attacks by leveraging
control over navigation timing.
|
| CVE-2013-0785 |
Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla
before 3.6.13, 3.7.x and 4.0.x before 4.0.10, 4.1.x and 4.2.x before
4.2.5, and 4.3.x and 4.4.x before 4.4rc2 allows remote attackers to
inject arbitrary web script or HTML via the id parameter in
conjunction with an invalid value of the format parameter.
|
| CVE-2013-0751 |
Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do
not restrict a touch event to a single IFRAME element, which allows
remote attackers to obtain sensitive information or possibly conduct
cross-site scripting (XSS) attacks via a crafted HTML document.
|
| CVE-2013-0741 |
Cross-site scripting (XSS) vulnerability in imagegen.ashx in
Percipient Studios ImageGen before 2.9.0 for Umbraco CMS allows remote
attackers to inject arbitrary web script or HTML via the font
parameter.
|
| CVE-2013-0736 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow
remote attackers to hijack the authentication of administrators for
requests that (1) modify user privileges or (2) conduct cross-site
scripting (XSS) attacks via unspecified vectors.
|
| CVE-2013-0734 |
Multiple cross-site scripting (XSS) vulnerabilities in the Mingle
Forum plugin before 1.0.34 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) search_words parameter
in a search action to wpf.class.php or (2) togroupusers parameter in
an add_user_togroup action to fs-admin/fs-admin.php.
|
| CVE-2013-0731 |
ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress
does not properly restrict access to unspecified Ajax functions, which
allows remote attackers to modify plugin settings and conduct
cross-site scripting (XSS) attacks by setting the wordpress_logged_in
cookie. NOTE: this is due to an incomplete fix for a similar issue
that was fixed in 1.3.2.
|
| CVE-2013-0730 |
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x
through 4.1.0 allow remote attackers to inject arbitrary web script or
HTML via vectors involving the (1) language parameter to
application/modules/admin/controllers/LanguagesController.php or (2)
user parameter to
application/modules/admin/controllers/UserController.php.
|
| CVE-2013-0709 |
Cross-site scripting (XSS) vulnerability in dopvSTAR* 0091 allows
remote attackers to inject arbitrary web script or HTML via the HTTP
Referer header, which is not properly handled during display of the
access log.
|
| CVE-2013-0708 |
Cross-site scripting (XSS) vulnerability in dopvCOMET* 0009b allows
remote attackers to inject arbitrary web script or HTML via the HTTP
Referer header, which is not properly handled during display of the
access log.
|
| CVE-2013-0703 |
Cross-site scripting (XSS) vulnerability in imgboard.com imgboard
before 1.22R6.1 u and 20xx before 2010u allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0702 |
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0
through 3.5.3 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-0688 |
Cross-site scripting (XSS) vulnerability in Invensys Wonderware
Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-0672 |
Cross-site scripting (XSS) vulnerability in the HMI web application in
Siemens WinCC (TIA Portal) 11 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified data.
|
| CVE-2013-0668 |
Multiple cross-site scripting (XSS) vulnerabilities in the HMI web
application in Siemens WinCC (TIA Portal) 11 allow remote attackers to
inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-0667 |
Cross-site scripting (XSS) vulnerability in the HMI web application in
Siemens WinCC (TIA Portal) 11 allows remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-0597 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application
Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before
8.5.5.0, when OAuth is used, allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0596 |
Cross-site scripting (XSS) vulnerability in the Administrative console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-0595 |
Multiple cross-site scripting (XSS) vulnerabilities in iNotes 8.5.x in
IBM Lotus Domino 8.5 before 8.5.3 FP5 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors, aka SPR
PTHN95XNR3.
|
| CVE-2013-0591 |
Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus
Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors, aka SPR
PTHN95XNR3, a different vulnerability than CVE-2013-0590.
|
| CVE-2013-0590 |
Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus
Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors, aka SPR
PTHN95XNR3, a different vulnerability than CVE-2013-0591.
|
| CVE-2013-0587 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere
Portal before 8.0.0.1 CF07 allow remote attackers to inject arbitrary
web script or HTML via vectors involving the (1) Portal, (2) Portal
7.0.0.2, (3) Portal 8.0, or (4) PortalWeb2 theme.
|
| CVE-2013-0586 |
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos
Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-0585 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere
Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allow
remote authenticated users to inject arbitrary web script or HTML via
vectors related to the (1) web console and (2) repository management
user interfaces.
|
| CVE-2013-0582 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated
Identity Manager (TFIM) 6.2.0 before 6.2.0.12, 6.2.1 before 6.2.1.5,
and 6.2.2 before 6.2.2.4 and Tivoli Federated Identity Manager
Business Gateway (TFIMBG) 6.2.0 before 6.2.0.12 and 6.2.1 before
6.2.1.5 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL that triggers a SAML 2.0 response.
|
| CVE-2013-0581 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Business
Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow
remote authenticated users to inject arbitrary web script or HTML via
vectors involving (1) ProcessPortal/jsp/socialPortal/dashboard.jsp,
(2) teamworks/executeServiceByName, (3)
portal/jsp/viewAdHocReportWizard.do, or (4) rest/bpm/wle/v1/process.
|
| CVE-2013-0576 |
Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise
Portal browser client in IBM Tivoli Monitoring 6.2.0 through FP03,
6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP02 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-0572 |
Cross-site scripting (XSS) vulnerability in IBM Document Connect for
Application Support Facility (aka DC4ASF) before 1.0.0.1218 in
Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and
AIX allows remote authenticated users to inject content, and conduct
phishing attacks, via unspecified vectors.
|
| CVE-2013-0571 |
Cross-site scripting (XSS) vulnerability in IBM Document Connect for
Application Support Facility (aka DC4ASF) before 1.0.0.1218 in
Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and
AIX allows remote attackers to inject arbitrary web script or HTML via
a crafted URL.
|
| CVE-2013-0569 |
Cross-site scripting (XSS) vulnerability in the Communities component
in IBM Connections 4.5 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-0566 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1)
Accelerator JSPs, (2) Organization Administration Console JSPs, and
(3) Administration Console JSPs in WebSphere Commerce Tools in IBM
WebSphere Commerce 5.6.1.0 through 5.6.1.5, 6.0.0.0 through 6.0.0.11,
and 7.0.0.0 through 7.0.0.7 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2013-0565 |
Cross-site scripting (XSS) vulnerability in the RPC adapter for the
Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS)
8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web
script or HTML via a crafted response.
|
| CVE-2013-0549 |
Cross-site scripting (XSS) vulnerability in the Web Content Manager -
Web Content Viewer Portlet in the server in IBM WebSphere Portal
7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the
IBM Portlet API is used, allows remote attackers to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2013-0548 |
Multiple cross-site scripting (XSS) vulnerabilities in the Basic
Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3,
6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in
IBM Application Manager for Smart Business (formerly Tivoli
Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004
and other products, allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-0542 |
Cross-site scripting (XSS) vulnerability in the Administrative console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0
before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows
remote attackers to inject arbitrary web script or HTML via crafted
field values.
|
| CVE-2013-0538 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before
8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 allows remote
attackers to inject arbitrary web script or HTML via a SCRIPT element
in an HTML e-mail message, aka SPRs JMOY95BLM6 and JMOY95BN49.
|
| CVE-2013-0535 |
Multiple cross-site scripting (XSS) vulnerabilities in the Classic
Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-0533 |
Cross-site scripting (XSS) vulnerability in the Sametime Links server
in IBM Sametime 8.0.2 through 8.5.2.1 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0525 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes
8.5.x allow local users to inject arbitrary web script or HTML via a
shared mail file, aka SPR DKEN8PDNTX.
|
| CVE-2013-0506 |
Cross-site scripting (XSS) vulnerability in IBM Sterling Order
Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0
before FP41, and 9.2.0 before FP13 allows remote authenticated users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0503 |
Cross-site scripting (XSS) vulnerability in the Bookmarks component in
IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0502 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information
Server 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1 allows remote
attackers to inject arbitrary web script or HTML via a malformed URL.
|
| CVE-2013-0499 |
Cross-site scripting (XSS) vulnerability in the echo functionality on
IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0,
4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary
web script or HTML via a SOAP message, as demonstrated by the XML
Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web
Token services.
|
| CVE-2013-0492 |
Cross-site scripting (XSS) vulnerability in IBM Informix Open Admin
Tool (OAT) 2.x and 3.x before 3.11.1 allows remote authenticated users
to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-0488 |
Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web
Administrator client) in IBM Domino 8.5.x allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0478 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data
Management - Collaborative Edition 10.0 and 10.1 before FP1 and
InfoSphere Master Data Management Server for Product Information
Management 6.0, 9.0, and 9.1 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0477 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere
Master Data Management - Collaborative Edition 10.0 and 10.1 before
FP1 and InfoSphere Master Data Management Server for Product
Information Management 6.0, 9.0, and 9.1 allow remote authenticated
users to inject content, and conduct phishing attacks, via unspecified
vectors.
|
| CVE-2013-0473 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Security
AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy
Tester 5.6 and 8.x before 8.5.0.4 allow remote attackers to inject
arbitrary web script or HTML via a crafted report.
|
| CVE-2013-0468 |
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B
Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2013-2983.
|
| CVE-2013-0466 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Message
Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is
enabled on a SOAPInput node, allows remote attackers to inject
arbitrary web script or HTML via a wsdl request that is not properly
handled during construction of an error message.
|
| CVE-2013-0464 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse
Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data
Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject
arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-0461 |
Cross-site scripting (XSS) vulnerability in the virtual member manager
(VMM) administrative console in IBM WebSphere Application Server (WAS)
6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5
before 8.5.0.2 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2013-0460 |
Cross-site request forgery (CSRF) vulnerability in the portlet
subsystem in the administrative console in IBM WebSphere Application
Server (WAS) 6.1 before 6.1.0.47 and 7.0 before 7.0.0.27 allows remote
attackers to hijack the authentication of arbitrary users for requests
that insert cross-site scripting (XSS) sequences.
|
| CVE-2013-0459 |
Cross-site scripting (XSS) vulnerability in the Administrative console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0
before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-0458 |
Cross-site scripting (XSS) vulnerability in the Administrative console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0
before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2, when
login security is disabled, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0457 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud
Control Desk 7.5 allows remote authenticated users to inject arbitrary
web script or HTML via vectors related to a uisessionid.
|
| CVE-2013-0455 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling
B2B Integrator 5.2.4 and Sterling File Gateway allow remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-0453 |
Cross-site scripting (XSS) vulnerability in Web Reports in IBM Tivoli
Endpoint Manager (TEM) before 8.2.1372 allows remote authenticated
users to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2013-0424 |
Unspecified vulnerability in the Java Runtime Environment (JRE)
component in Oracle Java SE 7 through Update 11, 6 through Update 38,
5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows
remote attackers to affect integrity via vectors related to RMI.
NOTE: the previous information is from the February 2013 CPU. Oracle
has not commented on claims from another vendor that this issue is
related to cross-site scripting (XSS) in the sun.rmi.transport.proxy
CGIHandler class that does not properly handle error messages in a (1)
command or (2) port number.
|
| CVE-2013-0328 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.502 and
LTS before 1.480.3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-0325 |
Multiple cross-site scripting (XSS) vulnerabilities in the Varnish
module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for
Drupal allow remote attackers to inject arbitrary web script or HTML
via crafted a (1) Watchdog message or (2) admin setting.
|
| CVE-2013-0324 |
Cross-site scripting (XSS) vulnerability in the Rendered links
formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for
Drupal allows remote authenticated users with the "Administer menus
and menu items" permission to inject arbitrary web script or HTML via
the menu link title.
|
| CVE-2013-0323 |
Cross-site scripting (XSS) vulnerability in the Display Suite module
7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows
remote attackers to inject arbitrary web script or HTML via the author
field.
|
| CVE-2013-0322 |
Cross-site scripting (XSS) vulnerability in Views in the Ubercart
module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to
inject arbitrary web script or HTML via the full name field.
|
| CVE-2013-0321 |
Cross-site scripting (XSS) vulnerability in Views in the Ubercart
Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote
attackers to inject arbitrary web script or HTML via the full name
field.
|
| CVE-2013-0319 |
Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module
6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows
remote attackers to inject arbitrary web script or HTML via vectors
related to the Yandex.Metrica service data.
|
| CVE-2013-0317 |
Cross-site scripting (XSS) vulnerability in the Manager Change for
Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for
Drupal might allow remote attackers to inject arbitrary web script or
HTML via the username in the new manager autocomplete field.
|
| CVE-2013-0307 |
Cross-site scripting (XSS) vulnerability in settings.php in ownCloud
before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to
inject arbitrary web script or HTML via the group input field
parameter.
|
| CVE-2013-0298 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x
before 4.5.7 allow remote attackers to inject arbitrary web script or
HTML via (1) a crafted iCalendar file to the calendar application, the
(2) dir or (3) file parameter to apps/files_pdfviewer/viewer.php, or
the (4) mountpoint parameter to
/apps/files_external/addMountPoint.php.
|
| CVE-2013-0297 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
4.0.12 and 4.5.x before 4.5.7 allow remote authenticated
administrators to inject arbitrary web script or HTML via the (1)
site_name or (2) site_url parameter to
apps/external/ajax/setsites.php.
|
| CVE-2013-0275 |
Multiple cross-site scripting (XSS) vulnerabilities in Ganglia Web
before 3.5.6 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2013-0259 |
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x
before 7.x-1.1 for Drupal allows remote authenticated users with
administer or edit boxes permissions to inject arbitrary web script or
HTML via the subject parameter.
|
| CVE-2013-0256 |
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before
4.0.0.preview2.1, as used in Ruby, does not properly generate
documents, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via a crafted URL.
|
| CVE-2013-0244 |
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and
7.x before 7.19, when running with older versions of jQuery that are
vulnerable to CVE-2011-4969, allows remote attackers to inject
arbitrary web script or HTML via vectors involving unspecified
Javascript functions that are used to select DOM elements.
|
| CVE-2013-0237 |
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode
plupload before 1.5.5, as used in WordPress before 3.5.1 and other
products, allows remote attackers to inject arbitrary web script or
HTML via the id parameter.
|
| CVE-2013-0236 |
Multiple cross-site scripting (XSS) vulnerabilities in WordPress
before 3.5.1 allow remote attackers to inject arbitrary web script or
HTML via vectors involving (1) gallery shortcodes or (2) the content
of a post.
|
| CVE-2013-0234 |
Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg
before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to
inject arbitrary web script or HTML via the params[twitter_username]
parameter to action/widgets/save.
|
| CVE-2013-0227 |
Cross-site scripting (XSS) vulnerability in the Search API Sorts
module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated
users with certain roles to inject arbitrary web script or HTML via
unspecified field labels.
|
| CVE-2013-0225 |
Cross-site scripting (XSS) vulnerability in the User Relationships
module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for
Drupal allows remote authenticated users with the "administer user
relationships" permission to inject arbitrary web script or HTML via a
relationship name.
|
| CVE-2013-0201 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5,
4.0.10, and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) QUERY_STRING to
core/lostpassword/templates/resetpassword.php, (2) mime parameter to
apps/files/ajax/mimeicon.php, or (3) token parameter to
apps/gallery/sharing.php.
|
| CVE-2013-0197 |
Cross-site scripting (XSS) vulnerability in the
filter_draw_selection_area2 function in core/filter_api.php in
MantisBT 1.2.12 before 1.2.13 allows remote attackers to inject
arbitrary web script or HTML via the match_type parameter to
bugs/search.php.
|
| CVE-2013-0181 |
Cross-site scripting (XSS) vulnerability in Views in the Search API
(search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using
certain backends and facets, allows remote attackers to inject
arbitrary web script or HTML via unspecified input, which is returned
in an error message.
|
| CVE-2013-0177 |
Multiple cross-site scripting (XSS) vulnerabilities in
widget/screen/ModelScreenWidget.java in Apache Open For Business
Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly
09.04.x allow remote authenticated users to inject arbitrary web
script or HTML via the (1) Screenlet.title or (2) Image.alt Widget
attribute, as demonstrated by the parentPortalPageId parameter to
exampleext/control/ManagePortalPages.
|
| CVE-2013-0134 |
Cross-site scripting (XSS) vulnerability in the web interface in
AirDroid allows remote attackers to inject arbitrary web script or
HTML via a crafted text message that is transmitted by a managed
phone.
|
| CVE-2013-0129 |
Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before
4.17 allow remote authenticated users to inject arbitrary web script
or HTML via (1) the WebFTP Overview "Create new directory" field or
(2) the body of an e-mail autoresponder message.
|
| CVE-2013-0125 |
Cross-site scripting (XSS) vulnerability in fileview.asp in C2
WebResource allows remote attackers to inject arbitrary web script or
HTML via the File parameter.
|
| CVE-2013-0124 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administration interface in ASKIA askiaweb allow remote attackers to
inject arbitrary web script or HTML via the (1) Number or (2)
UpdatePage parameter to WebProd/cgi-bin/AskiaExt.dll.
|
| CVE-2013-0083 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Server 2010 SP1 allows remote attackers to inject arbitrary web script
or HTML via crafted content, leading to administrative command
execution, aka "SharePoint XSS Vulnerability."
|
| CVE-2013-0010 |
Cross-site scripting (XSS) vulnerability in Microsoft System Center
Operations Manager 2007 SP1 and R2 allows remote attackers to inject
arbitrary web script or HTML via crafted input, aka "System Center
Operations Manager Web Console XSS Vulnerability," a different
vulnerability than CVE-2013-0009.
|
| CVE-2013-0009 |
Cross-site scripting (XSS) vulnerability in Microsoft System Center
Operations Manager 2007 SP1 and R2 allows remote attackers to inject
arbitrary web script or HTML via crafted input, aka "System Center
Operations Manager Web Console XSS Vulnerability," a different
vulnerability than CVE-2013-0010.
|
| CVE-2012-6705 |
Cross Site Scripting (XSS) exists in Jamroom before 4.2.7 via the
Status Update field.
|
| CVE-2012-6692 |
Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in
the WordPress SEO by Yoast plugin before 2.2 for WordPress allows
remote attackers to inject arbitrary web script or HTML via the
post_title parameter to wp-admin/post-new.php, which is not properly
handled in the snippet preview functionality.
|
| CVE-2012-6684 |
Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9
for Ruby and earlier allows remote attackers to inject arbitrary web
script or HTML via a javascript: URI.
|
| CVE-2012-6662 |
Cross-site scripting (XSS) vulnerability in the default content option
in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before
1.10.0 allows remote attackers to inject arbitrary web script or HTML
via the title attribute, which is not properly handled in the
autocomplete combo box demo.
|
| CVE-2012-6659 |
Cross-site scripting (XSS) vulnerability in the admin interface in
Phorum before 5.2.19 allows remote attackers to inject arbitrary web
script or HTML via a crafted URL.
|
| CVE-2012-6658 |
Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks
5.3.75941 allow remote attackers to inject arbitrary web script or
HTML via the (1) syslocation, (2) syscontact, or (3) sysName
configuration in snmpd.conf. NOTE: this entry was SPLIT from
CVE-2012-2956 per ADT2 due to different vulnerability types.
|
| CVE-2012-6645 |
Cross-site scripting (XSS) vulnerability in the autocomplete
functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x,
and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers
to inject arbitrary web script or HTML via the title of a node, a
different vulnerability than CVE-2012-1561.
|
| CVE-2012-6644 |
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6
allow remote attackers to inject arbitrary web script or HTML via the
(1) cat parameter to channels.php, (2) collections.php, (3)
groups.php, or (4) videos.php; (5) query parameter to
search_result.php; or (6) type parameter to view_collection.php or (7)
view_item.php.
|
| CVE-2012-6642 |
Cross-site scripting (XSS) vulnerability in ClipBucket 2.6 allows
remote attackers to inject arbitrary web script or HTML via the type
parameter to view_channel.php. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2012-6641 |
Cross-site scripting (XSS) vulnerability in redirect.php in the
Socolissimo module (modules/socolissimo/) in PrestaShop before 1.4.7.2
allows remote attackers to inject arbitrary web script or HTML via
vectors related to "parameter names and values."
|
| CVE-2012-6640 |
Cross-site scripting (XSS) vulnerability in Horde Internet Mail
Program (IMP) before 5.0.22, as used in Horde Groupware Webmail
Edition before 4.0.9, allows remote attackers to inject arbitrary web
script or HTML via a crafted SVG image attachment, a different
vulnerability than CVE-2012-5565.
|
| CVE-2012-6633 |
Cross-site scripting (XSS) vulnerability in
wp-includes/default-filters.php in WordPress before 3.3.3 allows
remote attackers to inject arbitrary web script or HTML via an
editable slug field.
|
| CVE-2012-6632 |
Multiple cross-site scripting (XSS) vulnerabilities in Vessio NetBill
1.2 allow remote attackers to inject arbitrary web script or HTML via
the (1) full name or (2) file title to accounts/admin/index.php or (3)
comment parameter in the support page to accounts/index2.php.
|
| CVE-2012-6630 |
Multiple cross-site scripting (XSS) vulnerabilities in the Media
Library Categories plugin 1.1.1 for WordPress allow remote attackers
to inject arbitrary web script or HTML via the (1) bulk parameter to
media-library-categories/add.php or (2) q parameter to
media-library-categories/view.php.
|
| CVE-2012-6628 |
Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter
Manager plugin before 1.0.2 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) xyz_em_campName to
admin/create_campaign.php or (2) admin/edit_campaign.php, (3)
xyz_em_email parameter to admin/edit_email.php, (4)
xyz_em_exportbatchSize parameter to import_export.php, or (5)
pagination limit in the Newsletter Manager options.
|
| CVE-2012-6627 |
Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the
Newsletter Manager plugin 1.0.2 and earlier for WordPress allows
remote attackers to inject arbitrary web script or HTML via the id
parameter.
|
| CVE-2012-6624 |
Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold
plugin 2.1 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the width parameter in a
soundcloud_is_gold_player_preview action to wp-admin/admin-ajax.php.
|
| CVE-2012-6623 |
Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php
in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
groupid parameter in an addforum action to wp-admin/admin.php.
|
| CVE-2012-6622 |
Multiple cross-site scripting (XSS) vulnerabilities in
fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before
1.7.4 for WordPress allow remote attackers to inject arbitrary web
script or HTML via the (1) groupid parameter in an editgroup action or
(2) usergroup_id parameter in an edit_usergroup action.
|
| CVE-2012-6621 |
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS
3.1, 3.1.2, 3.2.3, and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) Email Address or (2) Custom
Permalink Structure fields in admin/settings.php; (3) path parameter
to admin/upload.php; (4) err parameter to admin/theme.php; (5) error
parameter to admin/pages.php; or (6) success or (7) err parameter to
admin/index.php.
|
| CVE-2012-6620 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) tasks
and (2) search views in Horde Kronolith H4 before 3.0.17 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-6608 |
Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in
Elastix 2.3.0 allows remote attackers to inject arbitrary web script
or HTML via the Page parameter.
|
| CVE-2012-6589 |
Cross-site scripting (XSS) vulnerability in search.php in MYRE
Business Directory allows remote attackers to inject arbitrary web
script or HTML via the look parameter.
|
| CVE-2012-6587 |
Cross-site scripting (XSS) vulnerability in
vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software
allows remote attackers to inject arbitrary web script or HTML via the
link_idd parameter in a login action.
|
| CVE-2012-6585 |
Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty
Manager allows remote attackers to inject arbitrary web script or HTML
via the cat_id1 parameter.
|
| CVE-2012-6583 |
Cross-site scripting (XSS) vulnerability in the Imagemenu module
6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users
with the "administer imagemenu" permission to inject arbitrary web
script or HTML via an image file name.
|
| CVE-2012-6582 |
Cross-site scripting (XSS) vulnerability in the Spambot module 6.x-3.x
before 6.x-3.2 and 7.x-1.x before 7.x-1.1 for Drupal allows certain
remote attackers to inject arbitrary web script or HTML via a
stopforumspam.com API response, which is logged by the watchdog.
|
| CVE-2012-6576 |
Cross-site scripting (XSS) vulnerability in the PRH Search module
7.x-1.x before 7.x-1.1 for Drupal allows remote attackers from certain
sources to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-6575 |
Cross-site scripting (XSS) vulnerability in the Exposed Filter Data
module 6.x-1.x before 6.x-1.2 for Drupal allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-6574 |
Cross-site scripting (XSS) vulnerability in the Fonecta verify module
7.x-1.x before 7.x-1.6 for Drupal allows remote attackers from certain
sources to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-6573 |
Cross-site scripting (XSS) vulnerability in the Apache Solr
Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3
for Drupal allows remote attackers to inject arbitrary web script or
HTML via vectors involving autocomplete results.
|
| CVE-2012-6572 |
Cross-site scripting (XSS) vulnerability in the
phptemplate_preprocess_node function in template.php in the Inf08
theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated
users with the "administer taxonomy" permission to inject arbitrary
web script or HTML via a taxonomy vocabulary name.
|
| CVE-2012-6566 |
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-6565 |
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3
allows remote authenticated users to inject arbitrary web script or
HTML via uppercase characters in JavaScript events within user-defined
labels.
|
| CVE-2012-6564 |
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-6561 |
Cross-site scripting (XSS) vulnerability in engine/lib/views.php in
Elgg before 1.8.5 allows remote attackers to inject arbitrary web
script or HTML via the view parameter to index.php. NOTE: some of
these details are obtained from third party information.
|
| CVE-2012-6559 |
Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02
allow remote attackers to inject arbitrary web script or HTML via the
(1) comment, (2) mac, (3) graphtype, (4) name, or (5) type parameter
to stats.php; or (6) comment parameter to deviceadd.php.
|
| CVE-2012-6557 |
Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe
plugin 1.1.1 for Vanilla Forums allow remote attackers to inject
arbitrary web script or HTML via the (1) AboutMe/RealName, (2)
AboutMe/Name, (3) AboutMe/Quote, (4) AboutMe/Loc, (5) AboutMe/Emp, (6)
AboutMe/JobTit, (7) AboutMe/HS, (8) AboutMe/Col, (9) AboutMe/Bio, (10)
AboutMe/Inter, (11) AboutMe/Mus, (12) AboutMe/Gam, (13) AboutMe/Mov,
(14) AboutMe/FTV, or (15) AboutMe/Bks parameter to the Edit My Details
page. NOTE: some of these details are obtained from third party
information.
|
| CVE-2012-6556 |
Multiple cross-site scripting (XSS) vulnerabilities in the
FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers
to inject arbitrary web script or HTML via the (1) User/FirstName or
(2) User/LastName parameter to the edit user page. NOTE: some of these
details are obtained from third party information.
|
| CVE-2012-6555 |
Cross-site scripting (XSS) vulnerability in the LatestComment plugin
1.1 for Vanilla Forums allows remote attackers to inject arbitrary web
script or HTML via the discussion title.
|
| CVE-2012-6550 |
Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4
allows remote attackers to inject arbitrary web script or HTML via
"the clipText returned from the flash object," a different
vulnerability than CVE-2013-1808.
|
| CVE-2012-6528 |
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before
2.1 allow remote attackers to inject arbitrary web script or HTML via
the PATH_INFO to (1) themes/default/tile_search/index.tmpl.php, (2)
login.php, (3) search.php, (4) password_reminder.php, (5)
login.php/jscripts/infusion, (6) login.php/mods/_standard/flowplayer,
(7) browse.php/jscripts/infusion/framework/fss, (8)
registration.php/themes/default/ie_styles.css, (9) about.php, or (10)
themes/default/social/basic_profile.tmpl.php.
|
| CVE-2012-6527 |
Cross-site scripting (XSS) vulnerability in the My Calendar plugin
before 1.10.2 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2012-6523 |
Multiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01
allow remote attackers to inject arbitrary web script or HTML via (1)
the p parameter in the getMenus function in codes/wcms.php; or the
COMMENT parameter in (2) blog.php, (3) guestbook.php, or (4) forum.php
in codes/. NOTE: some of these details are obtained from third party
information.
|
| CVE-2012-6521 |
Cross-site scripting (XSS) vulnerability in
apps/admin/handlers/versions.php in Elefant CMS 1.2.0 allows remote
attackers to inject arbitrary web script or HTML via the id parameter
to admin/versions.
|
| CVE-2012-6520 |
Multiple SQL injection vulnerabilities in the advanced search in
Wikidforum 2.10 allow remote attackers to execute arbitrary SQL
commands via the (1) select_sort or (2) opt_search_select parameters.
NOTE: this issue could not be reproduced by third parties.
|
| CVE-2012-6517 |
Multiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) question parameter to in /modules/poll/add.php or (2) question or
(3) answer parameter to modules/poll/edit.php.
|
| CVE-2012-6514 |
Cross-site scripting (XSS) vulnerability in the nBill (com_nbill)
component 2.3.2 for Joomla! allows remote attackers to inject
arbitrary web script or HTML via the message parameter in an income
action to administrator/index.php.
|
| CVE-2012-6513 |
Cross-site scripting (XSS) vulnerability in
index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote
attackers to inject arbitrary web script or HTML via the jsoncallback
parameter.
|
| CVE-2012-6511 |
Multiple cross-site scripting (XSS) vulnerabilities in
organizer/page/users.php in the Organizer plugin 1.2.1 for WordPress
allow remote attackers to inject arbitrary web script or HTML via the
(1) delete_id parameter or (2) extension parameter in an "Update
Setting" action to wp-admin/admin.php.
|
| CVE-2012-6510 |
Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media
Car Portal 3.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) PWRS or (2) Description field when posting a new
vehicle; (3) news title when creating news; (4) Name when creating a
sub user; (5) group name when creating a group; or (6) dealer name,
(7) first name, or (8) last name when changing a profile.
|
| CVE-2012-6506 |
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web
Shop plugin 2.4.0 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) page parameter in
zing.inc.php or (2) notes parameter in
fws/pages-front/onecheckout.php.
|
| CVE-2012-6505 |
Cross-site scripting (XSS) vulnerability in
mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows
remote attackers to inject arbitrary web script or HTML via the id
parameter.
|
| CVE-2012-6464 |
Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows
remote attackers to inject arbitrary web script or HTML via crafted
JavaScript code that overrides methods of unspecified native objects
in documents that have different origins.
|
| CVE-2012-6463 |
Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows
remote attackers to inject arbitrary web script or HTML via vectors
involving an unspecified sequence of loading of documents and loading
of data: URLs.
|
| CVE-2012-6458 |
Multiple cross-site scripting (XSS) vulnerabilities in the
SilverStripe e-commerce module 3.0 for SilverStripe CMS allow remote
attackers to inject arbitrary web script or HTML via the (1)
FirstName, (2) Surname, or (3) Email parameter to
code/forms/OrderFormAddress.php; or the (4) FirstName or (5) Surname
parameter to code/forms/ShopAccountForm.php.
|
| CVE-2012-6453 |
Cross-site scripting (XSS) vulnerability in the RSS Reader extension
before 0.2.6 for MediaWiki allows remote attackers to inject arbitrary
web script or HTML via a crafted feed.
|
| CVE-2012-6447 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 5.0.0
through 5.0.2 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2012-6433 |
Cross-site request forgery (CSRF) vulnerability in
e107_admin/newspost.php in e107 1.0.1 allows remote attackers to
hijack the authentication of administrators for requests that conduct
XSS attacks via the news_title parameter in a create action.
|
| CVE-2012-6430 |
Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms
5.0 and Quick.Cart 6.0, possibly as downloaded before December 19,
2012, allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to admin.php. NOTE: this might be a duplicate of
CVE-2008-4140.
|
| CVE-2012-6397 |
Cross-site scripting (XSS) vulnerability in Cisco WebEx Social
(formerly Cisco Quad) allows remote attackers to inject arbitrary web
script or HTML via a crafted RSS service link, aka Bug ID CSCub61977.
|
| CVE-2012-6369 |
Cross-site scripting (XSS) vulnerability in the Troubleshooting
Reporting System feature in AgileBits 1Password 3.9.9 might allow
remote attackers to inject arbitrary web script or HTML via a crafted
User-Agent HTTP header that is not properly handled in a View
Troubleshooting Report action.
|
| CVE-2012-6360 |
Cross-site scripting (XSS) vulnerability in IBM Intelligent Operations
Center 1.5.0 allows remote attackers to inject arbitrary web script or
HTML via event data fields.
|
| CVE-2012-6350 |
Cross-site scripting (XSS) vulnerability in the Web component in IBM
Cognos TM1 before 9.5.2 FP3 and 10.1 before 10.1 FP1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-6339 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative web interface in Cerberus FTP Server before 5.0.6.0
allow (1) remote attackers to inject arbitrary web script or HTML via
a log entry that is not properly handled within the Log Manager
component, and might allow (2) remote authenticated administrators to
inject arbitrary web script or HTML via a Messages field to the
servermanager program.
|
| CVE-2012-6316 |
Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK
TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and
earlier allow remote administrators to inject arbitrary web script or
HTML via the (1) username or (2) pwd parameter to
userRpm/NoipDdnsRpm.htm.
|
| CVE-2012-6312 |
Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin
for WordPress allows remote attackers to inject arbitrary web script
or HTML via the errMsg parameter in a video-lead-form action to
wp-admin/admin.php.
|
| CVE-2012-6272 |
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage
Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote
attackers to inject arbitrary web script or HTML via the topic
parameter to html/index_main.htm in (1)
help/sm/en/Output/wwhelp/wwhimpl/js/, (2)
help/sm/es/Output/wwhelp/wwhimpl/js/, (3)
help/sm/ja/Output/wwhelp/wwhimpl/js/, (4)
help/sm/de/Output/wwhelp/wwhimpl/js/, (5)
help/sm/fr/Output/wwhelp/wwhimpl/js/, (6)
help/sm/zh/Output/wwhelp/wwhimpl/js/, (7)
help/hip/en/msgguide/wwhelp/wwhimpl/js/, or (8)
help/hip/en/msgguide/wwhelp/wwhimpl/common/.
|
| CVE-2012-6149 |
Multiple cross-site scripting (XSS) vulnerabilities in
systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite
5.6 allow remote attackers to inject arbitrary web script or HTML via
the (1) subject or (2) content values of a note in a system.addNote
XML-RPC call.
|
| CVE-2012-6148 |
Cross-site scripting (XSS) vulnerability in the function menu API in
TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6
allows remote authenticated backend users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-6147 |
Cross-site scripting (XSS) vulnerability in the tree render API
(TCA-Tree) in the Backend API in TYPO3 4.5.x before 4.5.21, 4.6.x
before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated
backend users to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-6145 |
Cross-site scripting (XSS) vulnerability in the Backend History module
in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before
4.7.6 allows remote authenticated backend users to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-6132 |
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20
allows remote attackers to inject arbitrary web script or HTML via the
otk parameter.
|
| CVE-2012-6131 |
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup
before 1.4.20 allows remote attackers to inject arbitrary web script
or HTML via the @action parameter to support/issue1.
|
| CVE-2012-6130 |
Cross-site scripting (XSS) vulnerability in the history display in
Roundup before 1.4.20 allows remote attackers to inject arbitrary web
script or HTML via a username, related to generating a link.
|
| CVE-2012-6121 |
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before
0.8.5 allows remote attackers to inject arbitrary web script or HTML
via a (1) data:text or (2) vbscript link.
|
| CVE-2012-6092 |
Multiple cross-site scripting (XSS) vulnerabilities in the web demos
in Apache ActiveMQ before 5.8.0 allow remote attackers to inject
arbitrary web script or HTML via (1) the refresh parameter to
PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data
Publisher), or vectors involving (2) debug logs or (3) subscribe
messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by
CVE-2012-6551.
|
| CVE-2012-6082 |
Cross-site scripting (XSS) vulnerability in the rsslink function in
theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject
arbitrary web script or HTML via the page name in a rss link.
|
| CVE-2012-6074 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.491,
Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before
1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1
allows remote authenticated users with write access to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-6045 |
Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui
Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary
web script or HTML via the query parameter.
|
| CVE-2012-6043 |
Cross-site scripting (XSS) vulnerability in downloads.php in
PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web
script or HTML via the cat_id parameter.
|
| CVE-2012-6040 |
Cross-site scripting (XSS) vulnerability in users.php in File King
Advanced File Management 1.4 allows remote attackers to inject
arbitrary web script or HTML via the page parameter.
|
| CVE-2012-6037 |
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x
before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2,
allow remote attackers to inject arbitrary web script or HTML via a
CSV header with "unknown fields," which are not properly handled in
error messages in the (1) bulk user, (2) group, and (3) group member
upload capabilities. NOTE: this issue was originally part of
CVE-2012-2243, but that ID was SPLIT due to different issues by
different researchers.
|
| CVE-2012-6029 |
Multiple cross-site scripting (XSS) vulnerabilities in the
web-authentication function on the Cisco NAC Appliance 4.9.2 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) cm or (2) uri parameters to (a) perfigo_weblogin.jsp, or
the (3) cm, (4) provider, (5) session, (6) uri, (7) userip, or (8)
username parameters to (b) perfigo_cm_validate.jsp, aka Bug ID
CSCud15109.
|
| CVE-2012-6007 |
Cross-site scripting (XSS) vulnerability in
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller
(WLC) devices with software 7.2.110.0 allows remote authenticated
users to inject arbitrary web script or HTML via the headline
parameter, aka Bug ID CSCud65187, a different vulnerability than
CVE-2012-5992.
|
| CVE-2012-5992 |
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco
Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow
remote attackers to hijack the authentication of administrators for
requests that (1) add administrative accounts via
screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the
headline parameter to screens/base/web_auth_custom.html, aka Bug ID
CSCud50283.
|
| CVE-2012-5990 |
Multiple cross-site scripting (XSS) vulnerabilities in Health Monitor
Login pages in Cisco Prime Network Control System (NCS) and Wireless
Control System (WCS) allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors, aka Bug ID CSCud18375.
|
| CVE-2012-5956 |
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine
AssetExplorer 5.6 before service pack 5614 allow remote attackers to
inject arbitrary web script or HTML via fields in XML asset data to
discoveryServlet/WsDiscoveryServlet, as demonstrated by the
DocRoot/Computer_Information/output element.
|
| CVE-2012-5949 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA
Application Platform 2.x and 3.x before 3.3, and 8, allow remote
attackers to inject content, and conduct phishing attacks, via vectors
involving (1) the html/en/default/ directory, (2) birt/frameset, (3)
WebProcess.srv, (4)
sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp, or (5)
a/html/en/default/om2/omObjectFinder.jsp.
|
| CVE-2012-5948 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA
Application Platform 2.x and 3.x before 3.3, and 8, allow remote
attackers to inject arbitrary web script or HTML via vectors involving
(1) WebProcess.srv, (2) the html/en/default/ directory, (3)
Widget/resource, (4) birt/frameset, or (5) ganttlib/gantt-jws.jnlp.
|
| CVE-2012-5943 |
Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before
8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary
web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.
|
| CVE-2012-5942 |
Cross-site scripting (XSS) vulnerability in the Data Management Portal
Web User Interface in IBM Tivoli Application Dependency Discovery
Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users
to inject content, and conduct phishing attacks, via unspecified
vectors.
|
| CVE-2012-5941 |
Cross-site scripting (XSS) vulnerability in the WebAdmin application
6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote
authenticated users to inject content, and conduct phishing attacks,
via unspecified vectors.
|
| CVE-2012-5939 |
Cross-site scripting (XSS) vulnerability in Welcome.do in the Data
Management Portal Web User Interface in IBM Tivoli Application
Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows
remote authenticated users to inject arbitrary web script or HTML via
a crafted URL.
|
| CVE-2012-5920 |
Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT)
2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1
and possibly other products, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors. NOTE: this
issue exists because of an incomplete fix for CVE-2012-4563.
|
| CVE-2012-5919 |
Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) find or (2) replace fields to
havalite/findReplace.php; (3) username parameter to
havalite/hava_login.php, (4) the Edit Article module, or (5)
hava_post.php in the postAuthor module; (6) postId parameter to
hava_post.php; (7) userId parameter to hava_user.php; or (8) linkId
parameter to hava_link.php.
|
| CVE-2012-5914 |
Multiple cross-site scripting (XSS) vulnerabilities in the sed_import
function in system/functions.php in Neocrome Seditio build 160 and 161
allow remote attackers to inject arbitrary web script or HTML via the
(1) newmsg or (2) rtext parameter. NOTE: some of these details are
obtained from third party information.
|
| CVE-2012-5913 |
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the
WordPress Integrator module 1.32 for WordPress allows remote attackers
to inject arbitrary web script or HTML via the redirect_to parameter
to wp-login.php.
|
| CVE-2012-5911 |
Cross-site scripting (XSS) vulnerability in blogs/blog1.php in
b2evolution 4.1.3 allows remote attackers to inject arbitrary web
script or HTML via the message body.
|
| CVE-2012-5908 |
Cross-site scripting (XSS) vulnerability in
admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6
allows remote attackers to inject arbitrary web script or HTML via the
conditions[usergroup][] parameter in a search action to
admin/index.php.
|
| CVE-2012-5906 |
Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser
6.1.0117 and 6.1.0216 allow remote attackers to inject arbitrary web
script or HTML via (1) the URI in an about: page or (2) the last
visited URL in the LastVisitWriteEn function in function.js.
|
| CVE-2012-5903 |
Cross-site scripting (XSS) vulnerability in Simple Machines Forum
(SMF) 2.0.2 allows remote attackers to inject arbitrary web script or
HTML via the scheduled parameter to index.php.
|
| CVE-2012-5902 |
Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php
in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web
script or HTML via the arg4 parameter.
|
| CVE-2012-5899 |
Cross-site scripting (XSS) vulnerability in admin/action/objects.php
in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary
web script or HTML via the OTR_HEADS[] parameter in an edit action.
NOTE: some of these details are obtained from third party information.
|
| CVE-2012-5889 |
Cross-site scripting (XSS) vulnerability in the powermail extension
before 1.6.5 for TYPO3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-5888 |
Cross-site scripting (XSS) vulnerability in Basic SEO Features
(seo_basics) extension before 0.8.2 for TYPO3 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-5883 |
Cross-site scripting (XSS) vulnerability in the Flash component
infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x
and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and
4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web
script or HTML via vectors related to swfstore.swf, a similar issue to
CVE-2010-4209.
|
| CVE-2012-5882 |
Cross-site scripting (XSS) vulnerability in the Flash component
infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to
inject arbitrary web script or HTML via vectors related to
uploader.swf, a similar issue to CVE-2010-4208.
|
| CVE-2012-5881 |
Cross-site scripting (XSS) vulnerability in the Flash component
infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to
inject arbitrary web script or HTML via vectors related to charts.swf,
a similar issue to CVE-2010-4207.
|
| CVE-2012-5866 |
Cross-site scripting (XSS) vulnerability in include.php in Achievo
1.4.5 allows remote attackers to inject arbitrary web script or HTML
via the field parameter.
|
| CVE-2012-5856 |
Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka
uk-cookie) plugin for WordPress allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-5851 |
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google
Chrome through 22 and Safari 5.1.7, does not consider all possible
output contexts of reflected data, which makes it easier for remote
attackers to bypass a cross-site scripting (XSS) protection mechanism
via a crafted string, aka rdar problem 12019108.
|
| CVE-2012-5841 |
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11,
Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and
SeaMonkey before 2.14 implement cross-origin wrappers with a filtering
behavior that does not properly restrict write actions, which allows
remote attackers to conduct cross-site scripting (XSS) attacks via a
crafted web site.
|
| CVE-2012-5837 |
The Web Developer Toolbar in Mozilla Firefox before 17.0 executes
script with chrome privileges, which allows user-assisted remote
attackers to conduct cross-site scripting (XSS) attacks via a crafted
string.
|
| CVE-2012-5762 |
Cross-site scripting (XSS) vulnerability in the WebAdmin application
6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote
authenticated users to inject arbitrary web script or HTML via vectors
involving the MHTML protocol.
|
| CVE-2012-5761 |
Cross-site scripting (XSS) vulnerability in the WebAdmin application
6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-5757 |
Cross-site scripting (XSS) vulnerability in the Web Client in IBM
Rational ClearQuest 7.1.x before 7.1.2.10 and 8.x before 8.0.0.6
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2012-5744 |
Multiple cross-site scripting (XSS) vulnerabilities in the guest
portal in Cisco Identity Services Engine (ISE) Software allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka Bug IDs CSCud11139 and CSCug02904.
|
| CVE-2012-5705 |
Cross-site scripting (XSS) vulnerability in the settings page
(admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before
6.x-1.8 for Drupal allows remote authenticated users with the
"administer hotblocks" permission to inject arbitrary web script or
HTML via the "block names."
|
| CVE-2012-5702 |
Multiple cross-site scripting (XSS) vulnerabilities in dotProject
before 2.1.7 allow remote attackers to inject arbitrary web script or
HTML via the (1) callback parameter in a color_selector action, (2)
field parameter in a date_format action, or (3) company_name parameter
in an addedit action to index.php. NOTE: the date parameter vector is
already covered by CVE-2008-3886.
|
| CVE-2012-5700 |
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko
before 1.2.2f allow remote attackers to inject arbitrary web script or
HTML via the (1) id parameter to admin/index.php or the (2) username
or (3) password parameter in blocks/loginbox/loginbox.template.php to
index.php. NOTE: some of these details are obtained from third party
information.
|
| CVE-2012-5684 |
Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
inFullname parameter in an UpdateAccountSettings action in the
my_account module to zpanel/.
|
| CVE-2012-5683 |
Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel
10.0.1 and earlier allow remote attackers to hijack the authentication
of administrators for requests that (1) create new FTP users via a
CreateFTP action in the ftp_management module to the default URI, (2)
conduct cross-site scripting (XSS) attacks via the inFullname
parameter in an UpdateAccountSettings action in the my_account module
to zpanel/, or (3) conduct SQL injection attacks via the
inEmailAddress parameter in an UpdateClient action in the
manage_clients module to the default URI.
|
| CVE-2012-5666 |
Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js
in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote
attackers to inject arbitrary web script or HTML via the PATH_INFO to
apps/bookmark/index.php.
|
| CVE-2012-5650 |
Cross-site scripting (XSS) vulnerability in the Futon UI in Apache
CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified parameters to the browser-based test suite.
|
| CVE-2012-5636 |
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before
1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote
attackers to inject arbitrary web script or HTML via vectors related
to <script> tags in a rendered response.
|
| CVE-2012-5608 |
Cross-site scripting (XSS) vulnerability in
apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2
allows remote attackers to inject arbitrary web script or HTML via
arbitrary POST parameters.
|
| CVE-2012-5606 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
4.0.9 and 4.5.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) file name to apps/files_versions/js/versions.js or
(2) apps/files/js/filelist.js; or (3) event title to
3rdparty/fullcalendar/js/fullcalendar.js.
|
| CVE-2012-5591 |
Cross-site scripting (XSS) vulnerability in the Zero Point module
6.x-1.x before 6.x-1.18 and 7.x-1.x before 7.x-1.4 for Drupal allows
remote attackers to inject arbitrary web script or HTML via the path
aliases.
|
| CVE-2012-5587 |
Cross-site scripting (XSS) vulnerability in the Email Field module
6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via the mailto link.
|
| CVE-2012-5585 |
Cross-site scripting (XSS) vulnerability in the Mixpanel module
6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users
with the "access administration pages" permission to inject arbitrary
web script or HTML via the Maxpanel token.
|
| CVE-2012-5569 |
Multiple cross-site scripting (XSS) vulnerabilities in the Basic
webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote
attackers to inject arbitrary web script or HTML via a (1) page title
or (2) crafted email message.
|
| CVE-2012-5567 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith
Calendar Application H4 before 3.0.18, as used in Horde Groupware
Webmail Edition before 4.0.9, allow remote attackers to inject
arbitrary web script or HTML via crafted event location parameters in
the (1) month, (2) monthlist, or (3) prevmonthlist fields, related to
portal blocks.
|
| CVE-2012-5566 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith
Calendar Application H4 before 3.0.17, as used in Horde Groupware
Webmail Edition before 4.0.8, allow remote attackers to inject
arbitrary web script or HTML via the (1) tasks view or (2) search
view.
|
| CVE-2012-5565 |
Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in
Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde
Groupware Webmail Edition before 4.0.9, allows remote attackers to
inject arbitrary web script or HTML via a crafted name for an attached
file, related to the dynamic view.
|
| CVE-2012-5559 |
Cross-site scripting (XSS) vulnerability in the page manager node view
task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10
for Drupal allows remote authenticated users with permissions to
submit or edit nodes to inject arbitrary web script or HTML via the
page title.
|
| CVE-2012-5553 |
Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu
module 6.x-1.x before 6.x-1.44 and 7.x-1.x before 7.x-1.44 for Drupal
allow remote authenticated users with the "administer OM Maximenu"
permission to inject arbitrary web script or HTML via the (1) Menu
Title (2) Link Title, (3) Path Query, (4) Anchor, or (5) vocabulary
names.
|
| CVE-2012-5551 |
Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp
module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to
inject arbitrary web script or HTML via vectors related to (1) a
predictable "webhook URL key" and (2) improper sanitization of
"Webhook variables from POST requests."
|
| CVE-2012-5548 |
Cross-site scripting (XSS) vulnerability in the Time Spent module 6.x
and 7.x for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-5545 |
Multiple cross-site scripting (XSS) vulnerabilities in the ShareThis
module 7.x-2.x before 7.x-2.5 for Drupal allow remote authenticated
users with the "administer sharethis" permission to inject arbitrary
web script or HTML via unspecified vectors related to "JavaScript
settings."
|
| CVE-2012-5541 |
Cross-site scripting (XSS) vulnerability in the Twitter Pull module
6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.0-rc3 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to "data coming from Twitter."
|
| CVE-2012-5540 |
Multiple cross-site scripting (XSS) vulnerabilities in the Hostip
module 6.x-2.x before 6.x-2.2 and 7.x-2.x before 7.x-2.2 for Drupal
allow remote attackers with control of hostip.info to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-5538 |
Cross-site scripting (XSS) vulnerability in the FileField Sources
module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal,
when the field has "Reference existing" source enabled, allows remote
authenticated users to inject arbitrary web script or HTML via the
filename of an uploaded file.
|
| CVE-2012-5531 |
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn
Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-5504 |
Cross-site scripting (XSS) vulnerability in widget_traversal.py in
Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-5502 |
Cross-site scripting (XSS) vulnerability in safe_html.py in Plone
before 4.2.3 and 4.3 before beta 1 allows remote authenticated users
with permissions to edit content to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-5494 |
Cross-site scripting (XSS) vulnerability in python_scripts.py in Plone
before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to
"{u,}translate."
|
| CVE-2012-5490 |
Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone
before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-5460 |
Cross-site scripting (XSS) vulnerability in the help page in Juniper
Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and
7.3.x before 7.3r2 allows remote attackers to inject arbitrary web
script or HTML via the WWHSearchWordsText parameter.
|
| CVE-2012-5455 |
Cross-site scripting (XSS) vulnerability in the language search
component in Joomla! before 3.0.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to a
"typographical error."
|
| CVE-2012-5452 |
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS
2.2.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days,
or (4) title[en] parameter to plans/add/; (5) name or (6) title[en]
parameter to fields/group/add/ in admin/manage/; or (7)
f[accounts][fullname] or (8) f[accounts][username] parameter to
advsearch/. NOTE: This might overlap CVE-2011-5211. NOTE: it was later
reported that the f[accounts][fullname] and f[accounts][username]
vectors might also affect 2.2.2.
|
| CVE-2012-5388 |
Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the
White Label CMS plugin 1.5 for WordPress allows remote authenticated
administrators to inject arbitrary web script or HTML via the
wlcms_o_developer_name parameter in a save action to
wp-admin/admin.php, a related issue to CVE-2012-5387.
|
| CVE-2012-5387 |
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in
the White Label CMS plugin before 1.5.1 for WordPress allows remote
attackers to hijack the authentication of administrators for requests
that modify the developer name via the wlcms_o_developer_name
parameter in a save action to wp-admin/admin.php, as demonstrated by a
developer name containing XSS sequences.
|
| CVE-2012-5384 |
Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen
WebCalendar allow remote attackers to inject arbitrary web script or
HTML via the (1) $name or (2) $description variables in
edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5)
$ext_users[] variables in view_entry.php, different vectors than
CVE-2012-0846.
|
| CVE-2012-5368 |
phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained
through an HTTP session to phpmyadmin.net without SSL, which allows
man-in-the-middle attackers to conduct cross-site scripting (XSS)
attacks by modifying this code.
|
| CVE-2012-5349 |
Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the
Pay With Tweet plugin before 1.2 allow remote attackers to inject
arbitrary web script or HTML via the (1) link, (2) title, or (3) dl
parameter.
|
| CVE-2012-5346 |
Cross-site scripting (XSS) vulnerability in wp-live.php in the WP
Live.php module 1.2.1 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the s parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2012-5343 |
Cross-site scripting (XSS) vulnerability in admin/login.php in Limny
3.0.1 allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO, related to the "PHP_SELF" variable.
|
| CVE-2012-5341 |
Multiple cross-site scripting (XSS) vulnerabilities in statistik.php
in Otterware StatIt 4 allow remote attackers to inject arbitrary web
script or HTML via the (1) action parameter, (2) show parameter in a
stat_tld action, or (3) order parameter in a stat_abfragen action.
|
| CVE-2012-5339 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
3.5.x before 3.5.3 allow remote authenticated users to inject
arbitrary web script or HTML via a crafted name of (1) an event, (2) a
procedure, or (3) a trigger.
|
| CVE-2012-5337 |
Multiple cross-site scripting (XSS) vulnerabilities in jforum.page in
JForum 2.1.9 allow remote attackers to inject arbitrary web script or
HTML via the (1) action, (2) match_type, (3) sort_by, or (4) start
parameters.
|
| CVE-2012-5330 |
Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9
allow remote attackers to inject arbitrary web script or HTML via the
(1) PATH_INFO to calc.php, (2) chat.php, (3) register.php, or (4)
index.php in libs/smarty_ajax/; or the (5) page parameter to
libs/smarty_ajax/index.php.
|
| CVE-2012-5325 |
Multiple cross-site scripting (XSS) vulnerabilities in the
scr_do_redirect function in scr.php in the Shortcode Redirect plugin
1.0.01 and earlier for WordPress allow remote authenticated users with
certain permissions to inject arbitrary web script or HTML via the (1)
url or (2) sec attributes in a redirect tag.
|
| CVE-2012-5322 |
Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968
allow remote attackers to inject arbitrary web script or HTML via the
(1) pvcName parameter to webconfig/wan/confirm.html/confirm or (2)
host_name_txtbox parameter to
webconfig/lan/lan_config.html/local_lan_config.
|
| CVE-2012-5316 |
Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Spam
& Virus Firewall 600 Firmware 4.0.1.009 and earlier allow remote
authenticated users to inject arbitrary web script or HTML via (1)
Troubleshooting in the Trace route Device module or (2) LDAP Username
in the LDAP Configuration module.
|
| CVE-2012-5315 |
Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0
allow remote attackers to inject arbitrary web script or HTML via the
message parameter to (1) messages_viewer.php, (2) home.php, or (3)
history.php.
|
| CVE-2012-5314 |
Cross-site scripting (XSS) vulnerability in ViewGit 0.0.6 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
f parameter.
|
| CVE-2012-5309 |
servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim
Fix 1 does not properly restrict invalid authentication attempts,
which makes it easier for remote attackers to obtain access via a
brute-force attack.
|
| CVE-2012-5308 |
Cross-site request forgery (CSRF) vulnerability in servlet/traveler in
IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 allows remote
attackers to hijack the authentication of arbitrary users for requests
that create problem reports via a getReportProblem upload action.
|
| CVE-2012-5307 |
Cross-site scripting (XSS) vulnerability in servlet/traveler in IBM
Lotus Notes Traveler before 8.5.3.3 Interim Fix 1, when Firefox is
used, allows remote attackers to inject arbitrary web script or HTML
via the redirectURL parameter, a different vulnerability than
CVE-2012-4824 and CVE-2012-4825.
|
| CVE-2012-5305 |
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC
Software DirectAdmin 1.403 allows remote attackers to inject arbitrary
web script or HTML via the domain parameter.
|
| CVE-2012-5299 |
Mavili Guestbook, as released in November 2007, allows remote attackers to
edit, delete, and approve arbitrary messages via a direct request to
(1) edit.asp, (2) delete.asp, or (3) approve.asp.
|
| CVE-2012-5298 |
Mavili Guestbook, as released in November 2007, stores guestbook.mdb under
the web root with insufficient access control, which allows remote
attackers to read the database via a direct request.
|
| CVE-2012-5297 |
SQL injection vulnerability in edit.asp in Mavili Guestbook, as
released in November 2007, allows remote attackers to execute arbitrary
SQL commands via the id parameter.
|
| CVE-2012-5296 |
Multiple cross-site scripting (XSS) vulnerabilities in Mavili
Guestbook, as released in November 2007, allow remote attackers to inject
arbitrary web script or HTML via the id parameter to (1) approve.asp,
(2) delete.asp, (3) edit.asp, or (4) edit2.asp.
|
| CVE-2012-5295 |
Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk
Forums 3.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via the windowed parameter.
|
| CVE-2012-5233 |
Cross-site scripting (XSS) vulnerability in the stickynote module
before 7.x-1.1 for Drupal allows remote authenticated users with edit
stickynotes privileges to inject arbitrary web script or HTML via
unspecified vecotrs.
|
| CVE-2012-5232 |
Cross-site scripting (XSS) vulnerability in the Quickl Form component
for Joomla! allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-5229 |
Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the
Slideshow Gallery2 plugin for WordPress allows remote attackers to
inject arbitrary web script or HTML via the border parameter.
|
| CVE-2012-5228 |
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist
2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows
remote attackers to inject arbitrary web script or HTML via the
testtarget parameter. NOTE: some of these details are obtained from
third party information.
|
| CVE-2012-5226 |
Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING
2.8 and 2.9 allow remote attackers to inject arbitrary web script or
HTML via the (1) motclef parameter to achat/recherche.php or (2)
PATH_INFO to index.php.
|
| CVE-2012-5225 |
Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart
1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script
or HTML via the shopping_url parameter.
|
| CVE-2012-5219 |
Cross-site scripting (XSS) vulnerability in HP Managed Printing
Administration (MPA) before 2.7.0 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-5200 |
Cross-site scripting (XSS) vulnerability in HP Intelligent Management
Center (iMC) and Intelligent Management Center for Automated Network
Manager (ANM) before 5.2 E0401 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-5186 |
Cross-site scripting (XSS) vulnerability in FLUGELz netmania myu-s and
PHP WeblogSystem allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-5184 |
Cross-site scripting (XSS) vulnerability in the Olive Toast Documents
Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-5181 |
Cross-site scripting (XSS) vulnerability in concrete5 Japanese 5.5.1
through 5.5.2.1 and concrete5 English 5.5.0 through 5.6.0.2 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-5177 |
Cross-site scripting (XSS) vulnerability in the Welcart plugin before
1.2.2 for WordPress allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-5176 |
Cross-site scripting (XSS) vulnerability in KENT-WEB ACCESS REPORT
5.02 and earlier allows remote attackers to inject arbitrary web
script or HTML via vectors related to tag embedding.
|
| CVE-2012-5175 |
Cross-site scripting (XSS) vulnerability in KENT-WEB ACCESS REPORT 4.2
and earlier allows remote attackers to inject arbitrary web script or
HTML via vectors related to access-log data.
|
| CVE-2012-5169 |
Multiple cross-site scripting (XSS) vulnerabilities in
file_manager/preview_top.php in ATutor AContent before 1.2-2 allow
remote attackers to inject arbitrary web script or HTML via the (1)
pathext, (2) popup, (3) framed, or (4) file parameter.
|
| CVE-2012-5164 |
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before
3.2.7 allow remote attackers to inject arbitrary web script or HTML
via the term parameter to (1) autocomplete.php, (2)
search/ajax/autosuggest.php, (3) livesuggest.php, or (4) save.php in
frontend/modules/search/ajax.
|
| CVE-2012-5163 |
Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in
OSClass before 2.3.5 allows remote attackers to inject arbitrary web
script or HTML via the id parameter in an enable_category action to
index.php.
|
| CVE-2012-5105 |
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager
1.2.4 allow remote attackers to inject arbitrary web script or HTML
via the dbsel parameter to (1) main.php or (2) index.php; or (3)
nsextt parameter to index.php.
|
| CVE-2012-5104 |
Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in
UBB.threads 7.5.6 and earlier allows remote attackers to inject
arbitrary web script or HTML via the Loginname parameter.
|
| CVE-2012-5103 |
Multiple cross-site scripting (XSS) vulnerabilities in
action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to
inject arbitrary web script or HTML via the (1) url or (2) message
parameter.
|
| CVE-2012-5102 |
Cross-site scripting (XSS) vulnerability in inc/extensions.php in
VertrigoServ 2.25 allows remote attackers to inject arbitrary web
script or HTML via the ext parameter.
|
| CVE-2012-5099 |
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the q parameter in a search action.
|
| CVE-2012-5056 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server
before 4.0.8 allow remote attackers to inject arbitrary web script or
HTML via the (1) readyCallback parameter to
apps/files_odfviewer/src/webodf/webodf/flashput/PUT.swf, the (2) root
parameter to apps/gallery/templates/index.php, or a (3) malformed
query to lib/db.php.
|
| CVE-2012-5053 |
Cross-site scripting (XSS) vulnerability in the Receiver Web User
Interface on Trimble Infrastructure GNSS Series Receivers NetR3,
NetR5, NetR8, and NetR9 before 4.70, and NetRS before 1.3-2, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-5050 |
Cross-site scripting (XSS) vulnerability in the server in VMware
vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-4998 |
Cross-site scripting (XSS) vulnerability in index.php in starCMS
allows remote attackers to inject arbitrary web script or HTML via the
q parameter.
|
| CVE-2012-4995 |
Cross-site scripting (XSS) vulnerability in
admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224
allows remote attackers to inject arbitrary web script or HTML via the
full_name parameter in a moduser action to admin/admin.php. NOTE: some
of these details are obtained from third party information.
|
| CVE-2012-4989 |
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in
OpenX 2.8.10 before revision 81823 allows remote attackers to inject
arbitrary web script or HTML via the parent parameter in an info
action.
|
| CVE-2012-4983 |
Multiple cross-site scripting (XSS) vulnerabilities on the Forescout
CounterACT NAC device before 7.0 allow remote attackers to inject
arbitrary web script or HTML via (1) the a parameter to assets/login
or (2) the query parameter to assets/rangesearch.
|
| CVE-2012-4972 |
Multiple cross-site scripting (XSS) vulnerabilities in Layton Helpbox
4.4.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) sys_solution_id, (2) sys_requesttype_id, (3)
sys_problem_desc, (4) sys_solution_desc, (5) sys_problemsummary, (6)
usr_Action_testing, (7) usr_Escalation, or (8)
usr_Additional_Resources parameter to writesolutionuser.asp or the (9)
sys_solution_id parameter to deletesolution.asp.
|
| CVE-2012-4970 |
Cross-site scripting (XSS) vulnerability in the web management
interface on Polycom HDX Video End Points with UC APL software before
2.7.1.1_J, and commercial software before 3.0.5, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-4968 |
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe
2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to
inject arbitrary web script or HTML via (1) a crafted string to the
AbsoluteLinks, (2) BigSummary, (3) ContextSummary, (4) EscapeXML, (5)
FirstParagraph, (6) FirstSentence, (7) Initial, (8) LimitCharacters,
(9) LimitSentences, (10) LimitWordCount, (11) LimitWordCountXML, (12)
Lower, (13) LowerCase, (14) NoHTML, (15) Summary, (16) Upper, (17)
UpperCase, or (18) URL method in a template, different vectors than
CVE-2012-0976.
|
| CVE-2012-4955 |
Cross-site scripting (XSS) vulnerability in Dell OpenManage Server
Administrator (OMSA) before 6.5.0.1, 7.0 before 7.0.0.1, and 7.1
before 7.1.0.1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2012-4950 |
Cross-site scripting (XSS) vulnerability in the Keyword Search page in
the web interface in Pattern Insight 2.3 allows remote attackers to
inject arbitrary web script or HTML via crafted characters that are
not properly handled during construction of error messages.
|
| CVE-2012-4942 |
Multiple cross-site scripting (XSS) vulnerabilities in Agile
FleetCommander and FleetCommander Kiosk before 4.08 allow remote
attackers to inject arbitrary web script or HTML via an arbitrary text
field.
|
| CVE-2012-4939 |
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in
the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network
Performance Monitor might allow remote attackers to inject arbitrary
web script or HTML via the "Search for an IP address" field.
|
| CVE-2012-4938 |
Cross-site scripting (XSS) vulnerability in the web interface in
Pattern Insight 2.3 allows remote authenticated administrators to
inject arbitrary web script or HTML via the banner message.
|
| CVE-2012-4932 |
Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices
before stable-2012-1-CIS3000 allow remote attackers to inject
arbitrary web script or HTML via (1) the having parameter in a manage
action to index.php; (2) the Email field in an Add User action; (3)
the Customer Name field in an Add Customer action; the (4) Street
address, (5) Street address 2, (6) City, (7) Zip code, (8) State, (9)
Country, (10) Mobile Phone, (11) Phone, (12) Fax, (13) Email, (14)
PayPal business name, (15) PayPal notify url, (16) PayPal return url,
(17) Eway customer ID, (18) Custom field 1, (19) Custom field 2, (20)
Custom field 3, or (21) Custom field 4 field in an Add Biller action;
(22) the Customer field in an Add Invoice action; the (23) Invoice or
(24) Notes field in a Process Payment action; (25) the Payment type
description field in a Payment Types action; (26) the Description
field in an Invoice Preferences action; (27) the Description field in
a Manage Products action; or (28) the Description field in a Tax Rates
action.
|
| CVE-2012-4928 |
Cross-site scripting (XSS) vulnerability in ow_updates/index.php in
Oxwall 1.1.1 allows remote attackers to inject arbitrary web script or
HTML via the plugin parameter.
|
| CVE-2012-4923 |
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall
2.4 allow remote attackers to inject arbitrary web script or HTML via
the (1) createrule parameter to dnat.cgi, (2) addrule parameter to
dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.
|
| CVE-2012-4921 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS
Custom Notification plugin 1.0.1 and earlier for WordPress allow
remote attackers to hijack the authentication of administrators for
requests that (1) change application settings or (2) conduct
cross-site scripting (XSS) attacks.
|
| CVE-2012-4912 |
Cross-site scripting (XSS) vulnerability in the WebAccess component in
Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support
Pack 1 allows remote attackers to inject arbitrary web script or HTML
via a crafted signature in an HTML e-mail message.
|
| CVE-2012-4905 |
Cross-site scripting (XSS) vulnerability in Google Chrome before
18.0.1025308 on Android allows remote attackers to inject arbitrary
web script or HTML via an extra in an Intent object, aka "Universal
XSS (UXSS)."
|
| CVE-2012-4904 |
Cross-application scripting vulnerability in Google Chrome before
18.0.1025308 on Android allows remote attackers to inject arbitrary
web script via unspecified vectors, as demonstrated by "Universal XSS
(UXSS)" attacks against the current tab.
|
| CVE-2012-4901 |
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the themes_editor parameter in an add_template action to
admin/index.php.
|
| CVE-2012-4892 |
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS
2012-03.08 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) title_en, (2) summary_en, or (3) body_en
parameter in a submitnews action to the news module, a different
vulnerability than CVE-2012-4890. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2012-4891 |
Cross-site scripting (XSS) vulnerability in fw/index2.do in
ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject
arbitrary web script or HTML via the url parameter, a different vector
than CVE-2012-4889. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2012-4890 |
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS
2011 08.09.2 and earlier allow remote attackers to inject arbitrary
web script or HTML via a (1) comment to the news, (2) title to the
news, or (3) the folder names in a gallery.
|
| CVE-2012-4889 |
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine
Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) subTab or (2) tab parameter to
createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter to
mindex.do; (6) tab parameter to index2.do; or (7) port parameter to
syslogViewer.do.
|
| CVE-2012-4873 |
Cross-site scripting (XSS) vulnerability in the file_download function
in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary
web script or HTML via the filename parameter.
|
| CVE-2012-4872 |
Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako
Fusion before 4.40.985 allows remote attackers to inject arbitrary web
script or HTML via certain vectors, possibly a crafted ticket
description.
|
| CVE-2012-4871 |
Cross-site scripting (XSS) vulnerability in service/graph_html.php in
the administrator panel in LiteSpeed Web Server 4.1.11 allows remote
attackers to inject arbitrary web script or HTML via the gtitle
parameter.
|
| CVE-2012-4870 |
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) context parameter to panel/index_amp.php or (2)
panel/dhtml/index.php; (3) clid or (4) clidname parameters to
panel/flash/mypage.php; (5) PATH_INFO to
admin/views/freepbx_reload.php; or (6) login parameter to
recordings/index.php.
|
| CVE-2012-4869 |
The callme_startcall function in recordings/misc/callme_page.php in
FreePBX 2.9, 2.10, and earlier allows remote attackers to execute
arbitrary commands via the callmenum parameter in a c action.
|
| CVE-2012-4851 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application
Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to
inject arbitrary web script or HTML via a crafted URI.
|
| CVE-2012-4848 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus
Foundations Start before 1.2.2c allow remote authenticated users to
inject arbitrary web script or HTML via a Webconfig Users
user-attribute field, as demonstrated by the (1) First Name or (2)
Last Name field.
|
| CVE-2012-4844 |
Cross-site scripting (XSS) vulnerability in the web server in IBM
Lotus Domino 8.5.x through 8.5.3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-4839 |
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational
ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows
remote attackers to conduct phishing attacks via a FRAME element.
|
| CVE-2012-4836 |
Cross-site scripting (XSS) vulnerability in IBM Cognos Business
Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before
IF2, and 10.2 before IF1 allows remote authenticated users to inject
arbitrary web script or HTML via a crafted string that is not properly
handled during rendering of stored data.
|
| CVE-2012-4835 |
Cross-site scripting (XSS) vulnerability in IBM Cognos Business
Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before
IF2, and 10.2 before IF1 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-4825 |
Multiple cross-site scripting (XSS) vulnerabilities in
servlet/traveler/ILNT.mobileconfig in IBM Lotus Notes Traveler before
8.5.3.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) userId or (2) address parameter in a getClientConfigFile
action.
|
| CVE-2012-4824 |
Open redirect vulnerability in servlet/traveler in IBM Lotus Notes
Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to
redirect users to arbitrary web sites and conduct phishing attacks via
a URL in the redirectURL parameter.
|
| CVE-2012-4819 |
Cross-site scripting (XSS) vulnerability in InfoSphere Business
Glossary 8.1.1 and 8.1.2, InfoSphere DataStage Operation Console,
InfoSphere Administration, and Reporting and Repository Management Web
Console in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and
8.7 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4771 |
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS
before 2.2.3 allow remote attackers to inject arbitrary web script or
HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/,
or (3) admin/manage/blocks/edit/; or (4) group parameter to
admin/configuration/. NOTE: The f[accounts][fullname] and
f[accounts][username] vectors are covered in CVE-2012-5452.
|
| CVE-2012-4768 |
Cross-site scripting (XSS) vulnerability in the Download Monitor
plugin before 3.3.5.9 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the dlsearch parameter to the default
URI.
|
| CVE-2012-4751 |
Cross-site scripting (XSS) vulnerability in Open Ticket Request System
(OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x
before 3.1.11 allows remote attackers to inject arbitrary web script
or HTML via an e-mail message body with whitespace before a
javascript: URL in the SRC attribute of an element, as demonstrated by
an IFRAME element.
|
| CVE-2012-4745 |
Cross-site scripting (XSS) vulnerability in admin/login.asp in Acuity
CMS 2.6.2 allows remote attackers to inject arbitrary web script or
HTML via the UserName parameter.
|
| CVE-2012-4744 |
Cross-site scripting (XSS) vulnerability in ssearch.php in the Siche
search module 0.5 for Zeroboard allows remote attackers to inject
arbitrary web script or HTML via the search parameter.
|
| CVE-2012-4740 |
Cross-site scripting (XSS) vulnerability in the captive portal in
PacketFence before 3.3.0 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-4739 |
Multiple cross-site scripting (XSS) vulnerabilities in Barracuda SSL
VPN before 2.2.2.203 (2012-07-05) allow remote attackers to inject
arbitrary web script or HTML via the (1) policyLaunching, (2)
resourcePrefix, or (3) actionPath parameter in
showUserResourceCategories.do; (4) list or (5) path parameter to
fileSystem.do; or (6) return-To parameter to launchAgent.do.
|
| CVE-2012-4685 |
Cross-site scripting (XSS) vulnerability in Arbor Networks Peakflow SP
5.1.1 before patch 6, 5.5 before patch 4, and 5.6.0 before patch 1
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to index.
|
| CVE-2012-4679 |
Cross-site scripting (XSS) vulnerability in admin/login.php in
Newscoop before 3.5.5 allows remote attackers to inject arbitrary web
script or HTML via the f_user_name parameter.
|
| CVE-2012-4675 |
Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors related to file update.
|
| CVE-2012-4668 |
Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1
and earlier allows remote attackers to inject arbitrary web script or
HTML via the signature in an email.
|
| CVE-2012-4667 |
Multiple cross-site scripting (XSS) vulnerabilities in SquidClamav 5.x
before 5.8 allow remote attackers to inject arbitrary web script or
HTML via the (1) url, (2) virus, (3) source, or (4) user parameter to
(a) clwarn.cgi, (b) clwarn.cgi.de_DE, (c) clwarn.cgi.en_EN, (d)
clwarn.cgi.fr_FR, (e) clwarn.cgi.pt_BR, or (f) clwarn.cgi.ru_RU in
cgi-bin/.
|
| CVE-2012-4612 |
Cross-site scripting (XSS) vulnerability in EMC RSA Data Protection
Manager Appliance and Software Server 2.7.x and 3.x before 3.2.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4611 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA
Adaptive Authentication On-Premise (AAOP) before 7.0 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-4602 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before
11.3.009 allow remote attackers to inject arbitrary web script or HTML
via the (1) cid or (2) uids parameter.
|
| CVE-2012-4600 |
Cross-site scripting (XSS) vulnerability in Open Ticket Request System
(OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x
before 3.1.10, when Firefox or Opera is used, allows remote attackers
to inject arbitrary web script or HTML via an e-mail message body with
nested HTML tags.
|
| CVE-2012-4597 |
Cross-site scripting (XSS) vulnerability in McAfee Email and Web
Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee
Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to inject
arbitrary web script or HTML via vectors related to the McAfee
Security Appliance Management Console/Dashboard.
|
| CVE-2012-4590 |
Multiple cross-site scripting (XSS) vulnerabilities in About.aspx in
the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0
might allow remote attackers to inject arbitrary web script or HTML
via the (1) User Agent or (2) Connection variable.
|
| CVE-2012-4580 |
Cross-site scripting (XSS) vulnerability in McAfee Email and Web
Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and
McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote attackers
to inject arbitrary web script or HTML via vectors related to the
McAfee Security Appliance Management Console/Dashboard.
|
| CVE-2012-4579 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
3.5.x before 3.5.2.2 allow remote authenticated users to inject
arbitrary web script or HTML via a Table Operations (1) TRUNCATE or
(2) DROP link for a crafted table name, (3) the Add Trigger popup
within a Triggers page that references crafted table names, (4) an
invalid trigger-creation attempt for a crafted table name, (5) crafted
data in a table, or (6) a crafted tooltip label name during GIS data
visualization, a different issue than CVE-2012-4345.
|
| CVE-2012-4569 |
Multiple cross-site scripting (XSS) vulnerabilities in
out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4567 |
Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS
(formerly MyDMS) before 3.3.8 allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters in (1)
inc/inc.ClassUI.php or (2) out/out.DocumentNotify.php.
|
| CVE-2012-4563 |
Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT)
2.4 Beta and release candidates before 2.4.0 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-4558 |
Multiple cross-site scripting (XSS) vulnerabilities in the
balancer_handler function in the manager interface in
mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache
HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow
remote attackers to inject arbitrary web script or HTML via a crafted
string.
|
| CVE-2012-4543 |
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat
Certificate System (RHCS) before 8.1.3 allow remote attackers to
inject arbitrary web script or HTML via the (1) pageStart or (2)
pageSize to the displayCRL script, or (3) nonce variable to the
profileProcess script.
|
| CVE-2012-4541 |
Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4533 |
Cross-site scripting (XSS) vulnerability in the "extra" details in the
DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before
1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with
repository commit access to inject arbitrary web script or HTML via
the "function name" line.
|
| CVE-2012-4532 |
Cross-site scripting (XSS) vulnerability in
modules/mod_languages/tmpl/default.php in the Language Switcher module
for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO to index.php. NOTE:
some of these details are obtained from third party information.
|
| CVE-2012-4531 |
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4497 |
Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in
the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows
remote authenticated users with the "administer themes" permission to
inject arbitrary web script or HTML via a slide URL.
|
| CVE-2012-4496 |
Cross-site scripting (XSS) vulnerability in the Custom Publishing
Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote
authenticated users with the "administer nodes" permission to inject
arbitrary web script or HTML via the status labels parameter.
|
| CVE-2012-4493 |
Cross-site scripting (XSS) vulnerability in the administrative
interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for
Drupal allows remote authenticated users with the "administer better
revisions" permission to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4492 |
Multiple cross-site scripting (XSS) vulnerabilities in the Shorten
URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for
Drupal allow remote authenticated users with certain permissions to
inject arbitrary web script or HTML via unspecified vectors to the (1)
report or (2) Custom Services List page.
|
| CVE-2012-4490 |
Multiple cross-site scripting (XSS) vulnerabilities in the Excluded
Users module 6.x-1.x before 6.x-1.1 for Drupal allow remote attackers
to inject arbitrary web script or HTML via a (1) user name or (2)
email address.
|
| CVE-2012-4485 |
Multiple cross-site scripting (XSS) vulnerabilities in the
galleryformatter_field_formatter_view functiuon in
galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2
for Drupal allow remote authenticated users with permissions to create
a node or entity to inject arbitrary web script or HTML via the (1)
title or (2) alt parameter.
|
| CVE-2012-4484 |
Cross-site scripting (XSS) vulnerability in the administrative
interface in the Campaign Monitor module before 6.x-2.5 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4476 |
Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery
module 6.x for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-4474 |
Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox
Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers
to inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2012-4469 |
Cross-site scripting (XSS) vulnerability in the Hashcash module
6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when
"Log failed hashcash" is enabled, allows remote attackers to inject
arbitrary web script or HTML via an invalid token, which is not
properly handled when administrators use the Database logging module.
|
| CVE-2012-4468 |
Cross-site scripting (XSS) vulnerability in the Privatemsg module
7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via a user name in a private message.
|
| CVE-2012-4437 |
Cross-site scripting (XSS) vulnerability in the SmartyException class
in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors that
trigger a Smarty exception.
|
| CVE-2012-4397 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
4.0.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) calendar displayname to part.choosecalendar.rowfields.php
or (2) part.choosecalendar.rowfields.shared.php in
apps/calendar/templates/; or (3) unspecified vectors to
apps/contacts/lib/vcard.php.
|
| CVE-2012-4396 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
4.0.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) file names to apps/user_ldap/settings.php; (2) url or (3)
title parameter to apps/bookmarks/ajax/editBookmark.php; (4) tag or
(5) page parameter to apps/bookmarks/ajax/updateList.php; (6) identity
to apps/user_openid/settings.php; (7) stack name in
apps/gallery/lib/tiles.php; (8) root parameter to
apps/gallery/templates/index.php; (9) calendar displayname in
apps/calendar/templates/part.import.php; (10) calendar uri in
apps/calendar/templates/part.choosecalendar.rowfields.php; (11) title,
(12) location, or (13) description parameter in
apps/calendar/lib/object.php; (14) certain vectors in
core/js/multiselect.js; or (15) artist, (16) album, or (17) title
comments parameter in apps/media/lib_scanner.php.
|
| CVE-2012-4395 |
Cross-site scripting (XSS) vulnerability in index.php in ownCloud
before 4.0.3 allows remote attackers to inject arbitrary web script or
HTML via the redirect_url parameter.
|
| CVE-2012-4394 |
Cross-site scripting (XSS) vulnerability in apps/files/js/filelist.js
in ownCloud before 4.0.5 allows remote attackers to inject arbitrary
web script or HTML via the file parameter.
|
| CVE-2012-4378 |
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki
before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript
gadgets are used, allow remote attackers to inject arbitrary web
script or HTML via the userlang parameter to w/index.php.
|
| CVE-2012-4377 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5
and 1.19.x before 1.19.2 allows remote attackers to inject arbitrary
web script or HTML via a File: link to a nonexistent image.
|
| CVE-2012-4360 |
Cross-site scripting (XSS) vulnerability in the mod_pagespeed module
0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-4352 |
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware
webNetwork 6.1 before SP1 allow remote attackers to inject arbitrary
web script or HTML via the blogName parameter to (1)
community/blog.jsp or (2) community/blogSearch.jsp, the (3)
calendarType or (4) monthNumber parameter to community/calendar.jsp,
or the (5) flag parameter to swDashboard/ajax/setAppFlag.jsp.
|
| CVE-2012-4345 |
Multiple cross-site scripting (XSS) vulnerabilities in the Database
Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before
3.5.2.2 allow remote authenticated users to inject arbitrary web
script or HTML via (1) a crafted table name during table creation, or
a (2) Empty link or (3) Drop link for a crafted table name.
|
| CVE-2012-4344 |
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold
15.02 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors involving the SNMP system name of the
attacking host.
|
| CVE-2012-4342 |
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3
before 3.0.4 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-4340 |
Cross-site scripting (XSS) vulnerability in Sybase EAServer before 6.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4336 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web
script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter.
|
| CVE-2012-4331 |
Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x
before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack
vectors that are not related to cross-site scripting (XSS), different
vulnerabilities than CVE-2012-2151.
|
| CVE-2012-4283 |
Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin
before 3.0.4.1 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the callback parameter.
|
| CVE-2012-4278 |
Multiple cross-site scripting (XSS) vulnerabilities in Free Realty
3.1-0.6 allow remote attackers to inject arbitrary web script or HTML
via the (1) notes parameter to (a) admin/agenteditor.php; (2) title,
(3) previewdesc, (4) fulldesc, or (5) notes parameter (b) to
agentadmin.php or (c) in an addlisting action to agentadmin.php; or
unspecified vectors to (d) admin/adminfeatures.php.
|
| CVE-2012-4277 |
Cross-site scripting (XSS) vulnerability in the
smarty_function_html_options_optoutput function in
distribution/libs/plugins/function.html_options.php in Smarty before
3.1.8 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2012-4275 |
Cross-site scripting (XSS) vulnerability in Hitachi IT Operations
Director 02-50-01 through 02-50-07, 03-00 before 03-00-08 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4273 |
Cross-site scripting (XSS) vulnerability in libs/xing.php in the 2
Click Social Media Buttons plugin before 0.34 for WordPress allows
remote attackers to inject arbitrary web script or HTML via the
xing-url parameter.
|
| CVE-2012-4272 |
Multiple cross-site scripting (XSS) vulnerabilities in the 2 Click
Social Media Buttons plugin before 0.34 for WordPress allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors related to the "processing of the buttons of Xing and
Pinterest".
|
| CVE-2012-4271 |
Multiple cross-site scripting (XSS) vulnerabilities in
bad-behavior-wordpress-admin.php in the Bad Behavior plugin before
2.0.47 and 2.2.x before 2.2.5 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) PATH_INFO, (2)
httpbl_key, (3) httpbl_maxage, (4) httpbl_threat, (5)
reverse_proxy_addresses, or (6) reverse_proxy_header parameter.
|
| CVE-2012-4270 |
Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows
remote authenticated users to inject arbitrary web script or HTML via
the subject box of a message.
|
| CVE-2012-4268 |
Cross-site scripting (XSS) vulnerability in
bulletproof-security/admin/options.php in the BulletProof Security
plugin before .47.1 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the HTTP_ACCEPT_ENCODING header.
|
| CVE-2012-4267 |
Cross-site scripting (XSS) vulnerability in user/register in Sockso
1.5 and earlier allows remote attackers to inject arbitrary web script
or HTML via the name parameter.
|
| CVE-2012-4266 |
Cross-site scripting (XSS) vulnerability in client_details.php in
Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web
script or HTML via the cl_comments parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2012-4264 |
Multiple cross-site scripting (XSS) vulnerabilities in the Better WP
Security (better_wp_security) plugin before 3.2.5 for WordPress allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to "server variables," a different
vulnerability than CVE-2012-4263.
|
| CVE-2012-4263 |
Cross-site scripting (XSS) vulnerability in inc/admin/content.php in
the Better WP Security (better_wp_security) plugin before 3.2.5 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the HTTP_USER_AGENT header.
|
| CVE-2012-4262 |
Multiple cross-site scripting (XSS) vulnerabilities in myCare2x allow
remote attackers to inject arbitrary web script or HTML via the (1)
name_last, (2) name_first, (3) name_middle, or (4) name_maiden
parameter to modules/patient/mycare_pid.php; (5) favorites or (6) lang
parameter to modules/nursing/mycare_ward_print.php; (7) aktion or (8)
callurl parameter to modules/patient/mycare2x_pat_info.php; or (9) ln
parameter to modules/drg/mycare2x_proc_search.php.
|
| CVE-2012-4259 |
Cross-site scripting (XSS) vulnerability in the contacts in (1) XPhone
UC Web and the (2) web frontend for XPhone Virtual Directory in C4B
XPhone Unified Communications (UC) 2011 Web 4.1.890S R1 allows remote
attackers to inject arbitrary web script or HTML via the company name.
NOTE: some of these details are obtained from third party information.
|
| CVE-2012-4251 |
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper
1.24.4 allow remote attackers to inject arbitrary web script or HTML
via the (1) page parameter to index.php, (2) phase parameter to
install.php, (3) tablename or (4) dbid parameter to sql.php, or (5)
filename parameter to restore.php in learn/cubemail/.
|
| CVE-2012-4247 |
Multiple cross-site scripting (XSS) vulnerabilities in
lists/admin/index.php in phpList before 2.10.19 allow remote attackers
to inject arbitrary web script or HTML via the (1) remote_user, (2)
remote_database, (3) remote_userprefix, (4) remote_password, or (5)
remote_prefix parameter to the import4 page; or the (6) id parameter
to the bouncerule page.
|
| CVE-2012-4246 |
Multiple cross-site scripting (XSS) vulnerabilities in
lists/admin/index.php in phpList before 2.10.19 allow remote attackers
to inject arbitrary web script or HTML via the (1) page parameter; or
the (2) footer, (3) status, or (4) testtarget parameter in the send
page.
|
| CVE-2012-4242 |
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin
0.9.2 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the query string to the calendar page.
|
| CVE-2012-4241 |
Multiple cross-site scripting (XSS) vulnerabilities in Microcart 1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) PATH_INFO or (2) query string to _admin/index.php or (3)
first_name, (4) last_name, (5) cc, (6) exp, (7) cvv, (8) address1, (9)
address2, (10) city, (11) state, (12) zip, (13) phone, or (14) email
parameter to checkout.php, which is not properly handled in an error
message.
|
| CVE-2012-4238 |
Cross-site scripting (XSS) vulnerability in
admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote
authenticated users with level 5 or greater permissions to inject
arbitrary web script or HTML via the question_subject_id parameter.
|
| CVE-2012-4236 |
Cross-site scripting (XSS) vulnerability in the refresh_page function
in application/modules/_main/views/_top.php in Total Shop UK eCommerce
Open Source before 2.1.2_p1 allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2012-4234 |
Cross-site scripting (XSS) vulnerability in the group moderation
screen in the control center (control.php) in Phorum before 5.2.19
allows remote attackers to inject arbitrary web script or HTML via the
group parameter.
|
| CVE-2012-4231 |
Cross-site scripting (XSS) vulnerability in admin/index.php in jCore
before 1.0pre2 allows remote attackers to inject arbitrary web script
or HTML via the path parameter.
|
| CVE-2012-4230 |
The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the
TinyMCE security policy for the (1) encoding directive and (2)
valid_elements attribute, which allows attackers to conduct cross-site
scripting (XSS) attacks via application-specific vectors, as
demonstrated using a textarea element.
|
| CVE-2012-4226 |
Multiple cross-site scripting (XSS) vulnerabilities in Quick Post
Widget plugin 1.9.1 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) Title, (2) Content, or (3)
New category field to wordpress/ or (4) query string to wordpress/.
|
| CVE-2012-4209 |
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11,
Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and
SeaMonkey before 2.14 do not prevent use of a "top" frame
name-attribute value to access the location property, which makes it
easier for remote attackers to conduct cross-site scripting (XSS)
attacks via vectors involving a binary plugin.
|
| CVE-2012-4207 |
The HZ-GB-2312 character-set implementation in Mozilla Firefox before
17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0,
Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does
not properly handle a ~ (tilde) character in proximity to a chunk
delimiter, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via a crafted document.
|
| CVE-2012-4201 |
The evalInSandbox implementation in Mozilla Firefox before 17.0,
Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird
ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect
context during the handling of JavaScript code that sets the
location.href property, which allows remote attackers to conduct
cross-site scripting (XSS) attacks or read arbitrary files by
leveraging a sandboxed add-on.
|
| CVE-2012-4195 |
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2,
Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2,
Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does
not properly determine the calling document and principal in its
return value, which makes it easier for remote attackers to conduct
cross-site scripting (XSS) attacks via a crafted web site, and makes
it easier for remote attackers to execute arbitrary JavaScript code by
leveraging certain add-on behavior.
|
| CVE-2012-4194 |
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10,
Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and
SeaMonkey before 2.13.2 do not prevent use of the valueOf method to
shadow the location object (aka window.location), which makes it
easier for remote attackers to conduct cross-site scripting (XSS)
attacks via vectors involving a plugin.
|
| CVE-2012-4189 |
Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x
before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote
attackers to inject arbitrary web script or HTML via a field value
that is not properly handled during construction of a tabular report,
as demonstrated by the Version field.
|
| CVE-2012-4184 |
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox
before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0,
Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not
prevent access to properties of a prototype for a standard class,
which allows remote attackers to execute arbitrary JavaScript code
with chrome privileges via a crafted web site.
|
| CVE-2012-4144 |
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x
before 12.01 on Mac OS X, does not properly escape characters in DOM
elements, which makes it easier for remote attackers to bypass
cross-site scripting (XSS) protection mechanisms via a crafted HTML
document.
|
| CVE-2012-4142 |
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x
before 12.01 on Mac OS X, ignores some characters in HTML documents in
unspecified circumstances, which makes it easier for remote attackers
to conduct cross-site scripting (XSS) attacks via a crafted document.
|
| CVE-2012-4071 |
Cross-site scripting (XSS) vulnerability in the comments module in the
RSGallery2 (com_rsgallery2) component before 2.3.0 for Joomla! 1.5.x,
and before 3.2.0 for Joomla! 2.5.x, allows remote attackers to inject
arbitrary web script or HTML via crafted BBCode markup in a comment.
|
| CVE-2012-4058 |
Cross-site scripting (XSS) vulnerability in SocketMail Pro 2.2.9
allows remote attackers to inject arbitrary web script or HTML via the
subject of an email.
|
| CVE-2012-4052 |
Multiple cross-site scripting (XSS) vulnerabilities in Jease before
2.9, when creating a comment, allow remote attackers to inject
arbitrary web script or HTML via the (1) author, (2) subject, or (3)
comment parameter.
|
| CVE-2012-4043 |
Cross-site scripting (XSS) vulnerability in global-protect/login.esp
in Palo Alto Networks Global Protect Portal, Global Protect Gateway,
and SSL VPN portals 3.1.x through 3.1.11 and 4.0.x through 4.0.5
allows remote attackers to inject arbitrary web script or HTML via the
inputStr parameter in a Login action.
|
| CVE-2012-4037 |
Multiple cross-site scripting (XSS) vulnerabilities in the web client
in Transmission before 2.61 allow remote attackers to inject arbitrary
web script or HTML via the (1) comment, (2) created by, or (3) name
field in a torrent file.
|
| CVE-2012-4019 |
Cross-site scripting (XSS) vulnerability in tokyo_bbs.cgi in Come on
Girls Interface (CGI) Tokyo BBS allows remote attackers to inject
arbitrary web script or HTML via vectors related to the error page.
|
| CVE-2012-4018 |
Cross-site scripting (XSS) vulnerability in Final Beta Laboratory
MyWebSearch before 1.23 allows remote attackers to inject arbitrary
web script or HTML via the keywords parameter.
|
| CVE-2012-4015 |
Cross-site scripting (XSS) vulnerability in the management screen in
myLittleTools myLittleAdmin for SQL Server 2000 allows remote
attackers to inject arbitrary web script or HTML via vectors that
trigger a crafted database entry.
|
| CVE-2012-4004 |
Cross-site scripting (XSS) vulnerability in the Sleipnir Mobile
application 2.2.0 and earlier and Sleipnir Mobile Black Edition
application 2.2.0 and earlier for Android allows remote attackers to
inject arbitrary web script or HTML via a crafted application that
interacts with an unspecified Sleipnir Mobile function.
|
| CVE-2012-4003 |
Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT
GLPI before 0.83.3 allow remote attackers to inject arbitrary web
script or HTML via unknown vectors.
|
| CVE-2012-4002 |
Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI
before 0.83.3 allows remote attackers to hijack the authentication of
unspecified victims via unknown vectors.
|
| CVE-2012-4000 |
Cross-site scripting (XSS) vulnerability in the print_textinputs_var
function in
editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php
in FCKeditor 2.6.7 and earlier allows remote attackers to inject
arbitrary web script or HTML via textinputs array parameters.
|
| CVE-2012-3999 |
Cross-site scripting (XSS) vulnerability in admin/login.php in Sticky
Notes 0.3.09062012.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via the username parameter.
|
| CVE-2012-3997 |
Multiple cross-site scripting (XSS) vulnerabilities in Sticky Notes
before 0.2.27052012.5 allow remote attackers to inject arbitrary web
script or HTML via the (1) paste_user or (2) paste_lang parameter to
(a) list.php or (b) show.php.
|
| CVE-2012-3994 |
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8,
Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and
SeaMonkey before 2.13 allow remote attackers to conduct cross-site
scripting (XSS) attacks via a binary plugin that uses
Object.defineProperty to shadow the top object, and leverages the
relationship between top.location and the location property.
|
| CVE-2012-3993 |
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox
before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0,
Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not
properly interact with failures of InstallTrigger methods, which
allows remote attackers to execute arbitrary JavaScript code with
chrome privileges via a crafted web site, related to an "XrayWrapper
pollution" issue.
|
| CVE-2012-3992 |
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8,
Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and
SeaMonkey before 2.13 do not properly manage history data, which
allows remote attackers to conduct cross-site scripting (XSS) attacks
or obtain sensitive POST content via vectors involving a location.hash
write operation and history navigation that triggers the loading of a
URL into the history object.
|
| CVE-2012-3987 |
Mozilla Firefox before 16.0 on Android assigns chrome privileges to
Reader Mode pages, which allows user-assisted remote attackers to
bypass intended access restrictions via a crafted web site.
|
| CVE-2012-3985 |
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey
before 2.13 do not properly implement the HTML5 Same Origin Policy,
which allows remote attackers to conduct cross-site scripting (XSS)
attacks by leveraging initial-origin access after document.domain has
been set.
|
| CVE-2012-3952 |
Cross-site scripting (XSS) vulnerability in admin/index.php in phpList
before 2.10.19 allows remote attackers to inject arbitrary web script
or HTML via the unconfirmed parameter to the user page.
|
| CVE-2012-3872 |
Multiple cross-site scripting (XSS) vulnerabilities in Open
Constructor 3.12.0 allow remote attackers to inject arbitrary web
script or HTML via (1) the result parameter to data/file/edit.php, (2)
the q parameter to confirm.php, or (3) the keyword parameter to
users/users.php.
|
| CVE-2012-3871 |
Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php
in Open Constructor 3.12.0 allows remote authenticated users to inject
arbitrary web script or HTML via the header parameter.
|
| CVE-2012-3870 |
Multiple cross-site scripting (XSS) vulnerabilities in
objects/createobject.php in Open Constructor 3.12.0 allow remote
authenticated users to inject arbitrary web script or HTML via the (1)
name or (2) description parameter.
|
| CVE-2012-3869 |
Cross-site scripting (XSS) vulnerability in
include/classes/class.rex_list.inc.php in REDAXO 4.3.x and 4.4 allows
remote attackers to inject arbitrary web script or HTML via the
subpage parameter to index.php.
|
| CVE-2012-3848 |
Multiple cross-site scripting (XSS) vulnerabilities in the web console
in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0
allow remote attackers to inject arbitrary web script or HTML via (1)
the query string to d4d/exporters.php, (2) the HTTP Referer header to
d4d/exporters.php, or (3) unspecified input to d4d/contextMenu.php.
|
| CVE-2012-3846 |
Cross-site scripting (XSS) vulnerability in index.php in PHP-pastebin
2.1 allows remote attackers to inject arbitrary web script or HTML via
the title parameter.
|
| CVE-2012-3844 |
Cross-site scripting (XSS) vulnerability in vBulletin 4.1.12 allows
remote attackers to inject arbitrary web script or HTML via a long
string in the subject parameter when creating a post.
|
| CVE-2012-3843 |
Cross-site scripting (XSS) vulnerability in the registration page in
e107, probably 1.0.1, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-3842 |
Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in
JBMC Software DirectAdmin 1.403 allow remote authenticated users with
certain privileges to inject arbitrary web script or HTML via the (1)
select0 or (2) select8 parameters.
|
| CVE-2012-3840 |
Multiple cross-site scripting (XSS) vulnerabilities in
index.php/users/form/user_id in MyClientBase 0.12 allow remote
attackers to inject arbitrary web script or HTML via the (1)
first_name or (2) last_name parameters.
|
| CVE-2012-3837 |
Multiple cross-site scripting (XSS) vulnerabilities in
apps/users/registration.template.php in Baby Gekko 1.2.0 and earlier
allow remote attackers to inject arbitrary web script or HTML via the
(1) username, (2) email_address, (3) password, (4) password_verify,
(5) firstname, (6) lastname, or (7) verification_code parameter to
users/action/register. NOTE: some of these details are obtained from
third party information.
|
| CVE-2012-3836 |
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko
before 1.2.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) groupname parameter in a savecategory in the users
module; (2) virtual_filename, (3) branch, (4) contact_person, (5)
street, (6) city, (7) province, (8) postal, (9) country, (10)
tollfree, (11) phone, (12) fax, or (13) mobile parameter in a saveitem
action in the contacts module; (14) title parameter in a savecategory
action in the menus module; (15) firstname or (16) lastname in a
saveitem action in the users module; (17) meta_key or (18)
meta_description in a saveitem action in the blog module; or (19) the
PATH_INFO to admin/index.php.
|
| CVE-2012-3835 |
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open
Source Security Information Management (OSSIM) 3.1 allow remote
attackers to inject arbitrary web script or HTML via the (1) url
parameter to top.php or (2) time[0][0] parameter to
forensics/base_qry_main.php, which is not properly handled in an error
page.
|
| CVE-2012-3833 |
Cross-site scripting (XSS) vulnerability in the default index page in
admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary
web script or HTML via the p parameter.
|
| CVE-2012-3832 |
Cross-site scripting (XSS) vulnerability in decoda/Decoda.php in
Decoda before 3.2 allows remote attackers to inject arbitrary web
script or HTML via vectors related to (1) b or (2) div tags.
|
| CVE-2012-3831 |
Cross-site scripting (XSS) vulnerability in decoda/templates/video.php
in Decoda before 3.3.1 allows remote attackers to inject arbitrary web
script or HTML via multiple URLs in an img tag.
|
| CVE-2012-3830 |
Cross-site scripting (XSS) vulnerability in decoda/templates/video.php
in Decoda before 3.3.3 allows remote attackers to inject arbitrary web
script or HTML via the video directive.
|
| CVE-2012-3828 |
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.3 allows
remote attackers to inject arbitrary web script or HTML via the Host
HTTP Header.
|
| CVE-2012-3805 |
Multiple cross-site scripting (XSS) vulnerabilities in the
getAllPassedParams function in system/functions.php in Kajona before
3.4.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) absender_name, (2) absender_email, or (3)
absender_nachricht parameter to the content page; (4) comment_name,
(5) comment_subject, or (6) comment_message parameter to the
postacomment module; (7) module parameter to index.php; (8) action
parameter to the admin login page; (9) pv or (10) pe parameter in a
list action to the user module; (11) user_username, (12) user_email,
(13) user_forename, (14) user_name, (15) user_street, (16)
user_postal, (17) user_city, (18) user_tel, or (19) user_mobil
parameter in a newUser action to the user module; (20) group_name or
(21) group_desc parameter in a groupNew action to the user module;
(22) name, (23) browsername, (24) seostring, (25) keywords, or (26)
folder_id parameter in a newPage action to the pages module; (27)
element_name or (28) element_cachetime parameter in a newElement
action in the pages module; (29) aspect_name parameter in a newAspect
action in the system module; (30) filemanager_name, (31)
filemanager_path, (32) filemanager_upload_filter, or (33)
filemanager_view_filter parameter in a NewRepo action to the
filemanager module; or (34) archive_title or (35) archive_path
parameter in a newArchive action to the downloads module. NOTE: some
of these details are obtained from third party information.
|
| CVE-2012-3800 |
Cross-site scripting (XSS) vulnerability in og.js in the Organic
Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with
the Vertical Tabs module, allows remote authenticated users to inject
arbitrary web script or HTML via vectors related the group title.
|
| CVE-2012-3799 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote
attackers to hijack the authentication of administrators for requests
that (1) change workflows or (2) insert cross-site scripting (XSS)
sequences.
|
| CVE-2012-3790 |
Cross-site scripting (XSS) vulnerability in index.php in Adiscon
LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows remote
attackers to inject arbitrary web script or HTML via the highlight
parameter in a Search action.
|
| CVE-2012-3695 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 6.0 allows remote attackers to inject arbitrary web script or
HTML by leveraging improper URL canonicalization during the handling
of the location.href property.
|
| CVE-2012-3556 |
Opera before 11.65 does not properly restrict the opening of a pop-up
window in response to the first click of a double-click action, which
makes it easier for user-assisted remote attackers to conduct
cross-site scripting (XSS) attacks or execute arbitrary code via a
crafted web site.
|
| CVE-2012-3555 |
Opera before 11.65 does not ensure that keyboard sequences are
associated with a visible window, which makes it easier for
user-assisted remote attackers to conduct cross-site scripting (XSS)
attacks or execute arbitrary code via a crafted web site, related to a
"hidden keyboard navigation" issue.
|
| CVE-2012-3551 |
Cross-site scripting (XSS) vulnerability in
crowbar_framework/app/views/support/index.html.haml in the Crowbar
barclamp in Crowbar, possibly 1.4 and earlier, allows remote attackers
to inject arbitrary web script or HTML via the file parameter to
/utils.
|
| CVE-2012-3531 |
Cross-site scripting (XSS) vulnerability in the Install Tool in TYPO3
4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-3530 |
Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API
function in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x
before 4.7.4 allows remote attackers to conduct cross-site scripting
(XSS) attacks via certain HTML5 JavaScript events.
|
| CVE-2012-3528 |
Multiple cross-site scripting (XSS) vulnerabilities in the backend in
TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4
allow remote authenticated backend users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-3522 |
Cross-site scripting (XSS) vulnerability in contrib/langwiz.php in
GeSHi before 1.0.8.11 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-3521 |
Multiple directory traversal vulnerabilities in the cssgen contrib
module in GeSHi before 1.0.8.11 allow remote attackers to read
arbitrary files via a .. (dot dot) in the (1) geshi-path or (2)
geshi-lang-path parameter.
|
| CVE-2012-3508 |
Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in
Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary
web script or HTML by using "javascript:" in an href attribute in the
body of an HTML-formatted email.
|
| CVE-2012-3507 |
Cross-site scripting (XSS) vulnerability in
program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when
using the Larry skin, allows remote attackers to inject arbitrary web
script or HTML via the email message subject.
|
| CVE-2012-3499 |
Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP
Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote
attackers to inject arbitrary web script or HTML via vectors involving
hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3)
mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
|
| CVE-2012-3476 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
application/views/admin/layout.php and (2)
themes/default/views/header.php in the Ushahidi Platform before 2.5
allow remote authenticated users to inject arbitrary web script or
HTML via vectors related to a site name.
|
| CVE-2012-3465 |
Cross-site scripting (XSS) vulnerability in
actionpack/lib/action_view/helpers/sanitize_helper.rb in the
strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8,
and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web
script or HTML via malformed HTML markup.
|
| CVE-2012-3464 |
Cross-site scripting (XSS) vulnerability in
activesupport/lib/active_support/core_ext/string/output_safety.rb in
Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before
3.2.8 might allow remote attackers to inject arbitrary web script or
HTML via vectors involving a ' (quote) character.
|
| CVE-2012-3463 |
Cross-site scripting (XSS) vulnerability in
actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails
3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows
remote attackers to inject arbitrary web script or HTML via the prompt
field to the select_tag helper.
|
| CVE-2012-3442 |
The (1) django.http.HttpResponseRedirect and (2)
django.http.HttpResponsePermanentRedirect classes in Django before
1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect
target, which might allow remote attackers to conduct cross-site
scripting (XSS) attacks via a data: URL.
|
| CVE-2012-3434 |
Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php
in the Count Per Day module before 3.2 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) page, (2)
datemin, or (3) datemax parameter.
|
| CVE-2012-3414 |
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload
2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image
Manager 1.1, and other products, allows remote attackers to inject
arbitrary web script or HTML via the movieName parameter, related to
the "ExternalInterface.call" function.
|
| CVE-2012-3396 |
Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in
Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4,
and 2.3.x before 2.3.1 allows remote authenticated administrators to
inject arbitrary web script or HTML via the idnumber field. NOTE: this
vulnerability exists because of an incorrect fix for CVE-2012-2365.
|
| CVE-2012-3393 |
Cross-site scripting (XSS) vulnerability in repository/lib.php in
Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote
authenticated administrators to inject arbitrary web script or HTML by
renaming a repository.
|
| CVE-2012-3389 |
Multiple cross-site scripting (XSS) vulnerabilities in
mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x
before 2.3.1 allow remote attackers to inject arbitrary web script or
HTML via the (1) lti_typename or (2) lti_toolurl parameter.
|
| CVE-2012-3383 |
The map_meta_cap function in wp-includes/capabilities.php in WordPress
3.4.x before 3.4.2, when the multisite feature is enabled, does not
properly assign the unfiltered_html capability, which allows remote
authenticated users to bypass intended access restrictions and conduct
cross-site scripting (XSS) attacks by leveraging the Administrator or
Editor role and composing crafted text.
|
| CVE-2012-3382 |
Cross-site scripting (XSS) vulnerability in the ProcessRequest
function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in
Mono 2.10.8 and earlier allows remote attackers to inject arbitrary
web script or HTML via a file with a crafted name and a forbidden
extension, which is not properly handled in an error message.
|
| CVE-2012-3373 |
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before
1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject
arbitrary web script or HTML via vectors involving a %00 sequence in
an Ajax link URL associated with a Wicket app.
|
| CVE-2012-3343 |
Cross-site request forgery (CSRF) vulnerability in Microdasys before
3.5.1-B708, as used in Bloxx Web Filtering before 5.0.14 and other
products, allows remote attackers to hijack the authentication of
arbitrary users for requests that trigger error pages containing XSS
sequences, a different vulnerability than CVE-2012-2564.
|
| CVE-2012-3328 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset
Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and
7.2, and Change and Configuration Management Database (CCMDB) 7.1 and
7.2 allows remote attackers to inject arbitrary web script or HTML via
vectors related to a hidden frame footer.
|
| CVE-2012-3327 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2
through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli
Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change
and Configuration Management Database (CCMDB) 7.1 and 7.2, and
SmartCloud Control Desk 7.5 allows remote attackers to inject
arbitrary web script or HTML via vectors related to a login action.
|
| CVE-2012-3326 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset
Management for IT, Tivoli Service Request Manager, Maximo Service
Desk, and Change and Configuration Management Database (CCMDB), allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-3322 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2
through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli
Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change
and Configuration Management Database (CCMDB) 7.1 and 7.2, and
SmartCloud Control Desk 7.5 allows remote authenticated users to
inject arbitrary web script or HTML via vectors related to a display
name.
|
| CVE-2012-3316 |
Cross-site scripting (XSS) vulnerability in the Tivoli Process
Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through
7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset
Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1
and 7.2, Maximo Service Desk 6.2, Change and Configuration Management
Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-3313 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli
Asset Management for IT, Tivoli Service Request Manager, Maximo
Service Desk, and Change and Configuration Management Database
(CCMDB), allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-3308 |
Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through
8.5.2.1 allows remote attackers to inject arbitrary web script or HTML
via an IM chat.
|
| CVE-2012-3302 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus
Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject
arbitrary web script or HTML via (1) a URL accessed during use of the
Mail template in the WebMail UI or (2) a URL accessed during use of
Domino Help through the Domino HTTP server.
|
| CVE-2012-3297 |
Cross-site scripting (XSS) vulnerability in the embedded HTTP server
in the Service Console in IBM Tivoli Monitoring 6.2.2 before
6.2.2-TIV-ITM-FP0009 and 6.3.2 before 6.2.3-TIV-ITM-FP0001 allows
remote attackers to inject arbitrary web script or HTML via a crafted
URI.
|
| CVE-2012-3296 |
Cross-site scripting (XSS) vulnerability in the Help link in the login
panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before
SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-3293 |
Cross-site scripting (XSS) vulnerability in the Administrative Console
in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x
before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows
remote attackers to inject arbitrary web script or HTML via vectors
involving FRAME elements, related to a cross-frame scripting (XFS)
issue.
|
| CVE-2012-3279 |
Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node
Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-3272 |
Cross-site scripting (XSS) vulnerability on the HP Color LaserJet
CM3530 with firmware before 53.190.9, Color LaserJet CM60xx with
firmware before 52.210.9, Color LaserJet CP3525 with firmware before
06.140.3 18, Color LaserJet CP4xxx with firmware before 07.120.6,
Color LaserJet CP6015 with firmware before 04.160.3, LaserJet P3015
with firmware before 07.140.3, and LaserJet P4xxx with firmware before
04.170.3 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-3255 |
Cross-site scripting (XSS) vulnerability in HP Business Availability
Center (BAC) 8.07 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-3251 |
Cross-site scripting (XSS) vulnerability in HP Service Manager Web
Tier 7.11, 9.21, and 9.30, and HP Service Center Web Tier 6.28, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-3243 |
Cross-site scripting (XSS) vulnerability in the SEOgento plugin for
Magento allows remote attackers to inject arbitrary web script or HTML
via the id parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2012-3238 |
Cross-site scripting (XSS) vulnerability in the Backup/Restore
component in WebAdmin in Astaro Security Gateway before 8.305 allows
remote attackers to inject arbitrary web script or HTML via the
"Comment (optional)" field.
|
| CVE-2012-3233 |
Cross-site scripting (XSS) vulnerability in
__swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in
Kayako Fusion 4.40.1148, and possibly before 4.50.1581, allows remote
attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2012-3232 |
Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0,
as downloaded before May 30, 2012, allows remote attackers to inject
arbitrary web script or HTML via the _text[title] parameter.
|
| CVE-2012-3047 |
Cross-site scripting (XSS) vulnerability in the web-wizard setup page
on Cisco Scientific Atlanta D20 and D30 cable modems allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-3040 |
Cross-site scripting (XSS) vulnerability in the web server on Siemens
SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to
inject arbitrary web script or HTML via a crafted URI.
|
| CVE-2012-3031 |
Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in
Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other
products, allow remote attackers to inject arbitrary web script or
HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP
header.
|
| CVE-2012-3003 |
Open redirect vulnerability in an unspecified web application in
Siemens WinCC 7.0 SP3 before Update 2 allows remote attackers to
redirect users to arbitrary web sites and conduct phishing attacks via
a URL in a GET request.
|
| CVE-2012-2995 |
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro
InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote
attackers to inject arbitrary web script or HTML via (1) the
wrsApprovedURL parameter to addRuleAttrWrsApproveUrl.imss or (2) the
src parameter to initUpdSchPage.imss.
|
| CVE-2012-2985 |
Cross-site scripting (XSS) vulnerability in InsertDocument.aspx in
CuteSoft Cute Editor 6.4 allows remote authenticated users to inject
arbitrary web script or HTML via the _UploadID parameter.
|
| CVE-2012-2984 |
Multiple cross-site scripting (XSS) vulnerabilities in
monitor/m_overview.ink in Websense Content Gateway before 7.7.3 allow
remote attackers to inject arbitrary web script or HTML via the (1)
menu or (2) item parameter.
|
| CVE-2012-2975 |
Cross-site scripting (XSS) vulnerability in the traffic overview page
on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote
attackers to inject arbitrary web script or HTML via crafted requests
that are later listed on a summary page.
|
| CVE-2012-2960 |
Cross-site scripting (XSS) vulnerability in the import functionality
in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger
appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web
script or HTML via a crafted file.
|
| CVE-2012-2956 |
SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote
authenticated users to execute arbitrary SQL commands via the id
parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to
different vulnerability types. CVE-2012-6658 is for the XSS.
|
| CVE-2012-2955 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative user interface in IBM Lotus Protector for Mail Security
2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security
System allow remote attackers to inject arbitrary web script or HTML
via the query string.
|
| CVE-2012-2941 |
Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server
2010 9.0 Enterprise allows remote attackers to inject arbitrary web
script or HTML via the text parameter.
|
| CVE-2012-2938 |
Multiple cross-site scripting (XSS) vulnerabilities in Travelon
Express 6.2.2 allow remote attackers to inject arbitrary web script or
HTML via the holiday name field to (1) holiday_add.php or (2)
holiday_view.php.
|
| CVE-2012-2936 |
Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS
before 1.2.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) user or (2) page parameter to (a)
admin/admin_comments.php or (b) admin/admin_links.php; or list
parameter in a (3) move or (4) minimize action to (c)
admin/admin_index.php.
|
| CVE-2012-2935 |
Cross-site scripting (XSS) vulnerability in
osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in
OSCommerce Online Merchant 3.0.2 allows remote attackers to inject
arbitrary web script or HTML via the value_title parameter, a
different vulnerability than CVE-2012-1059.
|
| CVE-2012-2932 |
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery
(TWG) before 1.8.8 allow remote attackers to inject arbitrary web
script or HTML via the selitems[] parameter in a (1) copy, (2) chmod,
or (3) arch action to admin/index.php or (4) searchitem parameter in a
search action to admin/index.php.
|
| CVE-2012-2920 |
Cross-site scripting (XSS) vulnerability in the userphoto_options_page
function in user-photo.php in the User Photo plugin before 0.9.5.2 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to wp-admin/options-general.php. NOTE: some of
these details are obtained from third party information.
|
| CVE-2012-2918 |
Cross-site scripting (XSS) vulnerability in Upload/engine.php in
Chevereto 1.91 allows remote attackers to inject arbitrary web script
or HTML via the v parameter.
|
| CVE-2012-2917 |
Cross-site scripting (XSS) vulnerability in the Share and Follow
plugin 1.80.3 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the CDN API Key (cnd-key) in a
share-and-follow-menu page to wp-admin/admin.php.
|
| CVE-2012-2916 |
Cross-site scripting (XSS) vulnerability in sabre_class_admin.php in
the SABRE plugin before 2.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the active_option parameter to
wp-admin/tools.php.
|
| CVE-2012-2914 |
Cross-site scripting (XSS) vulnerability in captchademo.php in
Unijimpe Captcha allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO.
|
| CVE-2012-2913 |
Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet
plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary
web script or HTML via the id parameter to (1) leaflet_layer.php or
(2) leaflet_marker.php, as reachable through wp-admin/admin.php.
|
| CVE-2012-2912 |
Multiple cross-site scripting (XSS) vulnerabilities in the
LeagueManager plugin 3.7 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) group parameter in the
show-league page or (2) season parameter in the team page to
wp-admin/admin.php.
|
| CVE-2012-2911 |
Cross-site scripting (XSS) vulnerability in backupDB.php in
SiliSoftware backupDB() 1.2.7a allows remote attackers to inject
arbitrary web script or HTML via the onlyDB parameter.
|
| CVE-2012-2910 |
Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware
phpThumb() 1.7.11 allow remote attackers to inject arbitrary web
script or HTML via the (1) dir parameter to
demo/phpThumb.demo.random.php or (2) title parameter to
demo/phpThumb.demo.showpic.php.
|
| CVE-2012-2909 |
Multiple cross-site scripting (XSS) vulnerabilities in Viscacha
0.8.1.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) text field in the Private Messages System, (2) Bad Word
field in Zensur, or (3) Portal or (4) Topic field in Kommentar.
|
| CVE-2012-2907 |
Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb
function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11
for Drupal, when set to append the content title to the breadcrumb,
allows remote attackers to inject arbitrary web script or HTML via the
content title in a breadcrumb.
|
| CVE-2012-2906 |
Multiple cross-site scripting (XSS) vulnerabilities in
artpublic/recommandation/index.php in Artiphp CMS 5.5.0 Neo (r422)
allow remote attackers to inject arbitrary web script or HTML via the
(1) add_img_name_post, (2) asciiart_post, (3) expediteur, (4)
titre_sav, or (5) z39d27af885b32758ac0e7d4014a61561 parameter.
|
| CVE-2012-2904 |
player.swf in LongTail JW Player 5.9 allows remote attackers to
conduct cross-site scripting (XSS) attacks to inject arbitrary web
script or HTML via multiple "javascript:" sequences in the debug
parameter.
|
| CVE-2012-2903 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address
Book 7.0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) PATH_INFO to group.php, or the (2)
target_language or (3) target_flag parameter to translate.php.
|
| CVE-2012-2901 |
Cross-site scripting (XSS) vulnerability in the Profile List in the
Joomla Content Editor (JCE) component before 2.1 for Joomla! allows
remote attackers to inject arbitrary web script or HTML via the search
parameter to administrator/index.php.
|
| CVE-2012-2899 |
Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls
to WebView methods that trigger use of an applewebdata: URL, which
allows remote attackers to bypass the Same Origin Policy and conduct
Universal XSS (UXSS) attacks via vectors involving the document.write
method.
|
| CVE-2012-2889 |
Cross-site scripting (XSS) vulnerability in Google Chrome before
22.0.1229.79 allows remote attackers to inject arbitrary web script or
HTML via vectors involving frames, aka "Universal XSS (UXSS)."
|
| CVE-2012-2886 |
Cross-site scripting (XSS) vulnerability in Google Chrome before
22.0.1229.79 allows remote attackers to inject arbitrary web script or
HTML via vectors related to the Google V8 bindings, aka "Universal XSS
(UXSS)."
|
| CVE-2012-2872 |
Cross-site scripting (XSS) vulnerability in an SSL interstitial page
in Google Chrome before 21.0.1180.89 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2769 |
Multiple cross-site scripting (XSS) vulnerabilities in the topic
administration page in the Extension::MobileUI extension before 1.02
for Best Practical Solutions RT 3.8.x and in Best Practical Solutions
RT before 4.0.6 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2012-2768 |
Multiple cross-site scripting (XSS) vulnerabilities in the topic
administration page in the RTFM extension 2.0.4 through 2.4.3 for Best
Practical Solutions RT allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-2759 |
Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the
Login With Ajax (aka login-with-ajax) plugin before 3.0.4.1 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the callback parameter in a lostpassword action to
wp-login.php.
|
| CVE-2012-2751 |
ModSecurity before 2.6.6, when used with PHP, does not properly handle
single quotes not at the beginning of a request parameter value in the
Content-Disposition field of a request with a multipart/form-data
Content-Type header, which allows remote attackers to bypass filtering
rules and perform other attacks such as cross-site scripting (XSS)
attacks. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2009-5031.
|
| CVE-2012-2741 |
Cross-site scripting (XSS) vulnerability in public_html/lists/admin/
in phpList before 2.10.18 allows remote attackers to inject arbitrary
web script or HTML via the num parameter in a reconcileusers action.
|
| CVE-2012-2740 |
SQL injection vulnerability in public_html/lists/admin in phpList
before 2.10.18 allows remote attackers to execute arbitrary SQL
commands via the sortby parameter in a find action.
|
| CVE-2012-2726 |
Cross-site scripting (XSS) vulnerability in the Protest module 6.x-1.x
before 6.x-1.2 or 7.x-1.x before 7.x-1.2 for Drupal allows remote
authenticated users with the "administer protest" permission to inject
arbitrary web script or HTML via the protest_body parameter.
|
| CVE-2012-2725 |
classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML
module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate
sources with the host white list, which allows remote authenticated
users to bypass intended access restrictions and conduct cross-site
scripting (XSS) attacks.
|
| CVE-2012-2723 |
Cross-site scripting (XSS) vulnerability in the Maestro module 7.x-1.x
before 7.x-1.2 for Drupal allows remote authenticated users with
maestro admin permissions to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-2717 |
Multiple cross-site scripting (XSS) vulnerabilities in the Mobile
Tools module 6.x-2.x before 6.x-2.3 for Drupal allow remote attackers
to inject arbitrary web script or HTML via the (1) Mobile URL field or
(2) Desktop URL field to the General configuration page, or the (3)
message to the Mobile Tools block message options.
|
| CVE-2012-2715 |
Cross-site scripting (XSS) vulnerability in the themes_links function
in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for
Drupal allows remote attackers to inject arbitrary web script or HTML
via vectors related to class attributes in a list of links.
|
| CVE-2012-2712 |
Multiple cross-site scripting (XSS) vulnerabilities in the Search API
module 7.x-1.x before 7.x-1.1 for Drupal, when supporting manual entry
of field identifiers, allow remote attackers to inject arbitrary web
script or HTML via vectors related to thrown exceptions and logging
errors.
|
| CVE-2012-2711 |
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy
List module 6.x-1.x before 6.x-1.4 for Drupal allow remote
authenticated users with create or edit taxonomy terms permissions to
inject arbitrary web script or HTML via vectors related to taxonomy
information.
|
| CVE-2012-2710 |
Cross-site scripting (XSS) vulnerability in the Zen module 6.x-1.x
before 6.x-1.1 for Drupal, when "Append the content title to the end
of the breadcrumb" is enabled, allows remote attackers to inject
arbitrary web script or HTML via the content title in a breadcrumb.
|
| CVE-2012-2708 |
Cross-site scripting (XSS) vulnerability in the
_hosting_task_log_table function in
modules/hosting/task/hosting_task.module in the Hostmaster (Aegir)
module 6.x-1.x before 6.x-1.9 for Drupal allows remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via a Drush log message in a provision task log.
|
| CVE-2012-2706 |
Cross-site scripting (XSS) vulnerability in the Post Affiliate Pro
(PAP) module for Drupal allows remote attackers to inject arbitrary
web script or HTML via vectors related to user registration.
|
| CVE-2012-2705 |
The filter_titles function in the Smart Breadcrumb module 6.x-1.x
before 6.x-1.3 for Drupal does not properly convert a title to
plain-text, which allows remote authenticated users with create or
edit node permissions to conduct cross-site scripting (XSS) attacks
via the title parameter.
|
| CVE-2012-2703 |
Cross-site scripting (XSS) vulnerability in the Advertisement module
6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows
remote attackers to inject arbitrary web script or HTML via vectors
related to the "$conf variable in settings.php."
|
| CVE-2012-2698 |
Cross-site scripting (XSS) vulnerability in the outputPage function in
includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before
1.18.4, and 1.19.x before 1.19.1 allows remote attackers to inject
arbitrary web script or HTML via the uselang parameter to
index.php/Main_page.
|
| CVE-2012-2687 |
Multiple cross-site scripting (XSS) vulnerabilities in the
make_variant_list function in mod_negotiation.c in the mod_negotiation
module in the Apache HTTP Server 2.4.x before 2.4.3, when the
MultiViews option is enabled, allow remote attackers to inject
arbitrary web script or HTML via a crafted filename that is not
properly handled during construction of a variant list.
|
| CVE-2012-2683 |
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before
0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid
(MRG) 2.0, allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors related to (1) "error message displays"
or (2) "in source HTML on certain pages."
|
| CVE-2012-2662 |
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat
Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System
allow remote attackers to inject arbitrary web script or HTML via
unspecified parameters to the (1) System Agent or (2) End Entity
pages.
|
| CVE-2012-2648 |
Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16
and earlier for iOS on the iPad, and 3.15.1 and earlier for iOS on the
iPhone and iPod touch, allows remote attackers to inject arbitrary web
script or HTML via vectors involving use of this app in conjunction
with a web browser.
|
| CVE-2012-2644 |
Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4
and earlier for Movable Type allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2012-2642.
|
| CVE-2012-2643 |
Cross-site scripting (XSS) vulnerability in KENT-WEB YY-BOARD before
6.4 allows remote attackers to inject arbitrary web script or HTML via
a crafted form entry.
|
| CVE-2012-2642 |
Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4
and earlier for Movable Type allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2012-2644.
|
| CVE-2012-2641 |
Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3
allows remote attackers to inject arbitrary web script or HTML by
triggering improper interaction with an unspecified library.
|
| CVE-2012-2638 |
Cross-site scripting (XSS) vulnerability in SmallPICT.cgi in SmallPICT
before 2.7 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-2637 |
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04
and earlier might allow remote attackers to inject arbitrary web
script or HTML via a crafted cookie.
|
| CVE-2012-2636 |
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04
and earlier allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-2634 |
Cross-site scripting (XSS) vulnerability in FeedDemon before 4.0, when
the feed preview option is enabled, allows remote attackers to inject
arbitrary web script or HTML via a feed.
|
| CVE-2012-2633 |
Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp
plugin before 1.8.3.1 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the User-Agent HTTP header.
|
| CVE-2012-2631 |
Cross-site scripting (XSS) vulnerability in WEBLOGIC @WEB ShoppingCart
before 1.5.2.0, and @WEB ShoppingCart T 1.5.0.1 and earlier, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-2605 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
administrative interface in Bradford Network Sentry before 5.3.3 allow
remote attackers to hijack the authentication of administrators for
requests that (1) insert XSS sequences or (2) send messages to
clients.
|
| CVE-2012-2604 |
Multiple cross-site scripting (XSS) vulnerabilities in GuestAccess.jsp
in the Guest/Contractor access component in the administrative
interface in Bradford Network Sentry before 5.3.3 allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified fields.
|
| CVE-2012-2595 |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified web
applications in Siemens WinCC 7.0 SP3 before Update 2 allow remote
attackers to inject arbitrary web script or HTML via vectors involving
special characters in parameters.
|
| CVE-2012-2592 |
Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1
allows remote attackers to inject arbitrary web script or HTML via the
body of an email.
|
| CVE-2012-2591 |
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect
Email Server 10.0 and 10.0.0.3 allow remote attackers to inject
arbitrary web script or HTML via the (1) From or (2) Date field in an
email.
|
| CVE-2012-2590 |
Multiple cross-site scripting (XSS) vulnerabilities in ESCON
SupportPortal Professional Edition 3.0 allow remote attackers to
inject arbitrary web script or HTML via an e-mail message body with
(1) a SCRIPT element, (2) a crafted SRC attribute of an IFRAME
element, (3) a crafted CONTENT attribute of an HTTP-EQUIV="Set-Cookie"
META element, or (4) an innerHTML attribute within an XML document.
|
| CVE-2012-2588 |
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable
Enterprise 6.5 allow remote attackers to inject arbitrary web script
or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in
an SMTP e-mail message.
|
| CVE-2012-2587 |
Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic
MailSuite Pro 6.3 allow remote attackers to inject arbitrary web
script or HTML via an e-mail message body with a crafted SRC attribute
of (1) an IFRAME element or (2) a SCRIPT element.
|
| CVE-2012-2586 |
Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq
2.17.3.3150 allow remote attackers to inject arbitrary web script or
HTML via an e-mail message subject with (1) a JavaScript alert
function used in conjunction with the fromCharCode method or (2) a
SCRIPT element; an e-mail message body with (3) a crafted SRC
attribute of an IFRAME element, (4) a data: URL in the CONTENT
attribute of an HTTP-EQUIV="refresh" META element, or (5) a Cascading
Style Sheets (CSS) expression property in the STYLE attribute of an
IMG element; or an e-mail message Date header with (6) a JavaScript
alert function used in conjunction with the fromCharCode method, (7) a
SCRIPT element, (8) a CSS expression property in the STYLE attribute
of an arbitrary element, (9) a crafted SRC attribute of an IFRAME
element, or (10) a data: URL in the CONTENT attribute of an
HTTP-EQUIV="refresh" META element.
|
| CVE-2012-2585 |
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine
ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web
script or HTML via an e-mail message body with (1) a SCRIPT element,
(2) a crafted Cascading Style Sheets (CSS) expression property, (3) a
CSS expression property in the STYLE attribute of an arbitrary
element, or (4) a crafted SRC attribute of an IFRAME element, or an
e-mail message subject with (5) a SCRIPT element, (6) a CSS expression
property in the STYLE attribute of an arbitrary element, (7) a crafted
SRC attribute of an IFRAME element, (8) a crafted CONTENT attribute of
an HTTP-EQUIV="refresh" META element, or (9) a data: URL in the
CONTENT attribute of an HTTP-EQUIV="refresh" META element.
|
| CVE-2012-2584 |
Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon
Free 12.5.4 allow remote attackers to inject arbitrary web script or
HTML via an e-mail message body with (1) the Cascading Style Sheets
(CSS) expression property in conjunction with a CSS comment within the
STYLE attribute of an IMG element, (2) the CSS expression property in
conjunction with multiple CSS comments within the STYLE attribute of
an arbitrary element, or (3) an innerHTML attribute within an XML
document.
|
| CVE-2012-2583 |
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget
plugin 1.42 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the body of an email.
|
| CVE-2012-2582 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket
Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before
3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5,
3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow remote attackers to
inject arbitrary web script or HTML via an e-mail message body with
(1) a Cascading Style Sheets (CSS) expression property in the STYLE
attribute of an arbitrary element or (2) UTF-7 text in an
HTTP-EQUIV="CONTENT-TYPE" META element.
|
| CVE-2012-2580 |
Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3,
and possibly before 1.5.15, for WordPress allows remote attackers to
inject arbitrary web script or HTML via the From field of an email.
|
| CVE-2012-2579 |
Multiple cross-site scripting (XSS) vulnerabilities in the WP
SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or
(4) Subject field of an email.
|
| CVE-2012-2578 |
Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2
allow remote attackers to inject arbitrary web script or HTML via an
e-mail message body with (1) a JavaScript alert function used in
conjunction with the fromCharCode method, (2) a SCRIPT element, (3) a
Cascading Style Sheets (CSS) expression property in the STYLE
attribute of an arbitrary element, or (4) an innerHTML attribute
within an XML document.
|
| CVE-2012-2577 |
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds
Orion Network Performance Monitor (NPM) before 10.3.1 allow remote
attackers to inject arbitrary web script or HTML via the (1)
syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf
file.
|
| CVE-2012-2575 |
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4
allows remote attackers to inject arbitrary web script or HTML via the
SRC attribute of an IFRAME element in the body of an HTML e-mail
message.
|
| CVE-2012-2573 |
Multiple cross-site scripting (XSS) vulnerabilities in T-dah WebMail
3.2.0-2.3 allow remote attackers to inject arbitrary web script or
HTML via an e-mail message body with (1) a SCRIPT element, (2) a
crafted Cascading Style Sheets (CSS) expression property, (3) a CSS
expression property in the STYLE attribute of an arbitrary element,
(4) an ONLOAD attribute of a BODY element, (5) a crafted SRC attribute
of an IFRAME element, (6) a crafted CONTENT attribute of an
HTTP-EQUIV="refresh" META element, or (7) a data: URL in the CONTENT
attribute of an HTTP-EQUIV="refresh" META element.
|
| CVE-2012-2572 |
Cross-site scripting (XSS) vulnerability in the ThreeWP Email
Reflector plugin before 1.16 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the Subject of an email.
|
| CVE-2012-2571 |
Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail
Server 3.8.1.6 allow remote attackers to inject arbitrary web script
or HTML via an e-mail message body with (1) a SCRIPT element, (2) a
crafted Cascading Style Sheets (CSS) expression property, (3) a CSS
expression property in the STYLE attribute of an arbitrary element,
(4) a crafted SRC attribute of an IFRAME element, or (5) UTF-7 text in
an HTTP-EQUIV="CONTENT-TYPE" META element.
|
| CVE-2012-2570 |
Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart
Gold 4.5 allows remote attackers to inject arbitrary web script or
HTML via the symb parameter.
|
| CVE-2012-2569 |
Cross-site scripting (XSS) vulnerability in Synametrics Technologies
Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web
script or HTML via the body of an email.
|
| CVE-2012-2563 |
Multiple cross-site scripting (XSS) vulnerabilities in Bloxx Web
Filtering before 5.0.14 allow (1) remote attackers to inject arbitrary
web script or HTML via web traffic that is examined within the Bloxx
Reports component, and allow (2) remote authenticated administrators
to inject arbitrary web script or HTML via vectors involving
administrative menu functions.
|
| CVE-2012-2552 |
Cross-site scripting (XSS) vulnerability in the SQL Server Report
Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL
Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote
attackers to inject arbitrary web script or HTML via an unspecified
parameter, aka "Reflected XSS Vulnerability."
|
| CVE-2012-2536 |
Cross-site scripting (XSS) vulnerability in Microsoft Systems
Management Server 2003 SP3 and System Center Configuration Manager
2007 SP2 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
|
| CVE-2012-2520 |
Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007
SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010
Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove
Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint
Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote
attackers to inject arbitrary web script or HTML via a crafted string,
aka "HTML Sanitization Vulnerability."
|
| CVE-2012-2446 |
Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in
the WebAdmin Portal in Netsweeper allows remote attackers to inject
arbitrary web script or HTML via the group parameter in a lookup
action.
|
| CVE-2012-2436 |
Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS
before 1.2.2 allow remote attackers to inject arbitrary web script or
HTML via (1) an arbitrary parameter in a move or (2) minimize action
to admin/admin_index.php; (3) the karma_username parameter to
module.php in the karma module; (4) q_1_low, (5) q_1_high, (6)
q_2_low, or (7) q_2_high parameter in a configure action to module.php
in the captcha module; or (8) the edit parameter to module.php in the
admin_language module.
|
| CVE-2012-2413 |
Cross-site scripting (XSS) vulnerability in the ja_purity template for
Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary
web script or HTML via the Mod* cookie parameter to html/modules.php.
|
| CVE-2012-2404 |
wp-comments-post.php in WordPress before 3.3.2 supports offsite
redirects, which makes it easier for remote attackers to conduct
cross-site scripting (XSS) attacks via unspecified vectors.
|
| CVE-2012-2403 |
wp-includes/formatting.php in WordPress before 3.3.2 attempts to
enable clickable links inside attributes, which makes it easier for
remote attackers to conduct cross-site scripting (XSS) attacks via
unspecified vectors.
|
| CVE-2012-2399 |
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload
2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image
Manager 1.1 and earlier, and other products allows remote attackers to
inject arbitrary web script or HTML via the buttonText parameter, a
different vulnerability than CVE-2012-3414.
|
| CVE-2012-2398 |
Cross-site scripting (XSS) vulnerability in files/ajax/download.php in
ownCloud before 3.0.3 allows remote attackers to inject arbitrary web
script or HTML via the files parameter, a different vulnerability than
CVE-2012-2269.4.
|
| CVE-2012-2397 |
Cross-site request forgery (CSRF) vulnerability in ownCloud before
3.0.3 allows remote attackers to hijack the authentication of
arbitrary users for requests that insert cross-site scripting (XSS)
sequences via vectors involving contacts.
|
| CVE-2012-2381 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller
before 5.0.1 allow remote authenticated users to inject arbitrary web
script or HTML by leveraging the blogger role.
|
| CVE-2012-2371 |
Cross-site scripting (XSS) vulnerability in index.php in the
WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the pagination_wp_facethumb
parameter.
|
| CVE-2012-2365 |
Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9,
2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated
users to inject arbitrary web script or HTML via the idnumber field to
cohort/edit.php.
|
| CVE-2012-2364 |
Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle
2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows
remote authenticated users to inject arbitrary web script or HTML via
an assignment submission with zip compression, leading to text/html
rendering during a "download all" action.
|
| CVE-2012-2362 |
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog
implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer
is used, allows remote attackers to inject arbitrary web script or
HTML via a crafted parameter to blog/index.php.
|
| CVE-2012-2361 |
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php
in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x
before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users
to inject arbitrary web script or HTML via the name field (aka the
service name) to admin/webservice/service.php.
|
| CVE-2012-2360 |
Cross-site scripting (XSS) vulnerability in the Wiki subsystem in
Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3
allows remote authenticated users to inject arbitrary web script or
HTML via a crafted string that is inserted into a page title.
|
| CVE-2012-2339 |
Cross-site scripting (XSS) vulnerability in the Glossary module
6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors related to
"taxonomy information."
|
| CVE-2012-2332 |
SQL injection vulnerability in serendipity/serendipity_admin.php in
Serendipity before 1.6.1 allows remote attackers to execute arbitrary
SQL commands via the serendipity[plugin_to_conf] parameter. NOTE: this
issue might be resultant from cross-site request forgery (CSRF).
|
| CVE-2012-2331 |
Cross-site scripting (XSS) vulnerability in
serendipity/serendipity_admin_image_selector.php in Serendipity before
1.6.1 allows remote attackers to inject arbitrary web script or HTML
via the serendipity[textarea] parameter. NOTE: this issue might be
resultant from cross-site request forgery (CSRF).
|
| CVE-2012-2326 |
Cross-site scripting (XSS) vulnerability in the Admin Control Panel
(ACP) in MyBB (aka MyBulletinBoard) before 1.6.7 allows remote
administrators to inject arbitrary web script or HTML via a malformed
file name in an orphaned attachment.
|
| CVE-2012-2310 |
Cross-site scripting (XSS) vulnerability in the cctags module for
Drupal 6.x-1.x before 6.x-1.10 and 7.x-1.x before 7.x-1.10 allows
remote authenticated users with certain roles to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-2309 |
Cross-site scripting (XSS) vulnerability in the Glossify Internal
Links Auto SEO module for Drupal 6.x-2.5 and earlier allows remote
authenticated users with certain roles to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2012-2308 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Grid :
Catalog module for Drupal 6.x-1.6 and earlier allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-2300 |
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart
module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal
allow remote authenticated users with the administer product classes
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-2298 |
Multiple cross-site scripting (XSS) vulnerabilities in the RealName
module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to
inject arbitrary web script or HTML via vectors related to (1) "user
names in page titles" and (2) "autocomplete callbacks."
|
| CVE-2012-2297 |
Multiple cross-site scripting (XSS) vulnerabilities in the Creative
Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote
authenticated users with the administer creative commons permission to
inject arbitrary web script or HTML via the (1)
creativecommons_user_message or (2)
creativecommons_site_license_additional_text parameter.
|
| CVE-2012-2278 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1)
Self-Service Console and (2) Security Console in EMC RSA
Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance
3.0 before SP4 P14 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-2274 |
Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in
PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary
web script or HTML via the file parameter.
|
| CVE-2012-2269 |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before
3.0.3 allow remote attackers to inject arbitrary web script or HTML
via (1) an arbitrary field to apps/contacts/ajax/addcard.php, (2) the
parameter parameter to apps/contacts/ajax/addproperty.php, (3) the
name parameter to apps/contacts/ajax/createaddressbook, (4) the file
parameter to files/download.php, or the (5) name, (6) user, or (7)
redirect_url parameter to files/index.php.
|
| CVE-2012-2253 |
Cross-site scripting (XSS) vulnerability in group/members.php in
Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote
attackers to inject arbitrary web script or HTML via the query
parameter.
|
| CVE-2012-2247 |
Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5
and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web
script or HTML via vectors related to artefact/file/ and a crafted SVG
file.
|
| CVE-2012-2243 |
Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5
and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web
script or HTML by uploading an XML file with the xhtml extension,
which is rendered inline as script. NOTE: this can be leveraged with
CVE-2012-2244 to execute arbitrary code without authentication, as
demonstrated by modifying the clamav path.
|
| CVE-2012-2235 |
Cross-site scripting (XSS) vulnerability in Support Incident Tracker
(SiT!) 3.65 and earlier allows remote attackers to inject arbitrary
web script or HTML via the id parameter to index.php, which is not
properly handled in an error message.
|
| CVE-2012-2234 |
Cross-site scripting (XSS) vulnerability in sources/users.queries.php
in TeamPass before 2.1.6 allows remote authenticated users to inject
arbitrary web script or HTML via the login parameter in an
add_new_user action.
|
| CVE-2012-2211 |
Cross-site scripting (XSS) vulnerability in
phpgwapi/inc/common_functions_inc.php in eGroupware before
1.8.004.20120405 allows remote attackers to inject arbitrary web
script or HTML via the menuaction parameter to
etemplate/process_exec.php. NOTE: some of these details are obtained
from third party information.
|
| CVE-2012-2209 |
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in
Piwigo before 2.3.4 allow remote attackers to inject arbitrary web
script or HTML via the (1) section parameter in the configuration
module, (2) installstatus parameter in the languages_new module, or
(3) theme parameter in the theme module.
|
| CVE-2012-2205 |
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest
7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote
authenticated users to inject arbitrary web script or HTML via a
workspace query.
|
| CVE-2012-2193 |
Cross-site scripting (XSS) vulnerability in Query Studio in IBM Cognos
Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1
before IF2, and 10.2 before IF1 allows user-assisted remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2177 |
Cross-site scripting (XSS) vulnerability in IBM Cognos Business
Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before
IF2, and 10.2 before IF1 allows user-assisted remote attackers to
inject arbitrary web script or HTML via vectors related to the search
feature.
|
| CVE-2012-2172 |
Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in
the Storage Manager Profiler in IBM System Storage DS Storage Manager
before 10.83.xx.18 on DS Series devices allows remote attackers to
inject arbitrary web script or HTML via the updateRegn parameter.
|
| CVE-2012-2169 |
Cross-site scripting (XSS) vulnerability in the file-upload
functionality in the Web client in IBM Rational ClearQuest 7.1.x
before 7.1.2.7 allows remote authenticated users to inject arbitrary
web script or HTML via the File Description field.
|
| CVE-2012-2161 |
Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM
Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x
and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0
and 6.0.1, allows remote attackers to inject arbitrary web script or
HTML via a crafted URL.
|
| CVE-2012-2156 |
Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the u_email parameter (aka Authors Email field) to
manager/users.php, (2) the u_realname parameter (aka Authors Name
field) to manager/users.php, or (3) the c_author parameter (aka Author
field) in an ADD A COMMENT section.
|
| CVE-2012-2154 |
Cross-site scripting (XSS) vulnerability in the CDN2 Video module 6.x
for Drupal allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-2151 |
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x
before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-2129 |
Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki
2012-01-25 Angua allows remote attackers to inject arbitrary web
script or HTML via the target parameter in an edit action.
|
| CVE-2012-2128 |
** DISPUTED **
Cross-site request forgery (CSRF) vulnerability in doku.php in
DokuWiki 2012-01-25 Angua allows remote attackers to hijack the
authentication of administrators for requests that add arbitrary
users. NOTE: this issue has been disputed by the vendor, who states
that it is resultant from CVE-2012-2129: "the exploit code simply uses
the XSS hole to extract a valid CSRF token."
|
| CVE-2012-2117 |
Cross-site scripting (XSS) vulnerability in the Gigya - Social
optimization module 6.x before 6.x-3.2 for Drupal allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-2112 |
Cross-site scripting (XSS) vulnerability in the Exception Handler in
TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8,
and 4.7 allows remote attackers to inject arbitrary web script or HTML
via exception messages.
|
| CVE-2012-2099 |
Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10
allow remote attackers to inject arbitrary web script or HTML via the
(1) search field, or the (2) Author or (3) select_sort parameters in
an advanced search.
|
| CVE-2012-2094 |
Cross-site scripting (XSS) vulnerability in the refresh mechanism in
the log viewer in horizon/static/horizon/js/horizon.js in OpenStack
Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote
attackers to inject arbitrary web script or HTML via the guest
console.
|
| CVE-2012-2084 |
Cross-site scripting (XSS) vulnerability in the Printer, email and PDF
versions module 6.x-1.x before 6.x-1.15 and 7.x-1.x before 7.x-1.0 for
Drupal allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, probably the PATH_INFO.
|
| CVE-2012-2083 |
Cross-site scripting (XSS) vulnerability in the
fusion_core_preprocess_page function in fusion_core/template.php in
the Fusion module before 6.x-1.13 for Drupal allows remote attackers
to inject arbitrary web script or HTML via the q parameter.
|
| CVE-2012-2082 |
Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka
CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote
authenticated users with the post comments permission to inject
arbitrary web script or HTML via a user signature.
|
| CVE-2012-2076 |
Cross-site scripting (XSS) vulnerability in the administration forms
in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows
remote authenticated users with administer sharethis permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2075 |
Cross-site scripting (XSS) vulnerability in the Contact Save module
6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users
with the access site-wide contact form permission to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-2072 |
Cross-site scripting (XSS) vulnerability in the Share Buttons
(AddToAny) module 6.x-3.x before 6.x-3.4 for Drupal allows remote
authenticated users with the administer addtoany permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2071 |
Cross-site scripting (XSS) vulnerability in the Contact Forms module
6.x-1.x before 6.x-1.13 for Drupal when the core contact form is
enabled, allows remote authenticated users with the administer
site-wide contact form permission to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-2070 |
Cross-site scripting (XSS) vulnerability in the MultiBlock module
6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows
remote authenticated users with the administer blocks permission to
inject arbitrary web script or HTML via the block title.
|
| CVE-2012-2069 |
Cross-site request forgery (CSRF) vulnerability in the Wishlist module
6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.6 for Drupal allows
remote attackers to hijack the authentication of arbitrary users for
requests that insert cross-site scripting (XSS) sequences via the (1)
wl_reveal or (2) q parameters.
|
| CVE-2012-2068 |
Multiple cross-site scripting (XSS) vulnerabilities in
fancy_slide.module in the Fancy Slide module before 6.x-2.7 for Drupal
allow remote authenticated users with the administer fancy_slide
permission to inject arbitrary web script or HTML via the (1)
node_title or (2) nodequeue_title parameter.
|
| CVE-2012-2066 |
Cross-site scripting (XSS) vulnerability in the FCKeditor module
6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9
and 7.x-1.x before 7.x-1.7 for Drupal allows remote authenticated
users or remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-2065 |
Cross-site scripting (XSS) vulnerability in the Language Icons module
6.x-2.x before 6.x-2.1 and 7.x-1.x before 7.x-1.0 for Drupal allows
remote authenticated users with administer languages permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2064 |
Cross-site scripting (XSS) vulnerability in
theme/views_lang_switch.theme.inc in the Views Language Switcher
module before 7.x-1.2 for Drupal allows remote attackers to inject
arbitrary web script or HTML via the q parameter.
|
| CVE-2012-2060 |
Cross-site scripting (XSS) vulnerability in the Admin tools module for
Drupal allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2012-2059 |
Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker
module for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-2022 |
Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node
Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2021 |
Multiple cross-site scripting (XSS) vulnerabilities in HP AssetManager
5.20, 5.21, 5.22, and 9.30 allow remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2018 |
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i
(NNMi) 8.x, 9.0x, and 9.1x allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-2011 |
Multiple cross-site scripting (XSS) vulnerabilities in HP Web Jetadmin
8.x allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-2008 |
Cross-site scripting (XSS) vulnerability in HP Performance Insight for
Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2005 |
Cross-site scripting (XSS) vulnerability in HP Insight Management
Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-2001 |
Cross-site scripting (XSS) vulnerability in HP SNMP Agents for Linux
before 9.0.0 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-1992 |
Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS
Made Simple 1.10.3 and earlier allows remote attackers to inject
arbitrary web script or HTML via the email parameter (aka the Email
Address field in the Edit User template).
|
| CVE-2012-1990 |
Multiple cross-site scripting (XSS) vulnerabilities in Schneider
Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 allow remote
attackers to inject arbitrary web script or HTML via (1) the
evtvariablename parameter in an evts.xml action to kw.dll, (2)
unspecified search fields, or (3) unspecified content-display fields.
|
| CVE-2012-1984 |
Multiple cross-site scripting (XSS) vulnerabilities in RealNetworks
Helix Server and Helix Mobile Server 14.x before 14.3.x allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-1982 |
Cross-site scripting (XSS) vulnerability in
my_admin/admin1_list_pages.php in SocialCMS 1.0.2 and earlier allows
remote authenticated users to inject arbitrary web script or HTML via
the TR_title parameter in an edit action.
|
| CVE-2012-1979 |
Cross-site scripting (XSS) vulnerability in starnet/index.php in
SyndeoCMS 3.0.01 and earlier allows remote authenticated users to
inject arbitrary web script or HTML via the email parameter (aka Email
address field) in an edit_user configuration action.
|
| CVE-2012-1966 |
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do
not have the same context-menu restrictions for data: URLs as for
javascript: URLs, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via a crafted URL.
|
| CVE-2012-1965 |
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do
not properly establish the security context of a feed: URL, which
allows remote attackers to bypass unspecified cross-site scripting
(XSS) protection mechanisms via a feed:javascript: URL.
|
| CVE-2012-1957 |
An unspecified parser-utility class in Mozilla Firefox 4.x through
13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0,
Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not
properly handle EMBED elements within description elements in RSS
feeds, which allows remote attackers to conduct cross-site scripting
(XSS) attacks via a feed.
|
| CVE-2012-1956 |
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey
before 2.12 do not prevent use of the Object.defineProperty method to
shadow the location object (aka window.location), which makes it
easier for remote attackers to conduct cross-site scripting (XSS)
attacks via vectors involving a plugin.
|
| CVE-2012-1944 |
The Content Security Policy (CSP) implementation in Mozilla Firefox
4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0
through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before
2.10 does not block inline event handlers, which makes it easier for
remote attackers to conduct cross-site scripting (XSS) attacks via a
crafted HTML document.
|
| CVE-2012-1935 |
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x
before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject
arbitrary web script or HTML via the (1) Back parameter to
admin/ad.php, or the (2) token or (3) f_email parameter to
admin/password_check_token.php.
|
| CVE-2012-1912 |
Cross-site scripting (XSS) vulnerability in preferences.php in PHP
Address Book 7.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the from parameter. NOTE: the
index.php vector is already covered by CVE-2008-2566.
|
| CVE-2012-1908 |
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.3
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2012-1899 |
Multiple cross-site scripting (XSS) vulnerabilities in
webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow
remote attackers to inject arbitrary web script or HTML via the (1)
First name, (2) Last name or (3) Email (required) fields.
|
| CVE-2012-1898 |
Multiple cross-site scripting (XSS) vulnerabilities in
wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1)
user[name], (2) user[email], or (3) user[username] parameters.
|
| CVE-2012-1892 |
Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio
Team Foundation Server 2010 SP1 allows remote attackers to inject
arbitrary web script or HTML via an unspecified parameter, aka "XSS
Vulnerability."
|
| CVE-2012-1872 |
Cross-site scripting (XSS) vulnerability in Microsoft Internet
Explorer 6 through 9 allows remote attackers to inject arbitrary web
script or HTML via crafted character sequences with EUC-JP encoding,
aka "EUC-JP Character Encoding Vulnerability."
|
| CVE-2012-1863 |
Cross-site scripting (XSS) vulnerability in Microsoft Office
SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0
SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote
attackers to inject arbitrary web script or HTML via crafted
JavaScript elements in a URL, aka "SharePoint Reflected List Parameter
Vulnerability."
|
| CVE-2012-1861 |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint
Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and
Office Web Apps 2010 Gold and SP1 allows remote attackers to inject
arbitrary web script or HTML via crafted JavaScript elements in a URL,
aka "SharePoint Script in Username Vulnerability."
|
| CVE-2012-1859 |
Cross-site scripting (XSS) vulnerability in scriptresx.ashx in
Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation
2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote
attackers to inject arbitrary web script or HTML via crafted
JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
|
| CVE-2012-1858 |
The toStaticHTML API (aka the SafeHTML component) in Microsoft
Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and
2010 Attendee does not properly handle event attributes and script,
which makes it easier for remote attackers to conduct cross-site
scripting (XSS) attacks via a crafted HTML document, aka "HTML
Sanitization Vulnerability."
|
| CVE-2012-1857 |
Cross-site scripting (XSS) vulnerability in the Enterprise Portal
component in Microsoft Dynamics AX 2012 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL, aka "Dynamics
AX Enterprise Portal XSS Vulnerability."
|
| CVE-2012-1842 |
Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the
Quantum Scalar i500 tape library with firmware before i7.0.3
(604G.GS00100), also distributed as the Dell ML6000 tape library with
firmware before A20-00 (590G.GS00100), allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1835 |
Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One
Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers
to inject arbitrary web script or HTML via the (1) title parameter to
app/view/agenda-widget-form.php; (2) args, (3) title, (4)
before_title, or (5) after_title parameter to
app/view/agenda-widget.php; (6) button_value parameter to
app/view/box_publish_button.php; or (7) msg parameter to
/app/view/save_successful.php.
|
| CVE-2012-1834 |
Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head
function in functions.php in the CMS Tree Page View plugin before
0.8.9 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the cms_tpv_view parameter to
wp-admin/options-general.php.
|
| CVE-2012-1829 |
Multiple cross-site scripting (XSS) vulnerabilities in AutoFORM PDM
Archive before 6.920 allow remote authenticated users to inject
arbitrary web script or HTML via unspecified fields.
|
| CVE-2012-1825 |
Multiple cross-site scripting (XSS) vulnerabilities in the status
program on the ForeScout CounterACT appliance with software 6.3.3.2
through 6.3.4.10 allow remote attackers to inject arbitrary web script
or HTML via (1) the loginname parameter in a forgotpass action or (2)
the username parameter.
|
| CVE-2012-1814 |
Cross-site scripting (XSS) vulnerability in Emerson DeltaV and DeltaV
Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials
Scientific Graph 5.0.0.6 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-1807 |
Cross-site scripting (XSS) vulnerability in the web server in the ECOM
Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F,
H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1792 |
Cross-site scripting (XSS) vulnerability in
osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in
OSCommerce Online Merchant 3.0.2, when the software is being
installed, allows remote attackers to inject arbitrary web script or
HTML via the name parameter to oscommerce/index.php, which is not
properly handled in an error message. NOTE: this might not be a
vulnerability, since the ability to access oscommerce/index.php during
installation may already imply administrator privileges.
|
| CVE-2012-1789 |
Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3
allow remote attackers to inject arbitrary web script or HTML via the
(1) surname or (2) firstname parameters to
modules/members/addmember.php; or (3) groupdescription or (4)
groupname parameters to modules/groups/addgroupform.php.
|
| CVE-2012-1788 |
Multiple cross-site scripting (XSS) vulnerabilities in wonderdesk.cgi
in WonderDesk SQL 4.14 allow remote attackers to inject arbitrary web
script or HTML via the (1) cus_email parameter in a cust_lostpw
action; or (2) help_name, (3) help_email, (4) help_website, or (5)
help_example_url parameters in an hd_modify_record action.
|
| CVE-2012-1787 |
Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in
Webglimpse 2.20.0 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DOMAIN
parameters.
|
| CVE-2012-1782 |
Multiple cross-site scripting (XSS) vulnerabilities in questions/ask
in OSQA 3b allow remote attackers to inject arbitrary web script or
HTML via the (1) url bar or (2) picture bar.
|
| CVE-2012-1781 |
Multiple cross-site scripting (XSS) vulnerabilities in
ajax/commentajax.php in SocialCMS 1.0.5 allow remote attackers to
inject arbitrary web script or HTML via the (1) TREF_email_address or
(2) TR_name parameters.
|
| CVE-2012-1779 |
Cross-site scripting (XSS) vulnerability in IDevSpot
idev-BusinessDirectory 3.0 allows remote attackers to inject arbitrary
web script or HTML via the SEARCH parameter to index.php.
|
| CVE-2012-1664 |
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel
in osCMax before 2.5.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) username parameter in a process action to
admin/login.php; (2) pageTitle, (3) current_product_id, or (4) cPath
parameter to admin/new_attributes_include.php; (5) sb_id, (6) sb_key,
(7) gc_id, (8) gc_key, or (9) path parameter to admin/htaccess.php;
(10) title parameter to admin/information_form.php; (11) search
parameter to admin/xsell.php; (12) gross or (13) max parameter to
admin/stats_products_purchased.php; (14) status parameter to
admin/stats_monthly_sales.php; (15) sorted parameter to
admin/stats_customers.php; (16) information_id parameter to
/admin/information_manager.php; or (17) zID parameter to
/admin/geo_zones.php.
|
| CVE-2012-1660 |
Multiple cross-site scripting (XSS) vulnerabilities in
components/select.inc in the Webform module 6.x-3.x before 6.x-3.17
and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)"
module is enabled, allow remote authenticated users with the create
webform content permission to inject arbitrary web script or HTML via
vectors related to (1) checkboxes or (2) radios.
|
| CVE-2012-1659 |
Cross-site scripting (XSS) vulnerability in the Node Recommendation
module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2012-1658 |
Cross-site scripting (XSS) vulnerability in the Read More Link module
6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users
with the access administration pages permission to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-1657 |
Cross-site scripting (XSS) vulnerability in block_class.module in the
Block Class module before 7.x-1.1 for Drupal allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via the class name.
|
| CVE-2012-1654 |
Multiple cross-site scripting (XSS) vulnerabilities in the Data module
6.x-1.x before 6.x-1.0 and 7.x-1.x before 7.x-1.0-alpha3 for Drupal
allow remote authenticated users with the administer data tables
permission to inject arbitrary web script or HTML via the title
parameter in (1) data.views.inc and (2) data_ui/data_ui.admin.inc.
|
| CVE-2012-1653 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Views
Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors, related to "views pages."
|
| CVE-2012-1652 |
Cross-site scripting (XSS) vulnerability in the Hierarchical Select
module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated
users with administer taxonomy permissions to inject arbitrary web
script or HTML via unspecified vectors related to "the vocabulary's
help text."
|
| CVE-2012-1651 |
Cross-site scripting (XSS) vulnerability in the Submenu Tree module
before 6.x-1.5 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1648 |
Cross-site scripting (XSS) vulnerability in the Cool Aid module before
6.x-1.9 for Drupal allows remote authenticated users with the
administer coolaid permission to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2012-1647 |
Multiple cross-site scripting (XSS) vulnerabilities in the "stand
alone PHP application for the OSM Player," as used in the MediaFront
module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal,
allow remote attackers to inject arbitrary web script or HTML via (1)
$_SERVER['HTTP_HOST'] or (2) $_SERVER['SCRIPT_NAME'] to
players/osmplayer/player/OSMPlayer.php, (3) playlist parameter to
players/osmplayer/player/getplaylist.php, and possibly other vectors
related to $_SESSION.
|
| CVE-2012-1646 |
Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module
6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote
authenticated users to inject arbitrary web script or HTML via the (1)
title parameter in faq.admin.inc or (2) detailed_question parameter in
faq.module.
|
| CVE-2012-1640 |
Multiple cross-site scripting (XSS) vulnerabilities in the Managesite
module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated
users with "administer managesite" permissions to inject arbitrary web
script or HTML via the title parameter when (1) adding or (2) updating
a category.
|
| CVE-2012-1639 |
Multiple cross-site scripting (XSS) vulnerabilities in
product/commerce_product.module in the Drupal Commerce module for
Drupal before 7.x-1.2 allow remote authenticated users to inject
arbitrary web script or HTML via the (1) sku or (2) title parameters.
|
| CVE-2012-1634 |
Cross-site scripting (XSS) vulnerability in video_filter.codecs.inc in
the Video Filter module 6.x-2.x and 7.x-2.x for Drupal allows remote
attackers to inject arbitrary web script or HTML via the EMBEDLOOKUP
parameter for Blip.tv links.
|
| CVE-2012-1632 |
Cross-site scripting (XSS) vulnerability in password_policy.admin.inc
in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for
Drupal allows remote authenticated users with administer policies
permissions to inject arbitrary web script or HTML via the name
parameter.
|
| CVE-2012-1630 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator
module for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-1629 |
Cross-site scripting (XSS) vulnerability in the Taxotouch module for
Drupal allows remote authenticated users with certain permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1628 |
Cross-site scripting (XSS) vulnerability in the SuperCron module for
Drupal allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-1627 |
Cross-site scripting (XSS) vulnerability in vud_term.module in the
Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1
for Drupal allows remote authenticated users to inject arbitrary web
script or HTML via taxonomy terms.
|
| CVE-2012-1624 |
Multiple cross-site scripting (XSS) vulnerabilities in the Lingotek
module 6.x-1.x before 6.x-1.40 for Drupal allow remote authenticated
users to inject arbitrary web script or HTML when (1) creating or (2)
editing page content.
|
| CVE-2012-1621 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For
Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote
attackers to inject arbitrary web script or HTML via (1) a parameter
array in freemarker templates, the (2) contentId or (3) mapKey
parameter in a cms event request, which are not properly handled in an
error message, or unspecified input in (4) an ajax request to the
getServerError function in checkoutProcess.js or (5) a Webslinger
component request. NOTE: some of these details are obtained from third
party information.
|
| CVE-2012-1613 |
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in
Coppermine Photo Gallery before 1.5.20 allows remote authenticated
users with certain privileges to inject arbitrary web script or HTML
via the keywords parameter.
|
| CVE-2012-1612 |
Cross-site scripting (XSS) vulnerability in the update manager in
Joomla! 2.5.x before 2.5.4 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-1608 |
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13,
4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote
attackers to bypass the cross-site scripting (XSS) protection
mechanism and inject arbitrary web script or HTML via non printable
characters.
|
| CVE-2012-1606 |
Multiple cross-site scripting (XSS) vulnerabilities in the Backend
component in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0
through 4.6.6, 4.7, and 6.0 allow remote authenticated backend users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1604 |
Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote
attackers to inject arbitrary web script or HTML via the do parameter
to index.php.
|
| CVE-2012-1600 |
Multiple cross-site scripting (XSS) vulnerabilities in functions.php
in phpPgAdmin before 5.0.4 allow remote attackers to inject arbitrary
web script or HTML via the (1) name or (2) type of a function.
|
| CVE-2012-1597 |
Cross-site scripting (XSS) vulnerability in the textEncode function in
classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-1582 |
Cross-site scripting (XSS) vulnerability in the wikitext parser in
MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote
attackers to inject arbitrary web script or HTML via a crafted page
with "forged strip item markers," as demonstrated using the CharInsert
extension.
|
| CVE-2012-1575 |
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before
r5238 allow remote attackers to inject arbitrary web script or HTML
via vectors involving (1) widgets or (2) pages.
|
| CVE-2012-1564 |
Cross-site scripting (XSS) vulnerability in
administration/create_album.php in YVS Image Gallery allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-1561 |
Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x
before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to the "checkbox and radio button
functionalities."
|
| CVE-2012-1556 |
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5
for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to
inject arbitrary web script or HTML via the name parameter to
photo/photo_one.php.
|
| CVE-2012-1512 |
Cross-site scripting (XSS) vulnerability in the internal browser in
vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before
Update 1 allows remote attackers to inject arbitrary web script or
HTML via a crafted log-file entry.
|
| CVE-2012-1511 |
Cross-site scripting (XSS) vulnerability in View Manager Portal in
VMware View before 4.6.1 allows remote attackers to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2012-1507 |
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM
before 2.7 allow remote attackers to inject arbitrary web script or
HTML via the (1) newHspStatus parameter to
plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to
templates/hrfunct/emppop.php, or (3) uri parameter to index.php.
|
| CVE-2012-1503 |
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six
Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject
arbitrary web script or HTML via the comment section.
|
| CVE-2012-1470 |
Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php
in ocPortal before 7.1.6 allow remote attackers to inject arbitrary
web script or HTML via the (1) path or (2) line parameters.
|
| CVE-2012-1469 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Journal
Systems before 2.3.7 allow remote attackers and remote authenticated
users to inject arbitrary web script or HTML via the (1) editor or (2)
callback parameters to
lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in
the iBrowser plugin, (3) authors[][url] parameter to index.php, or (4)
Bio Statement or (5) Abstract of Submission fields to the
stripUnsafeHtml function in lib/pkp/classes/core/String.inc.php.
|
| CVE-2012-1417 |
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone
book and Blacklist form in Yealink VOIP Phones allow remote
authenticated users to inject arbitrary web script or HTML via the
user field to cgi-bin/ConfigManApp.com.
|
| CVE-2012-1413 |
Cross-site scripting (XSS) vulnerability in
zc_install/includes/modules/pages/database_setup/header_php.php in Zen
Cart 1.5.0 and earlier, when the software is being installed, allows
remote attackers to inject arbitrary web script or HTML via the
db_username parameter to zc_install/index.php.
|
| CVE-2012-1410 |
Multiple cross-site scripting (XSS) vulnerabilities in the History
Window implementation in Kadu 0.9.0 through 0.11.0 allow remote
attackers to inject arbitrary web script or HTML via a crafted (1) SMS
message, (2) presence message, or (3) status description.
|
| CVE-2012-1303 |
Multiple cross-site scripting (XSS) vulnerabilities in amCharts Flash
1 allow remote attackers to inject arbitrary web script or HTML via
the (1) data_file or (2) settings_file parameter to ampie.swf; the
message element in the chart_data parameter to (3) amcolumn.swf, (4)
amline.swf, (5) amradar.swf, or (6) amxy.sw; or (7) the settings_file
parameter to amstock.swf.
|
| CVE-2012-1302 |
Multiple cross-site scripting (XSS) vulnerabilities in amMap 2.6.3
allow remote attackers to inject arbitrary web script or HTML via the
(1) data_file or (2) settings_file parameter to ammap.swf, or (3) the
data_file parameter to amtimeline.swf.
|
| CVE-2012-1296 |
Multiple cross-site scripting (XSS) vulnerabilities in
apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2-Beta
and 1.1.x before 1.1.5-Beta allow remote attackers to inject arbitrary
web script or HTML via the (1) title or (2) body parameter to
admin/preview.
|
| CVE-2012-1293 |
Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams'
Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote
attackers to inject arbitrary web script or HTML via the (1) to or (2)
from parameters.
|
| CVE-2012-1290 |
Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp
in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows
remote attackers to inject arbitrary web script or HTML via the
_loadPage parameter.
|
| CVE-2012-1262 |
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi
in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13,
when the product is incompletely installed, allows remote attackers to
inject arbitrary web script or HTML via the dbuser parameter, a
different vulnerability than CVE-2012-0318.
|
| CVE-2012-1254 |
Cross-site scripting (XSS) vulnerability in Segue 2.2.10.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-1253 |
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before
0.7, when Internet Explorer is used, allows remote attackers to inject
arbitrary web script or HTML via vectors involving an embedded image
attachment.
|
| CVE-2012-1252 |
Cross-site scripting (XSS) vulnerability in RSSOwl before 2.1.1 allows
remote attackers to inject arbitrary web script or HTML via a feed, a
different vulnerability than CVE-2006-4760.
|
| CVE-2012-1247 |
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and
earlier, when Internet Explorer is used, allows remote attackers to
inject arbitrary web script or HTML by leveraging support for
Cascading Style Sheets (CSS) expressions.
|
| CVE-2012-1246 |
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and
earlier might allow remote attackers to inject arbitrary web script or
HTML via a crafted cookie.
|
| CVE-2012-1245 |
Cross-site scripting (XSS) vulnerability in the cleanup_urls function
in forum/utils/html.py in OSQA before 1234, and 0.9.0 Beta 3 and
earlier, allows remote attackers to inject arbitrary web script or
HTML via vectors related to a crafted URI.
|
| CVE-2012-1240 |
Cross-site scripting (XSS) vulnerability in the RECRUIT Dokodemo
Rikunabi 2013 extension before 1.0.1 for Google Chrome allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-1224 |
Cross-site scripting (XSS) vulnerability in system/classes/login.php
in ContentLion Alpha 1.3 allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO.
|
| CVE-2012-1219 |
Multiple cross-site scripting (XSS) vulnerabilities in freelancerKit
2.35 allow remote attackers to inject arbitrary web script or HTML via
the (1) ticket parameter to tickets.php, (2) title parameter to
notes.php, or (3) task parameter to todo.php. NOTE: some of these
details are obtained from third party information.
|
| CVE-2012-1217 |
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web
Portal 2.2 allow remote attackers to inject arbitrary web script or
HTML via the team parameter to (1) prospects.php, (2) prospect.php, or
(3) team.php.
|
| CVE-2012-1215 |
Cross-site scripting (XSS) vulnerability in the Add friends module in
the Yoono extension before 7.7.8 for Firefox allows remote attackers
to inject arbitrary web script or HTML via the create field in a
"Create a group" action.
|
| CVE-2012-1214 |
Cross-site scripting (XSS) vulnerability in the Add friends module in
Yoono Desktop Application before 1.8.21 allows remote attackers to
inject arbitrary web script or HTML via the create field in a "Create
a group" action.
|
| CVE-2012-1213 |
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in
Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before
6.0.15 and 7.x before 7.1.3 allows remote attackers to inject
arbitrary web script or HTML via the view parameter.
|
| CVE-2012-1212 |
Cross-site scripting (XSS) vulnerability in the smwfOnSfSetTargetName
function in extensions/SMWHalo/includes/SMW_Initialize.php in Semantic
Enterprise Wiki (SMW+) 1.5.6, 1.6.0_2 and earlier allows remote
attackers to inject arbitrary web script or HTML via the target
parameter to index.php/Special:FormEdit. NOTE: some of these details
are obtained from third party information.
|
| CVE-2012-1211 |
Cross-site scripting (XSS) vulnerability in pfile/kommentar.php in
Powie pFile 1.02 allows remote attackers to inject arbitrary web
script or HTML via the filecat parameter.
|
| CVE-2012-1209 |
Cross-site scripting (XSS) vulnerability in
backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other
versions before 3.2.5 allows remote attackers to inject arbitrary web
script or HTML via the highlight parameter.
|
| CVE-2012-1208 |
Multiple cross-site scripting (XSS) vulnerabilities in
backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other
versions before 3.2.5 allow remote attackers to inject arbitrary web
script or HTML via the (1) report parameter to blog/settings or (2)
error parameter to users/index.
|
| CVE-2012-1190 |
Cross-site scripting (XSS) vulnerability in the replication-setup
functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1
allows user-assisted remote attackers to inject arbitrary web script
or HTML via a crafted database name.
|
| CVE-2012-1188 |
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before
3.2.7 allow remote attackers to inject arbitrary web script or HTML
via the (1) type or (2) querystring parameters to private/en/error or
(3) name parameter to private/en/locale/index.
|
| CVE-2012-1117 |
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-1113 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administration subsystem in Gallery 2 before 2.3.2 and 3 before 3.0.3
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-1110 |
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) user, (2) email, (3) email2, (4) f17_zip, or (5) agree
parameter to join.php; (6) PATH_INFO, (7) st, (8) f17_city, (9)
f17_country, (10) f17_state, (11) f17_zip, (12) f19, (13) wphoto, (14)
search, or (15) v parameter to search.php; (16) PATH_INFO or (17) st
parameter to photo_search.php; or (18) return parameter to
photo_view.php.
|
| CVE-2012-1099 |
Cross-site scripting (XSS) vulnerability in
actionpack/lib/action_view/helpers/form_options_helper.rb in the
select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before
3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject
arbitrary web script or HTML via vectors involving certain generation
of OPTION elements within SELECT elements.
|
| CVE-2012-1098 |
Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before
3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote
attackers to inject arbitrary web script or HTML via vectors involving
a SafeBuffer object that is manipulated through certain methods.
|
| CVE-2012-1087 |
Cross-site scripting (XSS) vulnerability in the Post data records to
facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-1086 |
Cross-site scripting (XSS) vulnerability in the UrlTool (aeurltool)
extension 0.1.0 for TYPO3 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-1084 |
Cross-site scripting (XSS) vulnerability in the BE User Switch
(beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1082 |
Cross-site scripting (XSS) vulnerability in the Terminal PHP Shell
(terminal) extension 0.3.2 and earlier for TYPO3 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-1081 |
Cross-site scripting (XSS) vulnerability in the Yet another Google
search (ya_googlesearch) extension before 0.3.10 for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-1080 |
Cross-site scripting (XSS) vulnerability in the Euro Calculator
(skt_eurocalc) extension 0.0.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1076 |
Cross-site scripting (XSS) vulnerability in the Documents download
(rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1073 |
Cross-site scripting (XSS) vulnerability in the Category-System
(toi_category) extension 0.6.0 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-1070 |
Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq)
extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, possibly related to the "return url parameter."
|
| CVE-2012-1069 |
Cross-site scripting (XSS) vulnerability in module/kb/search_word in
the search module in lknSupport allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2012-1068 |
Cross-site scripting (XSS) vulnerability in the rc_ajax function in
core.php in the WP-RecentComments plugin before 2.0.7 for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
page parameter, related to AJAX paging.
|
| CVE-2012-1066 |
Cross-site scripting (XSS) vulnerability in the template module in
SmartyCMS 0.9.4 allows remote attackers to inject arbitrary web script
or HTML via the title bar.
|
| CVE-2012-1064 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer
SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-1062 |
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine
Applications Manager 9.x and 10.x allow remote attackers to inject
arbitrary web script or HTML via the (1) period parameter to
showHistoryData.do; (2) selectedNetwork, (3) network, or (4) group
parameters to showresource.do; (5) header parameter to AlarmView.do;
or (6) attName parameter to jsp/PopUp_Graph.jsp. NOTE: the
Search.do/query vector is already covered by CVE-2008-1566, and the
jsp/ThresholdActionConfiguration.jsp redirectto vector is already
covered by CVE-2008-0474.
|
| CVE-2012-1060 |
Multiple cross-site scripting (XSS) vulnerabilities in
revisioning_theme.inc in the Taxonomy module in the Revisioning module
6.x-3.13 and other versions before 6.x-3.14 for Drupal allow remote
authenticated users with certain privileges to inject arbitrary web
script or HTML via the (1) tags or (2) term parameters.
|
| CVE-2012-1059 |
Cross-site scripting (XSS) vulnerability in
osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in
OSCommerce Online Merchant 3.0.2 allows remote attackers to inject
arbitrary web script or HTML via the value_title parameter, as
demonstrated using the "Front" field in the shirt module.
|
| CVE-2012-1049 |
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine
ADManager Plus 5.2 Build 5210 allow remote attackers to inject
arbitrary web script or HTML via the (1) domainName parameter to
jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.
|
| CVE-2012-1048 |
Cross-site scripting (XSS) vulnerability in
communityplusplus/www/administrator.php in eFront Community++ edition
3.6.10, and possibly other editions, allows remote attackers to inject
arbitrary web script or HTML via the filter parameter.
|
| CVE-2012-1046 |
Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1
9.5.2 FP1 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, a different vulnerability than
CVE-2012-0696.
|
| CVE-2012-1039 |
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before
2.4.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) login_data parameter to admin/auth.php; (2) nb parameter
to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status
parameters to admin/comments.php; or (7) page parameter to
admin/plugin.php.
|
| CVE-2012-1038 |
Cross-site scripting (XSS) vulnerability in the WebAAA login
functionality (wba_login.html) in Juniper Networks Mobility System
Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before
7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote
attackers to inject arbitrary web script or HTML via a crafted
parameter name.
|
| CVE-2012-1036 |
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in
DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers
to inject arbitrary web script or HTML via a message.
|
| CVE-2012-1034 |
Multiple cross-site scripting (XSS) vulnerabilities in the admin
interface in EPiServer CMS through 6R2 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1032 |
Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker
module 3.x before 3.4.5 for EPiServer allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2012-1030 |
Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through
6.0.2 allows user-assisted remote attackers to inject arbitrary web
script or HTML via a crafted URL containing text that is used within a
modal popup.
|
| CVE-2012-1028 |
Cross-site scripting (XSS) vulnerability in bin/index.php in
SimpleGroupware 0.742 and other versions before 0.743 allows remote
attackers to inject arbitrary web script or HTML via the export
parameter.
|
| CVE-2012-1027 |
Cross-site scripting (XSS) vulnerability in account-closed.tcl in
]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other
versions allows remote attackers to inject arbitrary web script or
HTML via the message parameter to register/account-closed.
|
| CVE-2012-1021 |
Cross-site scripting (XSS) vulnerability in admin/categories.php in
4images 1.7.10 allows remote attackers to inject arbitrary web script
or HTML via the cat_parent_id parameter in an addcat action.
|
| CVE-2012-1020 |
Multiple cross-site scripting (XSS) vulnerabilities in login.php in
NexorONE Online Banking allow remote attackers to inject arbitrary web
script or HTML via the (1) visitor_language parameter to register.php
or (2) message parameter.
|
| CVE-2012-1019 |
Multiple cross-site scripting (XSS) vulnerabilities in XWiki
Enterprise 3.4 allow remote attackers to inject arbitrary web script
or HTML via the (1) XWiki.XWikiComments_comment parameter to
xwiki/bin/commentadd/Main/WebHome, (2) XWiki.XWikiUsers_0_company
parameter when editing a user profile, or (3) projectVersion parameter
to xwiki/bin/view/DownloadCode/DownloadFeedback. NOTE: some of these
details are obtained from third party information.
|
| CVE-2012-1018 |
Cross-site scripting (XSS) vulnerability in includes/convert.php in
D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0
for Joomla! allows remote attackers to inject arbitrary web script or
HTML via the from parameter.
|
| CVE-2012-1007 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts
1.3.10 allow remote attackers to inject arbitrary web script or HTML
via (1) the name parameter to struts-examples/upload/upload-submit.do,
or the message parameter to (2) struts-cookbook/processSimple.do or
(3) struts-cookbook/processDyna.do.
|
| CVE-2012-1006 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts
2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script
or HTML via the (1) name or (2) lastName parameter to
struts2-showcase/person/editPerson.action, or the (3) clientName
parameter to struts2-rest-showcase/orders.
|
| CVE-2012-1005 |
Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software
Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary
web script or HTML via the comment parameter to a blog, as
demonstrated using (1) Blog/MyFirstBlog.txt or (2)
Blog/AboutSomething.txt.
|
| CVE-2012-1004 |
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm
in Foswiki before 1.1.5 allow remote authenticated users with CHANGE
privileges to inject arbitrary web script or HTML via the (1) text,
(2) FirstName, (3) LastName, (4) OrganisationName, (5)
OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address,
(10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM,
(14) Email, (15) HomePage, or (16) Comment parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2012-1000 |
Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3
and other versions before 1.1.4 allow remote attackers to inject
arbitrary web script or HTML via the (1) message parameter to
admins/login/forgot/index.php, or the (2) display_name or (3) email
parameter to account/preferences.php.
|
| CVE-2012-0995 |
Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) msg parameter in an external action to zp-core/admin.php, (2)
PATH_INTO to an unspecified URL, as demonstrated using /1/, (3)
PATH_INFO to zp-core/admin.php, or (4) album parameter to
zp-core/admin-edit.php.
|
| CVE-2012-0989 |
Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial
Edition build231211 and possibly earlier allows remote attackers to
inject arbitrary web script or HTML via the PATH_INFO to index.php.
|
| CVE-2012-0988 |
Multiple cross-site scripting (XSS) vulnerabilities in
config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier
allow remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to (1) login.php, (2) admin.php, or (3) preferences.php.
|
| CVE-2012-0986 |
Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS
1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote
attackers to inject arbitrary web script or HTML via the PATH_INFO to
(1) notifications.php, (2) modules/system/admin/images/browser.php,
and (3) modules/content/admin/content.php.
|
| CVE-2012-0984 |
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before
2.5.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) to_userid parameter to modules/pm/pmlite.php or the (2)
current_file, (3) imgcat_id, or (4) target parameter to
class/xoopseditor/tinymce/tinymce/jscripts/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php.
|
| CVE-2012-0979 |
Cross-site scripting (XSS) vulnerability in TWiki allows remote
attackers to inject arbitrary web script or HTML via the organization
field in a profile, involving (1) registration or (2) editing of the
user.
|
| CVE-2012-0976 |
Cross-site scripting (XSS) vulnerability in admin/EditForm in
SilverStripe 2.4.6 allows remote authenticated users with Content
Authors privileges to inject arbitrary web script or HTML via the
Title parameter. NOTE: some of these details are obtained from third
party information.
|
| CVE-2012-0975 |
Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting
Script DPI 1.0, 1.3, and earlier allows remote attackers to inject
arbitrary web script or HTML via the showseries parameter.
|
| CVE-2012-0974 |
Multiple cross-site scripting (XSS) vulnerabilities in the getParam
function in oc-includes/osclass/core/Params.php in OSClass before
2.3.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin
parameters in a search action to index.php.
|
| CVE-2012-0936 |
Cross-site scripting (XSS) vulnerability in
web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java
in OpenNMS 1.8.x before 1.8.17, 1.9.93 and earlier, and 1.10.x before
1.10.1 allows remote attackers to inject arbitrary web script or HTML
via the Username field, related to login.
|
| CVE-2012-0933 |
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS
3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to
inject arbitrary web script or HTML via the PATH_INFO to (1)
admin_colors.asp, (2) admin_config.asp, and (3) admin_cat_add.asp in
admin/.
|
| CVE-2012-0932 |
Cross-site scripting (XSS) vulnerability in admin/login.php in Lead
Capture Page System allows remote attackers to inject arbitrary web
script or HTML via the message parameter.
|
| CVE-2012-0930 |
Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon
Quantum PLC allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-0919 |
Cross-site scripting (XSS) vulnerability in Hitachi IT Operations
Director 02-50-01 through 02-50-07, 03-00 through 03-00-04, and
possibly other versions before 03-00-06, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0917 |
Cross-site scripting (XSS) vulnerability in Hitachi IT Operations
Analyzer 02-01, 02-51 through 02-51-01, and 02-53 through 02-53-02
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-0914 |
Cross-site scripting (XSS) vulnerability in
display_renderers/panels_renderer_editor.class.php in the admin view
in the Panels module 6.x-2.x before 6.x-3.10 and 7.x-3.x before
7.x-3.0 for Drupal allows remote authenticated users with certain
privileges to inject arbitrary web script or HTML via the Region
title.
|
| CVE-2012-0909 |
Cross-site scripting (XSS) vulnerability in Horde_Form in Horde
Groupware Webmail Edition before 4.0.6 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, related
to email verification. NOTE: Some of these details are obtained from
third party information.
|
| CVE-2012-0908 |
Cross-site scripting (XSS) vulnerability in logout.php in
SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows
remote attackers to inject arbitrary web script or HTML via the
link_href parameter.
|
| CVE-2012-0903 |
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop
7.1.2 b10978 allow remote attackers to inject arbitrary web script or
HTML via the (1) Username or (2) MailBox Name.
|
| CVE-2012-0901 |
Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo
auto-publishing plugin 1.0 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the submit parameter.
|
| CVE-2012-0900 |
Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum
1.0.1 allow remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.
|
| CVE-2012-0899 |
Cross-site scripting (XSS) vulnerability in
referencement/sites_inscription.php in Annuaire PHP allows remote
attackers to inject arbitrary web script or HTML via the url parameter
and possibly the nom parameter.
|
| CVE-2012-0895 |
Cross-site scripting (XSS) vulnerability in map/map.php in the Count
Per Day module before 3.1.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the map parameter.
|
| CVE-2012-0891 |
Multiple cross-site scripting (XSS) vulnerabilities in Puppet
Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5 and 2.x
before 2.0.1 allow remote attackers to inject arbitrary web script or
HTML via unspecified fields.
|
| CVE-2012-0873 |
Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin
before 7.0.8 allow remote attackers to inject arbitrary web script or
HTML via the (1) explain parameter to explanation.php or the (2)
photos_only, (3) online_only, or (4) mode parameters to
viewFriends.php.
|
| CVE-2012-0872 |
Multiple cross-site scripting (XSS) vulnerabilities in OxWall 1.1.1
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) captchaField, (2) email, (3) form_name, (4) password,
(5) realname, (6) repeatPassword, or (7) username parameters to
Oxwall/join; (8) captcha, (9) email, (10) form_name, (11) from, or
(12) subject parameters to Oxwall/contact; (13) tag parameter to
Oxwall/blogs/browse-by-tag; or (14) PATH_INFO to
Oxwall/photo/viewlist/tagged, (15) Oxwall/photo/viewlist, or (16)
Oxwall/video/viewlist.
|
| CVE-2012-0869 |
Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File
EXchange (F*EX, aka fex) before 20120215 allows remote attackers to
inject arbitrary web script or HTML via the id parameter.
|
| CVE-2012-0846 |
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar
1.2.4 allows remote attackers to inject arbitrary web script or HTML
via the Location variable.
|
| CVE-2012-0834 |
Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in
phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the base parameter in a query_engine
action to cmd.php.
|
| CVE-2012-0829 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew
Messenger 1.6.4 and earlier allow remote attackers to hijack the
authentication of operators for requests that insert cross-site
scripting (XSS) sequences via the (1) address or (2) threadid
parameters to operator/ban.php; or (3) geolinkparams, (4) title, or
(5) chattitle parameters to operator/settings.php.
|
| CVE-2012-0822 |
Cross-site scripting (XSS) vulnerability in Joomla! 1.6 and 1.7.x
before 1.7.4 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, a different vulnerability than
CVE-2012-0820.
|
| CVE-2012-0820 |
Cross-site scripting (XSS) vulnerability in Joomla! 1.6.x and 1.7.x
before 1.7.4 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, a different vulnerability than
CVE-2012-0822.
|
| CVE-2012-0811 |
Multiple SQL injection vulnerabilities in Postfix Admin (aka
postfixadmin) before 2.3.5 allow remote authenticated users to execute
arbitrary SQL commands via (1) the pw parameter to the pacrypt
function, when mysql_encrypt is configured, or (2) unspecified vectors
that are used in backup files generated by backup.php.
|
| CVE-2012-0791 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP
before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow
remote attackers to inject arbitrary web script or HTML via the (1)
composeCache, (2) rtemode, or (3) filename_* parameters to the compose
page; (4) formname parameter to the contacts popup window; or (5) IMAP
mailbox names. NOTE: some of these details are obtained from third
party information.
|
| CVE-2012-0790 |
Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping
2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers
to inject arbitrary web script or HTML via the displaymode parameter.
|
| CVE-2012-0782 |
** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in
wp-admin/setup-config.php in the installation component in WordPress
3.3.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter.
NOTE: the vendor disputes the significance of this issue; also, it is
unclear whether this specific XSS scenario has security relevance.
|
| CVE-2012-0767 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before
10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux,
and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before
11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, aka "Universal XSS
(UXSS)," as exploited in the wild in February 2012.
|
| CVE-2012-0765 |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp
8 and 9 for Word allow remote attackers to inject arbitrary web script
or HTML via a crafted URL, related to certain .htm files in (1)
template_stock and (2) template_csh directories.
|
| CVE-2012-0746 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset
Management for IT, Tivoli Service Request Manager, Maximo Service
Desk, and Change and Configuration Management Database (CCMDB), allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-0740 |
Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM
Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before
6.3.0.11 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-0737 |
Cross-site scripting (XSS) vulnerability in IBM Rational AppScan
Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0720 |
Cross-site scripting (XSS) vulnerability in the Integration Solution
Console in the Administration Console in IBM WebSphere Application
Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary
web script or HTML via a crafted URL.
|
| CVE-2012-0719 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint
Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject
arbitrary web script or HTML via the ScheduleParam parameter to the
webreports program.
|
| CVE-2012-0716 |
Cross-site scripting (XSS) vulnerability in the Administration Console
in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-0715 |
Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in
IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1
and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-0707 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi
Edition 7.2 allows remote attackers to inject arbitrary web script or
HTML via crafted text input to a coach that is configured with a
document attachment control section.
|
| CVE-2012-0696 |
Multiple cross-site scripting (XSS) vulnerabilities in the Executive
Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to
inject arbitrary web script or HTML via unspecified requests to (1)
aspnet_client or (2) evserver/createcontrol.js.
|
| CVE-2012-0688 |
Cross-site scripting (XSS) vulnerability in TIBCO ActiveMatrix
Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution
3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks
Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-0678 |
Cross-site scripting (XSS) vulnerability in Apple Safari before 6.0
allows remote attackers to inject arbitrary web script or HTML via a
feed:// URL.
|
| CVE-2012-0590 |
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple
iOS before 5.1, allows user-assisted remote attackers to inject
arbitrary web script or HTML via vectors involving a drag-and-drop
operation.
|
| CVE-2012-0589 |
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple
iOS before 5.1, allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2012-0586, CVE-2012-0587, and CVE-2012-0588.
|
| CVE-2012-0588 |
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple
iOS before 5.1, allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2012-0586, CVE-2012-0587, and CVE-2012-0589.
|
| CVE-2012-0587 |
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple
iOS before 5.1, allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2012-0586, CVE-2012-0588, and CVE-2012-0589.
|
| CVE-2012-0586 |
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple
iOS before 5.1, allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2012-0587, CVE-2012-0588, and CVE-2012-0589.
|
| CVE-2012-0477 |
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox
4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0
through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before
2.9 allow remote attackers to inject arbitrary web script or HTML via
the (1) ISO-2022-KR or (2) ISO-2022-CN character set.
|
| CVE-2012-0474 |
Cross-site scripting (XSS) vulnerability in the docshell
implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x
before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x
before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to
inject arbitrary web script or HTML via vectors related to
short-circuited page loads, aka "Universal XSS (UXSS)."
|
| CVE-2012-0471 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x
through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through
11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9
allows remote attackers to inject arbitrary web script or HTML via a
multibyte character set.
|
| CVE-2012-0466 |
template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before
3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1
does not properly handle multiple logins, which allows remote
attackers to conduct cross-site scripting (XSS) attacks and obtain
sensitive bug information via a crafted web page.
|
| CVE-2012-0458 |
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x
before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0,
Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not
properly restrict setting the home page through the dragging of a URL
to the home button, which allows user-assisted remote attackers to
execute arbitrary JavaScript code with chrome privileges via a
javascript: URL that is later interpreted in the about:sessionrestore
context.
|
| CVE-2012-0455 |
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x
before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0,
Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not
properly restrict drag-and-drop operations on javascript: URLs, which
allows user-assisted remote attackers to conduct cross-site scripting
(XSS) attacks via a crafted web page, related to a
"DragAndDropJacking" issue.
|
| CVE-2012-0451 |
CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0,
Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0,
Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows
remote web servers to bypass intended Content Security Policy (CSP)
restrictions and possibly conduct cross-site scripting (XSS) attacks
via crafted HTTP headers.
|
| CVE-2012-0446 |
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox
4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7
allow remote attackers to inject arbitrary web script or HTML via a
(1) web page or (2) Firefox extension, related to improper enforcement
of XPConnect security restrictions for frame scripts that call
untrusted objects.
|
| CVE-2012-0428 |
Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x
before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0414 |
Cross-site scripting (XSS) vulnerability in the Spacewalk service in
SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11 SP1 allows remote
attackers to inject arbitrary web script or HTML via an image name.
|
| CVE-2012-0404 |
Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom
before 7.4.4 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-0399 |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA
enVision 4.x before 4.1 Patch 4 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0389 |
Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in
MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x
before 5.53, and 6.x before 6.03 allows remote attackers to inject
arbitrary web script or HTML via the Username parameter.
|
| CVE-2012-0340 |
Cross-site scripting (XSS) vulnerability in the management interface
on the Cisco IronPort Encryption Appliance with software before 6.5.3
allows remote attackers to inject arbitrary web script or HTML via
the header parameter to the default URI under admin/, aka bug ID
72410.
|
| CVE-2012-0327 |
Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-0325 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454,
Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before
1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, a
different vulnerability than CVE-2012-0324.
|
| CVE-2012-0324 |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454,
Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before
1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, a
different vulnerability than CVE-2012-0325.
|
| CVE-2012-0323 |
Cross-site scripting (XSS) vulnerability in the Autocomplete plugin
before 3.0 for SquirrelMail allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0318 |
Multiple cross-site scripting (XSS) vulnerabilities in Movable Type
before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote
attackers to inject arbitrary web script or HTML via vectors involving
templates, a different issue than CVE-2012-1262.
|
| CVE-2012-0313 |
Cross-site scripting (XSS) vulnerability in glucose 2 before stage 6.2
allows remote attackers to inject arbitrary web script or HTML via an
RSS feed.
|
| CVE-2012-0312 |
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before
R9, and osCommerce Online Merchant before 2.3.1, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-0311 |
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before
R9 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-0309 |
Cross-site scripting (XSS) vulnerability in Cogent DataHub 7.1.2 and
earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20
and earlier allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-0307 |
Multiple cross-site scripting (XSS) vulnerabilities in Symantec
Messaging Gateway (SMG) before 10.0 allow remote attackers to inject
arbitrary web script or HTML via (1) web content or (2) e-mail
content.
|
| CVE-2012-0302 |
Cross-site scripting (XSS) vulnerability in Brightmail Control Center
in Symantec Message Filter 6.3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0296 |
Multiple cross-site scripting (XSS) vulnerabilities in the management
GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0287 |
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in
WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows
remote attackers to inject arbitrary web script or HTML via the query
string in a POST operation that is not properly handled by the
"Duplicate comment detected" feature.
|
| CVE-2012-0285 |
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware
webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-0283 |
Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList
function in inc/template.php in DokuWiki before 2012-01-25b allows
remote attackers to inject arbitrary web script or HTML via the ns
parameter in a medialist action to lib/exe/ajax.php.
|
| CVE-2012-0272 |
Cross-site scripting (XSS) vulnerability in the WebAccess component in
Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to
inject arbitrary web script or HTML via the merge parameter.
|
| CVE-2012-0253 |
Multiple cross-site scripting (XSS) vulnerabilities in Demand Media
Pluck SiteLife before 5.0.13 allow remote attackers to inject
arbitrary web script or HTML via (1) the jsonRequest parameter to
Direct/Process, the (2) r or (3) cb parameter to Direct/jsonp.htm, or
(4) the cb parameter to sys/jsonp.app/.htm.
|
| CVE-2012-0233 |
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin
WebAccess before 7.0 allows remote attackers to inject arbitrary web
script or HTML via a malformed URL.
|
| CVE-2012-0225 |
Cross-site scripting (XSS) vulnerability in Invensys Wonderware
Information Server 4.0 SP1 and 4.5 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0220 |
Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin
(Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers
to inject arbitrary web script or HTML via the (1) author or (2)
authorurl meta tags.
|
| CVE-2012-0216 |
The default configuration of the apache2 package in Debian GNU/Linux
squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid
before 2.2.22-4, when mod_php or mod_rivet is used, provides example
scripts under the doc/ URI, which might allow local users to conduct
cross-site scripting (XSS) attacks, gain privileges, or obtain
sensitive information via vectors involving localhost HTTP requests to
the Apache HTTP Server.
|
| CVE-2012-0203 |
Cross-site scripting (XSS) vulnerability in InfoSphere Metadata
Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server
8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-0195 |
Cross-site scripting (XSS) vulnerability in the Start Center Layout
and Configuration component in IBM Maximo Asset Management and Asset
Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management
for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and
7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and
Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows
remote attackers to inject arbitrary web script or HTML via the
display name.
|
| CVE-2012-0145 |
Cross-site scripting (XSS) vulnerability in wizardlist.aspx in
Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint
Foundation 2010 Gold and SP1 allows remote attackers to inject
arbitrary web script or HTML via JavaScript sequences in a URL, aka
"XSS in wizardlist.aspx Vulnerability."
|
| CVE-2012-0144 |
Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft
Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation
2010 Gold and SP1 allows remote attackers to inject arbitrary web
script or HTML via JavaScript sequences in a URL, aka "XSS in
themeweb.aspx Vulnerability."
|
| CVE-2012-0132 |
Cross-site scripting (XSS) vulnerability in HP Business Availability
Center (BAC) 9.01 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-0047 |
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before
1.4.20 allows remote attackers to inject arbitrary web script or HTML
via the wicket:pageMapName parameter.
|
| CVE-2012-0040 |
Cross-site scripting (XSS) vulnerability in
modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly
other versions before 1.8.2 allows remote attackers to inject
arbitrary web script or HTML via the retryURL parameter.
|
| CVE-2012-0017 |
Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft
SharePoint Foundation 2010 Gold and SP1 allows remote attackers to
inject arbitrary web script or HTML via JavaScript sequences in a URL,
aka "XSS in inplview.aspx Vulnerability."
|
| CVE-2012-0007 |
The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0
does not properly evaluate characters after the detection of a
Cascading Style Sheets (CSS) escaped character, which allows remote
attackers to conduct cross-site scripting (XSS) attacks via HTML
input, aka "AntiXSS Library Bypass Vulnerability."
|
| CVE-2011-5317 |
Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS
before 0.4 allows remote attackers to inject arbitrary web script or
HTML via the content parameter.
|
| CVE-2011-5312 |
Multiple cross-site scripting (XSS) vulnerabilities in Gollos 2.8
allow remote attackers to inject arbitrary web script or HTML via the
returnurl parameter to (1) register.aspx, (2) publication/info.aspx,
or (3) user/add.aspx, or (4) the q parameter to product/list.aspx.
|
| CVE-2011-5309 |
Cross-site scripting (XSS) vulnerability in pages.php in Wikipad 1.6.0
allows remote attackers to inject arbitrary web script or HTML via the
id parameter.
|
| CVE-2011-5307 |
Cross-site scripting (XSS) vulnerability in index.php in the
PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the action parameter.
|
| CVE-2011-5305 |
Multiple cross-site scripting (XSS) vulnerabilities in CosmoShop ePRO
10.05.00 allow remote attackers to inject arbitrary web script or HTML
via (1) the rcopy parameter to cgi-bin/admin/rubrikadmin.cgi, (2) the
typ parameter to cgi-bin/admin/artikeladmin.cgi, or (3) the
suchbegriff parameter to cgi-bin/admin/shophilfe_suche.cgi.
|
| CVE-2011-5304 |
Multiple cross-site scripting (XSS) vulnerabilities in the Sodahead
Polls plugin before 2.0.4 for WordPress allow remote attackers to
inject arbitrary web script or HTML via (1) the poll_id parameter to
customizer.php or (2) the customize parameter to poll.php.
|
| CVE-2011-5303 |
Cross-site scripting (XSS) vulnerability in Spitfire CMS 1.0.436
allows remote attackers to inject arbitrary web script or HTML via a
cms_username cookie.
|
| CVE-2011-5301 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0
allow remote attackers to inject arbitrary web script or HTML via (1)
the story_url parameter to add_story.php, (2) the email parameter to
editprofile.php, (3) the title parameter to adm/content_add.php, or
(4) the username parameter to adm/admin_edit.php.
|
| CVE-2011-5299 |
Multiple cross-site scripting (XSS) vulnerabilities in poMMo Aardvark
PR16.1 allow remote attackers to inject arbitrary web script or HTML
via (1) the referer parameter to index.php, (2) the site_name
parameter to admin/setup/config/general.php, (3) the group_name
parameter to admin/subscribers/subscribers_groups.php, or (4) the
field_name parameter to admin/setup/setup_fields.php.
|
| CVE-2011-5297 |
Multiple cross-site scripting (XSS) vulnerabilities in TTChat 1.0.4
allow remote attackers to inject arbitrary web script or HTML via (1)
the msg parameter to default.php or (2) the username parameter to
chat_form.php.
|
| CVE-2011-5296 |
Cross-site scripting (XSS) vulnerability in profilo.php in Happy Chat
1.0 allows remote attackers to inject arbitrary web script or HTML via
the nick parameter.
|
| CVE-2011-5287 |
Multiple cross-site scripting (XSS) vulnerabilities in HESK before
2.4.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) hesk_settings[tmp_title] or (2) hesklang[ENCODING]
parameter to inc/header.inc.php; the hesklang[attempt] parameter to
(3) inc/assignment_search.inc.php, (4) inc/attachments.inc.php, (5)
inc/common.inc.php, (6) inc/database.inc.php, (7)
inc/prepare_ticket_search.inc.php, (8) inc/print_tickets.inc.php, (9)
inc/show_admin_nav.inc.php, (10) inc/show_search_form.inc.php, or (11)
inc/ticket_list.inc.php; or (12) the PATH_INFO to
language/en/text.php.
|
| CVE-2011-5285 |
Multiple cross-site scripting (XSS) vulnerabilities in BugFree 2.1.3
allow remote attackers to inject arbitrary web script or HTML via (1)
the ActionType parameter to Bug.php, the ReportMode parameter to (2)
Report.php or (3) ReportLeft.php, or the PATH_INFO to (4)
AdminProjectList.php, (5) AdminGroupList.php, or (6)
AdminUserLogList.php.
|
| CVE-2011-5283 |
Cross-site scripting (XSS) vulnerability in the web management
interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and
3.0 SP3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the IP parameter in a Run action.
|
| CVE-2011-5269 |
Cross-site scripting (XSS) vulnerability in ProjectForge before 3.5.3
allows remote authenticated users to inject arbitrary web script or
HTML via a validation message.
|
| CVE-2011-5267 |
Multiple cross-site scripting (XSS) vulnerabilities in
spell-check-savedicts.php in the SpellChecker module in Xinha, as used
in WikiWig 5.01 and possibly other products, allow remote attackers to
inject arbitrary web script or HTML via the (1) to_p_dict or (2)
to_r_list parameter. NOTE: this issue might be related to the htmlarea
plugin and CVE-2013-5670.
|
| CVE-2011-5265 |
Cross-site scripting (XSS) vulnerability in cached_image.php in the
Featurific For WordPress plugin 1.6.2 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the snum
parameter. NOTE: this has been disputed by a third party.
|
| CVE-2011-5264 |
Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the
Lazyest Backup plugin before 0.2.2 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the xml_or_all
parameter.
|
| CVE-2011-5263 |
Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in
SAP NetWeaver 7.30 and earlier allows remote attackers to inject
arbitrary web script or HTML via the server parameter.
|
| CVE-2011-5261 |
Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis
M10 Series Network Cameras M1054 firmware 5.21 and earlier allows
remote attackers to inject arbitrary web script or HTML via the
pageTitle parameter to admin/showReport.shtml.
|
| CVE-2011-5260 |
Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP
NetWeaver allows remote attackers to inject arbitrary web script or
HTML via the page parameter.
|
| CVE-2011-5258 |
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM
before 2.6.11.2 allow remote attackers to inject arbitrary web script
or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or
the (3) PATH_INFO to lib/controllers/centralcontroller.php.
|
| CVE-2011-5257 |
Multiple cross-site scripting (XSS) vulnerabilities in the Classipress
theme before 3.1.5 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) twitter_id parameter related
to the Twitter widget and (2) facebook_id parameter related to the
Facebook widget.
|
| CVE-2011-5256 |
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey
before 1.91+ Build 11379-20111116, when viewing survey results, allows
remote attackers to inject arbitrary web script or HTML via unknown
parameters.
|
| CVE-2011-5255 |
Multiple cross-site scripting (XSS) vulnerabilities in admin/login in
X3 CMS 0.4.3.1 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) PATH_INFO, (2) username, or (3)
password parameter.
|
| CVE-2011-5249 |
Cross-site scripting (XSS) vulnerability in the events page in the
System iNtrusion Analysis and Reporting Environment (SNARE) for Linux
agent before 1.7.0 allows remote attackers to inject arbitrary web
script or HTML via a logged shell command.
|
| CVE-2011-5228 |
Cross-site scripting (XSS) vulnerability in the Search module
(quickstart/search) in appRain CMF 0.1.5 allows remote attackers to
inject arbitrary web script or HTML via the ss parameter.
|
| CVE-2011-5225 |
Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in
the Sentinel plugin 1.0.0 for WordPress allows remote attackers to
inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2011-5221 |
Cross-site scripting (XSS) vulnerability in the getLog function in
svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject
arbitrary web script or HTML via the path parameter to (1) comp.php,
(2) diff.php, or (3) revision.php.
|
| CVE-2011-5220 |
Cross-site scripting (XSS) vulnerability in
templates/default/Admin/Login.html in PHP-SCMS 1.6.8 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
lang parameter to index.php.
|
| CVE-2011-5214 |
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM
5.100.01 and earlier allow remote attackers to inject arbitrary web
script or HTML via the PATH_INFO to (1) index.php, (2)
modules/admin/admin_module_index.php, or (3)
modules/calendar/customise_calendar_times.php; login[] parameter to
(4) index.php or (5) pub/clients.php; or framed parameter to (6)
licence/index.php or (7) licence/view.php.
|
| CVE-2011-5211 |
Cross-site scripting (XSS) vulnerability in the poll module in Subrion
CMS 2.0.4 allows remote attackers to inject arbitrary web script or
HTML via the title field. NOTE: some of these details are obtained
from third party information. NOTE: this might overlap CVE-2012-5452.
|
| CVE-2011-5209 |
Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone
Script, possibly 1.11, allows remote attackers to inject arbitrary web
script or HTML via the term parameter.
|
| CVE-2011-5207 |
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php
in the TheCartPress plugin for WordPress before 1.1.6 before
2011-12-31 allows remote attackers to inject arbitrary web script or
HTML via the tcp_name_post_XXXXX parameter.
|
| CVE-2011-5206 |
Cross-site scripting (XSS) vulnerability in notes.php in Rapidleech
before 2.3 rev42 SVN r399 allows remote attackers to inject arbitrary
web script or HTML via the notes parameter.
|
| CVE-2011-5205 |
Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3
rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to
inject arbitrary web script or HTML via the links parameter.
|
| CVE-2011-5201 |
Multiple SQL injection vulnerabilities in sign.php in tinyguestbook
allow remote attackers to execute arbitrary SQL commands via the (1)
name and (2) msg parameters. NOTE: some of these details are obtained
from third party information.
|
| CVE-2011-5199 |
Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook
allows remote attackers to inject arbitrary web script or HTML via the
msg parameter.
|
| CVE-2011-5194 |
Cross-site scripting (XSS) vulnerability in
vendors/samswhois/samswhois.inc.php in the Whois Search plugin before
1.4.2.3 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the domain parameter, a different vulnerability
than CVE-2011-5193.
|
| CVE-2011-5193 |
Cross-site scripting (XSS) vulnerability in
vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3
for WordPress, when the WHOIS widget is enabled, allows remote
attackers to inject arbitrary web script or HTML via the domain
parameter to index.php, a different vulnerability than CVE-2011-5194.
|
| CVE-2011-5192 |
Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty
Link Lite plugin before 1.5.6 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the slug parameter, a
different vulnerability than CVE-2011-5191.
|
| CVE-2011-5191 |
Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty
Link Lite plugin before 1.5.4 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the slug parameter, a
different vulnerability than CVE-2011-5192.
|
| CVE-2011-5190 |
Multiple cross-site scripting (XSS) vulnerabilities in Social Book
Facebook Clone 2010 allow remote attackers to inject arbitrary web
script or HTML via the PATH_INFO parameter to (1) signup.php, (2)
lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6)
help_contact.php, or (7) help.php.
|
| CVE-2011-5189 |
Cross-site scripting (XSS) vulnerability in the Webform Validation
module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal
allows remote authenticated users with permissions to "update Webform
nodes" to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-5188 |
Cross-site scripting (XSS) vulnerability in the Support Timer module
6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users
with the "track time spent" permission to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2011-5187 |
Cross-site scripting (XSS) vulnerability in the Support Ticketing
System module 6.x-1.x before 6.x-1.7 for Drupal allows remote
authenticated users with the "administer support projects" permission
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-5186 |
Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop
plugin for e107 7 allows remote attackers to inject arbitrary web
script or HTML via the item_id parameter.
|
| CVE-2011-5185 |
Cross-site scripting (XSS) vulnerability in video_comments.php in
Online Subtitles Workshop before 2.0 rev 131 allows remote attackers
to inject arbitrary web script or HTML via the comment parameter.
|
| CVE-2011-5184 |
Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node
Manager i 9.10 allow remote attackers to inject arbitrary web script
or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename
parameter to nnm/protected/configurationpoll.jsp, (3)
nnm/protected/ping.jsp, (4) nnm/protected/statuspoll.jsp, or (5)
nnm/protected/traceroute.jsp; or (6) field parameter to nmm/validate.
NOTE: this might be a duplicate of CVE-2011-4155 or CVE-2011-4156.
|
| CVE-2011-5182 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in
lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the action parameter. NOTE: the vendor disputes this issue,
stating "Lanoba's plug in does sanitize user input, and because that
input is never sent to the browser, an attacker has no way of
executing script or code on a user's behalf."
|
| CVE-2011-5181 |
Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk
Live Support - Live Chat plugin 2.0 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the cdwidgetid
parameter. NOTE: some of these details are obtained from third party
information.
|
| CVE-2011-5180 |
Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in
the ZooEffect plugin 1.01 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the page parameter. NOTE:
some of these details are obtained from third party information.
NOTE: this has been disputed by a third party.
|
| CVE-2011-5179 |
Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php
in Skysa App Bar Integration plugin, possibly before 1.04, for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the submit parameter.
|
| CVE-2011-5178 |
Multiple cross-site scripting (XSS) vulnerabilities in
netmri/config/userAdmin/login.tdf in Infoblox NetMRI 6.0.2.42, 6.1.2,
6.2.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) eulaAccepted or (2) mode parameter.
|
| CVE-2011-5177 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to
inject arbitrary web script or HTML via the (1) id parameter to the
admins (2) blocks, (3) articles, or (4) suggest-category; or (5) sort
parameter to the search page.
|
| CVE-2011-5176 |
Multiple cross-site scripting (XSS) vulnerabilities in search.php in
Banana Dance, possibly B.1.5 and earlier, allow remote attackers to
inject arbitrary web script or HTML via the (1) q or (2) category
parameter.
|
| CVE-2011-5160 |
Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4
allows remote attackers to inject arbitrary web script or HTML via the
site parameter.
|
| CVE-2011-5159 |
Cross-site scripting (XSS) vulnerability in admin/configuration.php in
Geeklog before 1.7.1sr1 allows remote attackers to inject arbitrary
web script or HTML via the sub_group parameter, a different
vulnerability than CVE-2011-4942.
|
| CVE-2011-5150 |
Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.07
and possibly earlier allow remote attackers or authenticated users to
inject arbitrary web script or HTML via the (1) ipaddress or (2)
domain parameter to setup-network.php, different vectors than
CVE-2011-5149. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2011-5149 |
Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) testaddr or (2) testpass parameter to
auth-settings.php; (3) hostname, (4) domainname, or (5) mailserver
parameter to setup-relay.php; or (6) subnetmask or (7) defaultroute
parameter to setup-network.php.
|
| CVE-2011-5143 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Business
Management (OBM) 2.3.20 and probably earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) tf_name, (2)
tf_delegation, and (3) tf_ip parameters to index.php. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2011-5142 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Business
Management (OBM) 2.4.0-rc13 and probably earlier allow remote
attackers to inject arbitrary web script or HTML via the (1)
tf_delegation, (2) tf_ip, or (3) tf_name parameter in a search action
to host/host_index.php; (4) login parameter to obm.php; or (5) tf_user
parameter in a search action to group/group_index.php.
|
| CVE-2011-5138 |
Cross-site scripting (XSS) vulnerability in member.php in tForum
b0.915 allows remote attackers to inject arbitrary web script or HTML
via the username parameter in a viewprofile action.
|
| CVE-2011-5132 |
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows
remote attackers to inject arbitrary web script or HTML via vectors
related to "usernames via AJAX."
|
| CVE-2011-5128 |
Multiple cross-site scripting (XSS) vulnerabilities in the Adminimize
plugin before 1.7.22 for WordPress allow remote attackers to inject
arbitrary web script or HTML via the page parameter to (1)
inc-options/deinstall_options.php, (2) inc-options/theme_options.php,
or (3) inc-options/im_export_options.php, or the (4) post or (5)
post_ID parameters to adminimize.php, different vectors than
CVE-2011-4926.
|
| CVE-2011-5125 |
Cross-site scripting (XSS) vulnerability in Blue Coat Director before
5.5.2.3 allows remote attackers to inject arbitrary web script or HTML
via vectors involving the HTTP TRACE method.
|
| CVE-2011-5115 |
Cross-site scripting (XSS) vulnerability in DLGuard, possibly 4.6 and
earlier, allows remote attackers to inject arbitrary web script or
HTML via the searchCart parameter to index.php.
|
| CVE-2011-5114 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Authoritative DNS - DNS Zones page in Barracuda Link Balancer 330
Firmware 1.3.2.005 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) zoneid or (2) scope
parameter.
|
| CVE-2011-5108 |
Cross-site scripting (XSS) vulnerability in config.php in AdaptCMS
2.0.0 and 2.0.1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2011-5107 |
Cross-site scripting (XSS) vulnerability in post_alert.php in Alert
Before Your Post plugin, possibly 0.1.1 and earlier, for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
name parameter.
|
| CVE-2011-5106 |
Cross-site scripting (XSS) vulnerability in edit-post.php in the
Flexible Custom Post Type plugin before 0.1.7 for WordPress allows
remote attackers to inject arbitrary web script or HTML via the id
parameter.
|
| CVE-2011-5105 |
Multiple cross-site scripting (XSS) vulnerabilities in
EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build
4521 allow remote attackers to inject arbitrary web script or HTML via
the (1) searchType and (2) searchString parameters, a different
vulnerability than CVE-2010-3274.
|
| CVE-2011-5104 |
Cross-site scripting (XSS) vulnerability in
wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and
possibly earlier for WordPress allows remote attackers to inject
arbitrary web script or HTML via the custom_text parameter. NOTE: some
of these details are obtained from third party information.
|
| CVE-2011-5084 |
Cross-site scripting (XSS) vulnerability in Movable Type 4.x before
4.36 and 5.x before 5.05 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2011-5082 |
Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin
before 111220 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the
s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code
field).
|
| CVE-2011-5081 |
Cross-site scripting (XSS) vulnerability in RestoreFile.pm in BackupPC
3.1.0, 3.2.1, and possibly other earlier versions allows remote
attackers to inject arbitrary web script or HTML via the share
parameter in a RestoreFile action to index.cgi.
|
| CVE-2011-5080 |
Cross-site scripting (XSS) vulnerability in
lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms
(jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-5073 |
Multiple cross-site scripting (XSS) vulnerabilities in Support
Incident Tracker (aka SiT!) before 3.65 allow remote attackers to
inject arbitrary web script or HTML via the (1) mode parameter to
contact_support.php; (2) contractid parameter to
contract_add_service.php; (3) user parameter to edit_backup_users.php;
(4) id parameter to edit_escalation_path.php; the Referer to (5)
forgotpwd.php, (6) an approvalpage action to billable_incidents.php,
or (7) transactions.php; (8) action parameter to inbox.php; (9)
search_string parameter in a findcontact action to incident_add.php;
table1 parameter to (10) report_customers.php, (11)
report_incidents_by_engineer.php, (12) report_incidents_by_site.php,
or (13) report_marketing.php; or the (14) startdate or (15) enddate
parameter to report_incidents_by_vendor.php.
|
| CVE-2011-5070 |
Multiple cross-site scripting (XSS) vulnerabilities in Support
Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject
arbitrary web script or HTML via (1) the file name to
incident_attachments.php; (2) unspecified vectors in link_add.php,
possibly involving origref, linkref, linktype parameters, which are
not properly handled in the clean_int function in lib/base.inc.php, or
the redirect parameter, which is not properly handled in the
html_redirect function in lib/html.inc.php; and (3) unspecified
vectors in translate.php.
|
| CVE-2011-5065 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application
Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject
arbitrary web script or HTML via vectors related to web messaging.
|
| CVE-2011-5048 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Web
Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0
and 7.0.1 allow remote attackers to inject arbitrary web script or
HTML via a (1) text INPUT element or (2) TEXTAREA element, related to
an interaction between Smart Refresh and Dojo.
|
| CVE-2011-5047 |
Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in
pfSense before 2.0.1 allows remote attackers to inject arbitrary web
script or HTML via the style parameter.
|
| CVE-2011-5045 |
Cross-site scripting (XSS) vulnerability in details_view.php in PHP
Booking Calendar 10e allows remote attackers to inject arbitrary web
script or HTML via the page_info_message parameter.
|
| CVE-2011-5042 |
Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in
SASHA 0.2.0 allows remote attackers to inject arbitrary web script or
HTML via the instructors parameter. NOTE: the original disclosure also
mentions the section_title parameter, but this was disputed by the
vendor and retracted by the original researcher.
|
| CVE-2011-5041 |
Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS
1.7.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) d parameter in a blocks action and (2) post_id parameter
in an edit-post action to index.php.
|
| CVE-2011-5040 |
Multiple cross-site scripting (XSS) vulnerabilities in Infoproject
Biznis Heroj allow remote attackers to inject arbitrary web script or
HTML via the config parameter to (1) nalozi_naslov.php and (2)
widget.dokumenti_lista.php.
|
| CVE-2011-5030 |
Cross-site scripting (XSS) vulnerability in the Meta tags quick module
7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
unspecified vectors, probably related to "names of entity bundles."
|
| CVE-2011-5029 |
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog
0.7.0 and possibly earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) entry parameter to delete.php or (2)
category parameter to index.php.
|
| CVE-2011-5027 |
Cross-site scripting (XSS) vulnerability in ZABBIX before 1.8.10
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to the profiler.
|
| CVE-2011-5026 |
Cross-site scripting (XSS) vulnerability in the addPost function in
data/functions.php in Winn GuestBook before 2.4.8d allows remote
attackers to inject arbitrary web script or HTML via the name
parameter to index.php. NOTE: some of these details are obtained from
third party information.
|
| CVE-2011-5025 |
Multiple cross-site scripting (XSS) vulnerabilities in the wiki
application in Yaws 1.88 allow remote attackers to inject arbitrary
web script or HTML via (1) the tag parameter to editTag.yaws, (2) the
index parameter to showOldPage.yaws, (3) the node parameter to
allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.
|
| CVE-2011-5024 |
Cross-site scripting (XSS) vulnerability in mmsearch/design in the
Mailman/htdig integration patch for Mailman allows remote attackers to
inject arbitrary web script or HTML via the config parameter.
|
| CVE-2011-5023 |
Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows
remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to the search program, a different vulnerability than
CVE-2011-3986.
|
| CVE-2011-5019 |
Cross-site scripting (XSS) vulnerability in setup/index.php in
Textpattern CMS 4.4.1, when the product is incompletely installed,
allows remote attackers to inject arbitrary web script or HTML via the
ddb parameter.
|
| CVE-2011-4969 |
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when
using location.hash to select elements, allows remote attackers to
inject arbitrary web script or HTML via a crafted tag.
|
| CVE-2011-4958 |
Cross-site scripting (XSS) vulnerability in the process function in
SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6
allows remote attackers to inject arbitrary web script or HTML via the
QUERY_STRING to template placeholders, as demonstrated by a request to
(1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/,
(5) admin/assets/, and (6) admin/security/.
|
| CVE-2011-4956 |
Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-4955 |
Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in
the bSuite plugin before 5 alpha 3 for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) s or (2)
p parameters to index.php.
|
| CVE-2011-4950 |
Cross-site scripting (XSS) vulnerability in
phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL)
before 11.1.20110804-1 and EGroupware Community Edition before
1.8.001.20110805 allows remote attackers to inject arbitrary web
script or HTML via the lang parameter.
|
| CVE-2011-4947 |
Cross-site request forgery (CSRF) vulnerability in
e107_admin/users_extended.php in e107 before 0.7.26 allows remote
attackers to hijack the authentication of administrators for requests
that insert cross-site scripting (XSS) sequences via the user_include
parameter.
|
| CVE-2011-4942 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/configuration.php in Geeklog before 1.7.1sr1 allow remote
attackers to inject arbitrary web script or HTML via the (1) subgroup
or (2) conf_group parameters. NOTE: this vulnerability might require a
user-assisted attack or a bypass of a CSRF protection mechanism.
|
| CVE-2011-4940 |
The list_directory function in Lib/SimpleHTTPServer.py in
SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and
2.7.x before 2.7.2 does not place a charset parameter in the
Content-Type HTTP header, which makes it easier for remote attackers
to conduct cross-site scripting (XSS) attacks against Internet
Explorer 7 via UTF-7 encoding.
|
| CVE-2011-4928 |
Cross-site scripting (XSS) vulnerability in the textile formatter in
Redmine before 1.0.5 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2011-4926 |
Cross-site scripting (XSS) vulnerability in
adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22
for WordPress allows remote attackers to inject arbitrary web script
or HTML via the page parameter.
|
| CVE-2011-4923 |
Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0,
3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to
inject arbitrary web script or HTML via the num parameter in a view
action to index.cgi, related to the log file viewer, a different
vulnerability than CVE-2011-3361.
|
| CVE-2011-4920 |
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.26,
and other versions before 1.0.0, allow remote attackers to inject
arbitrary web script or HTML via the URL to (1) e107_images/thumb.php
or (2) rate.php, (3) resend_name parameter to e107_admin/users.php,
and (4) link BBCode in user signatures.
|
| CVE-2011-4918 |
Multiple cross-site scripting (XSS) vulnerabilities in Elxis CMS
2009.2, 2009.3 and 2009.3 Aphrodite before revision 2684 allow remote
attackers to inject arbitrary web script or HTML via the (1) task
parameter to elxis/index.php, and (2) PATH_INFO to
elxis/administrator/index.php.
|
| CVE-2011-4910 |
Cross-site scripting (XSS) vulnerability in Joomla! before 1.5.12
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO.
|
| CVE-2011-4909 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.5.12 allow remote attackers to inject arbitrary web script or HTML
via the HTTP_REFERER header to (1)
components/com_content/views/article/tmpl/form.php, (2)
components/com_user/controller.php, (3)
plugins/system/legacy/html.php, or (4)
templates/beez/html/com_content/article/form.php.
|
| CVE-2011-4899 |
** DISPUTED ** wp-admin/setup-config.php in the installation component
in WordPress 3.3.1 and earlier does not ensure that the specified
MySQL database service is appropriate, which allows remote attackers
to configure an arbitrary database via the dbhost and dbname
parameters, and subsequently conduct static code injection and
cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a
MySQL query. NOTE: the vendor disputes the significance of this issue;
however, remote code execution makes the issue important in many
realistic environments.
|
| CVE-2011-4887 |
Cross-site scripting (XSS) vulnerability in the Violations Table in
the management GUI in the MX Management Server in Imperva SecureSphere
Web Application Firewall (WAF) 9.0 allows remote attackers to inject
arbitrary web script or HTML via the username field.
|
| CVE-2011-4836 |
Cross-site scripting (XSS) vulnerability in the web interface in
HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web
script or HTML via a request for a crafted URI.
|
| CVE-2011-4830 |
Multiple cross-site scripting (XSS) vulnerabilities in the com_listing
component in Barter Sites component 1.3 for Joomla! allow remote
authenticated users to inject arbitrary web script or HTML via the (1)
listing_title, (2) description, (3) homeurl (aka Website Address), (4)
paystring (aka Payment types accepted), (5) sell_price, (6)
shipping_cost, and (7) quantity parameters to index.php.
|
| CVE-2011-4827 |
Multiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools
V-CMS 1.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) p parameter to redirect.php and (2) box parameter to
includes/TrueColorPicker/index.php, which is not properly handled in
includes/TrueColorPicker/class.TrueColorPicker.php.
|
| CVE-2011-4822 |
Multiple cross-site scripting (XSS) vulnerabilities in the user
profile feature in Atlassian FishEye before 2.5.5 allow remote
attackers to inject arbitrary web script or HTML via (1) snippets in a
user comment, which is not properly handled in a Confluence page, or
(2) the user profile display name, which is not properly handled in a
FishEye page.
|
| CVE-2011-4819 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo
Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5
allow remote attackers to inject arbitrary web script or HTML via the
uisesionid parameter to (1) maximo.jsp or (2) the default URI under
ui/.
|
| CVE-2011-4814 |
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0
RC and probably earlier allow remote attackers to inject arbitrary web
script or HTML via the PATH_INFO to (1) index.php, (2)
admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the
optioncss parameter to (5) admin/ihm.php and (6) user/home.php.
|
| CVE-2011-4812 |
Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro
allows remote attackers to inject arbitrary web script or HTML via the
str parameter.
|
| CVE-2011-4809 |
Multiple cross-site scripting (XSS) vulnerabilities in the HM
Community (com_hmcommunity) component before 1.01 for Joomla! allow
remote attackers to inject arbitrary web script or HTML via the (1)
language[], (2) university[], (3) persent[], (4) company_name[], (5)
designation[], (6) music[], (7) books[], (8) movies[], (9) games[],
(10) syp[], (11) ft[], and (12) fa[] parameters in a save task for a
profile to index.php. NOTE: some of these details are obtained from
third party information.
|
| CVE-2011-4806 |
Multiple cross-site scripting (XSS) vulnerabilities in main.php in
phpAlbum 0.4.1.16 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) var1 and (2) keyword
parameters.
|
| CVE-2011-4805 |
Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP
Crystal Report Server 2008 allows remote attackers to inject arbitrary
web script or HTML via the service parameter.
|
| CVE-2011-4782 |
Cross-site scripting (XSS) vulnerability in
libraries/config/ConfigFile.class.php in the setup interface in
phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject
arbitrary web script or HTML via the host parameter.
|
| CVE-2011-4780 |
Multiple cross-site scripting (XSS) vulnerabilities in
libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9
allow remote attackers to inject arbitrary web script or HTML via
crafted URL parameters, related to the export panels in the (1)
server, (2) database, and (3) table sections.
|
| CVE-2011-4778 |
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 4.2.x
before 4.2.5 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, aka SPL-44614.
|
| CVE-2011-4777 |
Cross-site scripting (XSS) vulnerability in the Site Editor (aka
SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18
allows remote attackers to inject arbitrary web script or HTML via the
login parameter to preferences.html.
|
| CVE-2011-4776 |
Multiple cross-site scripting (XSS) vulnerabilities in the Control
Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allow remote
attackers to inject arbitrary web script or HTML via crafted input to
a PHP script, as demonstrated by admin/update/settings/ and certain
other files.
|
| CVE-2011-4764 |
Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor
(aka SiteBuilder) feature in Parallels Plesk Small Business Panel
10.2.0 allow remote attackers to inject arbitrary web script or HTML
via crafted input to a PHP script, as demonstrated by
Wizard/Edit/Modules/Image and certain other files.
|
| CVE-2011-4754 |
Multiple cross-site scripting (XSS) vulnerabilities in Parallels Plesk
Small Business Panel 10.2.0 allow remote attackers to inject arbitrary
web script or HTML via crafted input to a PHP script, as demonstrated
by smb/app/available/id/apscatalog/ and certain other files.
|
| CVE-2011-4750 |
Multiple cross-site scripting (XSS) vulnerabilities in SmarterTools
SmarterStats 6.2.4100 allow remote attackers to inject arbitrary web
script or HTML via crafted input to a PHP script, as demonstrated by
Default.aspx and certain other files.
|
| CVE-2011-4745 |
Multiple cross-site scripting (XSS) vulnerabilities in the billing
system for Parallels Plesk Panel 10.3.1_build1013110726.09 allow
remote attackers to inject arbitrary web script or HTML via crafted
input to a PHP script, as demonstrated by admin/index.php/default and
certain other files.
|
| CVE-2011-4735 |
Multiple cross-site scripting (XSS) vulnerabilities in the Control
Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow remote
attackers to inject arbitrary web script or HTML via crafted input to
a PHP script, as demonstrated by smb/user/create and certain other
files.
|
| CVE-2011-4726 |
Multiple cross-site scripting (XSS) vulnerabilities in the Server
Administration Panel in Parallels Plesk Panel
10.2.0_build1011110331.18 allow remote attackers to inject arbitrary
web script or HTML via crafted input to a PHP script, as demonstrated
by admin/health/ and certain other files.
|
| CVE-2011-4709 |
Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in
the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject
arbitrary web script or HTML via the (1) SITE_NAME parameter to
admin_index.php, or the (2) return and (3) search parameters to
index.php. NOTE: some of these details are obtained from third party
information.
|
| CVE-2011-4708 |
Cross-site scripting (XSS) vulnerability in IBM Rational Asset Manager
before 7.5.1 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2011-4707 |
Multiple cross-site scripting (XSS) vulnerabilities in the Virus Scan
Interface in SAP Netweaver allow remote attackers to inject arbitrary
web script or HTML via the (1) instname parameter to the VsiTestScan
servlet and (2) name parameter to the VsiTestServlet servlet.
|
| CVE-2011-4680 |
Multiple cross-site scripting (XSS) vulnerabilities in the customer
portal in vtiger CRM before 5.2.0 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-4670 |
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM
5.2.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) viewname parameter in a CalendarAjax
action, (2) activity_mode parameter in a DetailView action, (3)
contact_id and (4) parent_id parameters in an EditView action, (5)
day, (6) month, (7) subtab, (8) view, and (9) viewOption parameters in
the index action, and (10) start parameter in the ListView action to
the Calendar module; (11) return_action and (12) return_module
parameters in the EditView action, and (13) query parameter in an
index action to the Campaigns module; (14) return_url and (15)
workflow_id parameters in an editworkflow action to the
com_vtiger_workflow module; (16) display_view parameter in an index
action to the Dashboard module; (17) closingdate_end, (18)
closingdate_start, (19) date_closed, (20) owner, (21) leadsource, (22)
sales_stage, and (23) type parameters in a ListView action to the
Potentials module; (24) folderid parameter in a SaveandRun action to
the Reports module; (25) returnaction and (26) groupId parameters in a
createnewgroup action, (27) mode and (28) parent parameters in a
createrole action, (29) src_module in a ModuleManager action, (30)
mode and (31) profile_id parameters in a profilePrivileges action, and
(32) roleid parameter in a RoleDetailView to the Settings module; and
(33) action parameter to the Home module and (34) module parameter to
phprint.php.
|
| CVE-2011-4647 |
Multiple cross-site scripting (XSS) vulnerabilities in the story
creation feature in Geeklog 1.8.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) code or (2) raw BBcode tags.
|
| CVE-2011-4634 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
3.4.x before 3.4.8 allow remote attackers to inject arbitrary web
script or HTML via (1) a crafted database name, related to the
Database Synchronize panel; (2) a crafted database name, related to
the Database rename panel; (3) a crafted SQL query, related to the
table overview panel; (4) a crafted SQL query, related to the view
creation dialog; (5) a crafted column type, related to the table
search dialog; or (6) a crafted column type, related to the create
index dialog.
|
| CVE-2011-4624 |
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND
FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress
allows remote attackers to inject arbitrary web script or HTML via the
i parameter.
|
| CVE-2011-4618 |
Cross-site scripting (XSS) vulnerability in advancedtext.php in
Advanced Text Widget plugin before 2.0.2 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the page
parameter.
|
| CVE-2011-4616 |
Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro
module before 0.9507 for Perl allows remote attackers to inject
arbitrary web script or HTML via template parameters, related to
improper handling of > (greater than) and < (less than) characters.
|
| CVE-2011-4615 |
Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before
1.8.10 allow remote attackers to inject arbitrary web script or HTML
via the gname parameter (aka host groups name) to (1) hostgroups.php
and (2) usergrps.php, the update action to (3) hosts.php and (4)
scripts.php, and (5) maintenance.php.
|
| CVE-2011-4591 |
Cross-site scripting (XSS) vulnerability in the print_object function
in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before
2.1.3, when a developer debugging script is enabled, allows remote
attackers to inject arbitrary web script or HTML via vectors involving
object states.
|
| CVE-2011-4580 |
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss
Enterprise Portal Platform before 5.2.0 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-4575 |
Cross-site scripting (XSS) vulnerability in the JMX console in JBoss
Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP)
before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before
5.3.1 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2011-4572 |
Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF
Image Hosting Script 1.3.82, 1.4.1, and probably other versions before
1.4.2 allows remote attackers to inject arbitrary web script or HTML
via the q parameter. NOTE: this was originally reported as a file
disclosure vulnerability, but this is likely inaccurate.
|
| CVE-2011-4568 |
Cross-site scripting (XSS) vulnerability in view/frontend-head.php in
the Flowplayer plugin before 1.2.12 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the URI.
|
| CVE-2011-4567 |
Cross-site scripting (XSS) vulnerability in
includes/templates/template_default/templates/tpl_gv_send_default.php
in Zen Cart before 1.5 allows remote attackers to inject arbitrary web
script or HTML via the message parameter in a gv_send action to
index.php, a different vulnerability than CVE-2011-4547.
|
| CVE-2011-4565 |
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a,
and possibly earlier versions, allow remote attackers to inject
arbitrary web script or HTML via the (1) text parameter to
include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the
message parameter to pmlite.php (aka Private Message). NOTE: some of
these details are obtained from third party information.
|
| CVE-2011-4564 |
Cross-site scripting (XSS) vulnerability in the admin script in Active
CMS 1.2 allows remote attackers to inject arbitrary web script or HTML
via the mod parameter in a module action.
|
| CVE-2011-4563 |
Cross-site scripting (XSS) vulnerability in index.php in JAKCMS
2.0.4.1, and possibly other versions before 2.2.6 2011-09-23, allows
remote attackers to inject arbitrary web script or HTML via the
userpost parameter in a PM request, related to tinymce. NOTE: some of
these details are obtained from third party information.
|
| CVE-2011-4562 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
view/admin/log_item.php and (2) view/admin/log_item_details.php in the
Redirection plugin 2.2.9 for WordPress allow remote attackers to
inject arbitrary web script or HTML via the Referer HTTP header in a
request to a post that does not exist.
|
| CVE-2011-4561 |
Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to admin/index.php. NOTE: some of these details are obtained
from third party information.
|
| CVE-2011-4560 |
Cross-site scripting (XSS) vulnerability in the Petition Node module
6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors related to
signing a petition.
|
| CVE-2011-4552 |
Multiple cross-site scripting (XSS) vulnerabilities in One Click Orgs
before 1.2.3 allow remote attackers to inject arbitrary web script or
HTML via the description field of (1) a new vote or (2) the eject
member proposal feature.
|
| CVE-2011-4551 |
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in
TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote
attackers to inject arbitrary web script or HTML via arbitrary
parameters.
|
| CVE-2011-4547 |
Multiple cross-site scripting (XSS) vulnerabilities in
includes/templates/template_default/common/tpl_header_test_info.php in
Zen Cart 1.3.9h, when debugging is enabled, might allow remote
attackers to inject arbitrary web script or HTML via the (1) main_page
parameter or (2) PATH_INFO, a different vulnerability than
CVE-2011-4567.
|
| CVE-2011-4544 |
Multiple cross-site scripting (XSS) vulnerabilities in Prestashop
before 1.5 allow remote attackers to inject arbitrary web script or
HTML via the (1) address or (2) relativ_base_dir parameter to
modules/mondialrelay/googlemap.php; the (3) relativ_base_dir, (4)
Pays, (5) Ville, (6) CP, (7) Poids, (8) Action, or (9) num parameter
to prestashop/modules/mondialrelay/googlemap.php; (10) the num_mode
parameter to
modules/mondialrelay/kit_mondialrelay/RechercheDetailPointRelais_ajax.php;
(11) the Expedition parameter to
modules/mondialrelay/kit_mondialrelay/SuiviExpedition_ajax.php; or the
(12) folder or (13) name parameter to
admin/ajaxfilemanager/ajax_save_text.php.
|
| CVE-2011-4541 |
Cross-site scripting (XSS) vulnerability in index.php in Hastymail2
2.1.1 before RC2 allows remote attackers to inject arbitrary web
script or HTML via the rs parameter in a mailbox Drafts action.
|
| CVE-2011-4540 |
Multiple cross-site scripting (XSS) vulnerabilities in AtMail Open
(aka AtMail Open-Source edition) 1.04 allow remote attackers to inject
arbitrary web script or HTML via the func parameter to (1) ldap.php or
(2) search.php.
|
| CVE-2011-4523 |
Cross-site scripting (XSS) vulnerability in bwview.asp in
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to
inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2011-4522 |
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to
inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2011-4511 |
Cross-site scripting (XSS) vulnerability in the HMI web server in
Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC
V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort
Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime
Advanced; and WinCC flexible Runtime allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2011-4510.
|
| CVE-2011-4510 |
Cross-site scripting (XSS) vulnerability in the HMI web server in
Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC
V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort
Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime
Advanced; and WinCC flexible Runtime allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2011-4511.
|
| CVE-2011-4465 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect
(LMC) 6.1.4 allows remote attackers to inject arbitrary web script or
HTML via vectors related to a hidden redirect URL.
|
| CVE-2011-4436 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative web interface on the Dell KACE K2000 System Deployment
Appliance allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2011-4368 |
Cross-site scripting (XSS) vulnerability in Remote Development
Services (RDS) in Adobe ColdFusion 8.0 through 9.0.1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2011-4346 |
Cross-site scripting (XSS) vulnerability in the web interface in Red
Hat Network (RHN) Satellite 5.4.1 allows remote authenticated users to
inject arbitrary web script or HTML via the Description field of the
asset tag in a Custom Info page.
|
| CVE-2011-4345 |
Cross-site scripting (XSS) vulnerability in Namazu before 2.0.21, when
Internet Explorer 6 or 7 is used, allows remote attackers to inject
arbitrary web script or HTML via a cookie.
|
| CVE-2011-4344 |
Cross-site scripting (XSS) vulnerability in Jenkins Core in Jenkins
before 1.438, and 1.409 LTS before 1.409.3 LTS, when a stand-alone
container is used, allows remote attackers to inject arbitrary web
script or HTML via vectors related to error messages.
|
| CVE-2011-4341 |
Multiple SQL injection vulnerabilities in
symphony/content/content.publish.php in Symphony CMS 2.2.3 and
possibly other versions before 2.2.4 allow remote authenticated users
with Author permissions to execute arbitrary SQL commands via the
filter parameter to (1) symphony/publish/comments or (2)
symphony/publish/images. NOTE: this issue can be leveraged to perform
cross-site scripting (XSS) attacks via error messages. NOTE: some of
these details are obtained from third party information.
|
| CVE-2011-4340 |
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS
2.2.3 and possibly other versions before 2.2.4 allow remote
authenticated users with Author privileges to inject arbitrary web
script or HTML via (1) the profile parameter to
extensions/profiledevkit/content/content.profile.php, as demonstrated
via requests to (a) the default URI, (b) about/, or (c) drafts/; or
(2) the filter parameter in symphony/lib/core/class.symphony.php, as
demonstrated via requests to (d) symphony/publish/comments or (e)
symphony/publish/images. NOTE: some of these details are obtained from
third party information.
|
| CVE-2011-4335 |
Multiple cross-site scripting (XSS) vulnerabilities in Contao before
2.10.2 allow remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/
action.
|
| CVE-2011-4333 |
Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) from parameter to index.php or the (2) page_no parameter
to recentchanges.php.
|
| CVE-2011-4332 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3
and earlier allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2011-4329 |
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0
allow remote attackers to inject arbitrary web script or HTML via (1)
the username parameter in a setup action to admin/company.php, or the
PATH_INFO to (2) admin/security_other.php, (3) admin/events.php, or
(4) admin/user.php.
|
| CVE-2011-4319 |
Cross-site scripting (XSS) vulnerability in the i18n translations
helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before
3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote
attackers to inject arbitrary web script or HTML via vectors related
to a translations string whose name ends with an "html" substring.
|
| CVE-2011-4312 |
Multiple cross-site scripting (XSS) vulnerabilities in the commenting
system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow
remote attackers to inject arbitrary web script or HTML via vectors
involving the (1) diff viewer or (2) screenshot component.
|
| CVE-2011-4307 |
Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php
in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote
attackers to inject arbitrary web script or HTML via the section
parameter.
|
| CVE-2011-4306 |
Cross-site scripting (XSS) vulnerability in course/editsection.html in
Moodle 1.9.x before 1.9.14 allows remote authenticated users to inject
arbitrary web script or HTML via crafted data.
|
| CVE-2011-4299 |
Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in
Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote
authenticated users to inject arbitrary web script or HTML via a wiki
comment.
|
| CVE-2011-4290 |
Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php
in Moodle 1.9.x before 1.9.12 allow remote attackers to inject
arbitrary web script or HTML via vectors related to URL encoding.
|
| CVE-2011-4286 |
Multiple cross-site scripting (XSS) vulnerabilities in the
media-filter implementation in filter/mediaplugin/filter.php in Moodle
1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to
inject arbitrary web script or HTML via vectors involving (1) Flash
Video (aka FLV) files and (2) YouTube videos.
|
| CVE-2011-4282 |
Multiple cross-site scripting (XSS) vulnerabilities in the course-tags
functionality in tag/coursetags_more.php in Moodle 2.0.x before 2.0.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) sort or (2) show parameter.
|
| CVE-2011-4280 |
Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka
spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and
other products, allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2011-4278 |
Cross-site scripting (XSS) vulnerability in the tag autocomplete
functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-4277 |
Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum
7.0.1.3038 allows remote attackers to inject arbitrary web script or
HTML via a crafted name of an object within a more object on a wiki
page.
|
| CVE-2011-4275 |
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT
Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to
inject arbitrary web script or HTML via (1) a crafted company name,
(2) a crafted database server name, (3) a crafted CSV file, (4) a
crafted copy-and-paste action, (5) the auth_user parameter in a
suggest_pwd action to UI.php, (6) the c[menu] parameter to
UniversalSearch.php, (7) the description parameter in a
SearchFormToAdd_document_list action to UI.php, (8) the category
parameter in an errors action to audit.php, or (9) the suggest_pwd
parameter to UI.php.
|
| CVE-2011-4274 |
Cross-site scripting (XSS) vulnerability in the A-Form PC and
PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors, a
different vulnerability than CVE-2011-2676.
|
| CVE-2011-4273 |
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead
Webserver 2.18 allow remote attackers to inject arbitrary web script
or HTML via (1) the group parameter to goform/AddGroup, related to
addgroup.asp; (2) the url parameter to goform/AddAccessLimit, related
to addlimit.asp; or the (3) user (aka User ID) or (4) group parameter
to goform/AddUser, related to adduser.asp.
|
| CVE-2011-4265 |
Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-4264 |
Cross-site scripting (XSS) vulnerability in Etomite before 1.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-4263 |
Cross-site scripting (XSS) vulnerability in Schneider Electric
PowerChute Business Edition before 8.5 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-4193 |
Cross-site scripting (XSS) vulnerability in the overlay files tab in
SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for
System z 1.2 before 1.2.1 allows remote attackers to inject arbitrary
web script or HTML via a crafted application, related to cloning.
|
| CVE-2011-4172 |
Multiple cross-site scripting (XSS) vulnerabilities in KENT-WEB WEB
FORUM before 5.1 allow remote attackers to inject arbitrary web script
or HTML via (1) an e-mail address field or (2) a cookie, a related
issue to CVE-2011-3383, CVE-2011-3983, and CVE-2011-3984.
|
| CVE-2011-4171 |
Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM
WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to
inject arbitrary web script or HTML via the project parameter to
teamserver/faces/home.jsp.
|
| CVE-2011-4170 |
Cross-site scripting (XSS) vulnerability in the
theme_adium_append_message function in empathy-theme-adium.c in the
Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows
remote attackers to inject arbitrary web script or HTML via a crafted
alias (aka nickname) in a /me event, a different vulnerability than
CVE-2011-3635.
|
| CVE-2011-4156 |
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i
(NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2011-4155.
|
| CVE-2011-4155 |
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i
(NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2011-4156.
|
| CVE-2011-4075 |
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before
1.2.2 allows remote attackers to execute arbitrary PHP code via the
orderby parameter (aka sortby variable) in a query_engine action to
cmd.php, as exploited in the wild in October 2011.
|
| CVE-2011-4074 |
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin
1.2.x before 1.2.2 allows remote attackers to inject arbitrary web
script or HTML via an _debug command.
|
| CVE-2011-4064 |
Cross-site scripting (XSS) vulnerability in the setup interface in
phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject
arbitrary web script or HTML via a crafted value.
|
| CVE-2011-4054 |
Cross-site scripting (XSS) vulnerability in login.fcc in CA SiteMinder
R6 SP6 before CR7 and R12 SP3 before CR8 allows remote attackers to
inject arbitrary web script or HTML via the postpreservationdata
parameter.
|
| CVE-2011-4038 |
Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI
Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream
Report before 4.0 and other products, allows remote attackers to
inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2011-4035 |
Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo
Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and
CitectSCADAReports 4.10 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-4024 |
Cross-site scripting (XSS) vulnerability in ocsinventory in OCS
Inventory NG 2.0.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-3999 |
Cross-site scripting (XSS) vulnerability in the RSS/Atom feed-reader
implementation in Iwate Portal Bar allows remote attackers to inject
arbitrary web script or HTML via a crafted feed.
|
| CVE-2011-3998 |
Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2011-3990 |
Cross-site scripting (XSS) vulnerability in plugin/comment.inc.php in
PukiWiki Plus! 1.4.7plus-u2-i18n and earlier allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-3986 |
Cross-site scripting (XSS) vulnerability in Pligg before 1.2.0 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-3985 |
Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-3984 |
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via vectors related to "web form entries."
|
| CVE-2011-3983 |
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via vectors related to cookies.
|
| CVE-2011-3979 |
Cross-site scripting (XSS) vulnerability in
ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme
module in Zikula Application Framework 1.3.0 build 3168, 1.2.7, and
probably other versions allows remote attackers to inject arbitrary
web script or HTML via the themename parameter in the setasdefault
action to index.php.
|
| CVE-2011-3978 |
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php
in LightNEasy 3.2.4 allow remote authenticated users to inject
arbitrary web script or HTML via the (1) commentemail, (2)
commentmessage, or (3) commentname parameter in a sendcomment action
for the news page.
|
| CVE-2011-3881 |
WebKit, as used in Google Chrome before 15.0.874.102 and Android
before 4.4, allows remote attackers to bypass the Same Origin Policy
and conduct Universal XSS (UXSS) attacks via vectors related to (1)
the DOMWindow::clear function and use of a selection object, (2) the
Object::GetRealNamedPropertyInPrototypeChain function and use of an
__proto__ property, (3) the
HTMLPlugInImageElement::allowedToLoadFrameURL function and use of a
javascript: URL, (4) incorrect origins for XSLT-generated documents in
the XSLTProcessor::createDocumentFromSource function, and (5) improper
handling of synchronous frame loads in the
ScriptController::executeIfJavaScriptURL function.
|
| CVE-2011-3877 |
Cross-site scripting (XSS) vulnerability in the appcache internals
page in Google Chrome before 15.0.874.102 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-3865 |
Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme
before 1.6 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO to index.php.
|
| CVE-2011-3864 |
Cross-site scripting (XSS) vulnerability in the The Erudite theme
before 2.7.9 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the cpage parameter.
|
| CVE-2011-3863 |
Cross-site scripting (XSS) vulnerability in the RedLine theme before
1.66 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the s parameter.
|
| CVE-2011-3862 |
Cross-site scripting (XSS) vulnerability in the Morning Coffee theme
before 3.6 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO to index.php.
|
| CVE-2011-3861 |
Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901
theme before 1.2 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO to index.php.
|
| CVE-2011-3860 |
Cross-site scripting (XSS) vulnerability in the Cover WP theme before
1.6.6 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the s parameter.
|
| CVE-2011-3859 |
Cross-site scripting (XSS) vulnerability in the Trending theme before
0.2 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the cpage parameter.
|
| CVE-2011-3858 |
Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme
before 2.1.6 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the s parameter.
|
| CVE-2011-3857 |
Cross-site scripting (XSS) vulnerability in the Antisnews theme before
1.10 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the s parameter.
|
| CVE-2011-3856 |
Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme
before 1.0.4 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the s parameter.
|
| CVE-2011-3855 |
Cross-site scripting (XSS) vulnerability in the F8 Lite theme before
4.2.2 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the s parameter.
|
| CVE-2011-3854 |
Cross-site scripting (XSS) vulnerability in the ZenLite theme before
4.4 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the s parameter.
|
| CVE-2011-3853 |
Cross-site scripting (XSS) vulnerability in the Hybrid theme before
0.10 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the cpage parameter.
|
| CVE-2011-3852 |
Cross-site scripting (XSS) vulnerability in the EvoLve theme before
1.2.6 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the s parameter.
|
| CVE-2011-3851 |
Cross-site scripting (XSS) vulnerability in the News theme before 0.2
for WordPress allows remote attackers to inject arbitrary web script
or HTML via the cpage parameter.
|
| CVE-2011-3850 |
Cross-site scripting (XSS) vulnerability in the Atahualpa theme before
3.6.8 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the s parameter.
|
| CVE-2011-3841 |
Cross-site scripting (XSS) vulnerability in
uploadify/get_profile_avatar.php in the WP Symposium plugin before
11.12.08 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the uid parameter.
|
| CVE-2011-3836 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Wuzly
2.0 allow remote attackers to hijack the authentication of
administrators for requests that (1) add an administrator, (2) perform
cross-site scripting (XSS), (3) perform SQL injection, or have other
unspecified impact via unknown vectors.
|
| CVE-2011-3835 |
Multiple cross-site scripting (XSS) vulnerabilities in Wuzly 2.0 allow
remote attackers to inject arbitrary web script or HTML via the
Referer header to (1) admin/login.php and (2) admin/404.php; the (3) q
parameter to search.php; the (4) theme_name parameter to
theme_settings.php, (5) extension_name parameter to
extension_settings.php, (6) q parameter to search.php, (7) type
parameter to comments.php, sort parameter to (8) pages.php and (9)
posts.php, and the (10) type and (11) q parameter to media.php in
admin/; the sidebar parameter to (12) add_widget.php and (13)
widgets.php, id parameter to (14) category_delete.php, (15)
comment.php, (16) page_delete.php, and (17) post_delete.php, (18) type
parameter to media.php, and (19) id and (20) sidebar parameter to
widget_delete.php in mobile/; and the (21) name, (22) email, (23)
website, and (24) comment parameters to index.php; and the (25)
username parameter to admin/login.php.
|
| CVE-2011-3830 |
Cross-site scripting (XSS) vulnerability in search.php in Support
Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject
arbitrary web script or HTML via the search_string parameter.
|
| CVE-2011-3689 |
Cross-site scripting (XSS) vulnerability in Licenses.html in
Wibu-Systems CodeMeter WebAdmin 3.30 and 4.30 allows remote attackers
to inject arbitrary web script or HTML via the BoxSerial parameter.
|
| CVE-2011-3687 |
Multiple cross-site scripting (XSS) vulnerabilities in Sonexis
ConferenceManager 9.2.11.0 allow remote attackers to inject arbitrary
web script or HTML via (1) the txtConferenceID parameter to
HostLogin.asp, (2) the txtConferenceID parameter to
ParticipantLogin.asp, (3) the acp parameter to ForgotPIN.asp, or the
(4) Description, (5) title, or (6) Heading parameter to Error.asp.
|
| CVE-2011-3686 |
Multiple cross-site scripting (XSS) vulnerabilities in
myAddressBook.asp in Sonexis ConferenceManager 9.2.11.0 and 9.3.14.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) fname, (2) lname, (3) email_edit, (4) email, (5) email2, (6)
email3, (7) sms, (8) sms_id, or (9) work parameter.
|
| CVE-2011-3684 |
Multiple cross-site scripting (XSS) vulnerabilities in Tembria Server
Monitor before 6.0.5 Build 2252 allow remote attackers to inject
arbitrary web script or HTML via (1) the siteid parameter to
logbook.asp, (2) the siteid parameter to monitor-events.asp, (3) the
siteid parameter to reports-config-by-device.asp, (4) the siteid
parameter to reports-config-by-monitor.asp, (5) the siteid parameter
to reports-monitoring-queue.asp, (6) the action parameter to
site-list.asp, the (7) siteid or (8) type parameter to
event-history.asp, the (9) siteid or (10) type parameter to
admin-history.asp, the (11) siteid or (12) id parameter to
dashboard-view.asp, the (13) siteid or (14) dn parameter to
device-events.asp, the (15) siteid or (16) submit parameter to
device-finder.asp, the (17) siteid or (18) dn parameter to
device-monitors.asp, the (19) siteid or (20) type parameter to
device-views.asp, the (21) siteid or (22) type parameter to
monitor-views.asp, the (23) siteid or (24) sel parameter to
reports-list.asp, the (25) siteid, (26) action, or (27) sel parameter
to monitor-list.asp, or the (28) siteid, (29) action, or (30) sel
parameter to device-list.asp.
|
| CVE-2011-3657 |
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x
and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x
before 4.0.3, and 4.1.x through 4.1.3, when debug mode is used, allow
remote attackers to inject arbitrary web script or HTML via vectors
involving a (1) tabular report, (2) graphical report, or (3) new
chart.
|
| CVE-2011-3648 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before
3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0
through 7.0 allows remote attackers to inject arbitrary web script or
HTML via crafted text with Shift JIS encoding.
|
| CVE-2011-3635 |
Cross-site scripting (XSS) vulnerability in the
theme_adium_append_message function in empathy-theme-adium.c in the
Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows
remote attackers to inject arbitrary web script or HTML via a crafted
alias (aka nickname).
|
| CVE-2011-3598 |
Multiple cross-site scripting (XSS) vulnerabilities in phpPgAdmin
before 5.0.3 allow remote attackers to inject arbitrary web script or
HTML via (1) a web page title, related to classes/Misc.php; or the (2)
return_url or (3) return_desc parameter to display.php.
|
| CVE-2011-3592 |
Multiple cross-site scripting (XSS) vulnerabilities in the
PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before
3.4.5 allow remote authenticated users to inject arbitrary web script
or HTML via a (1) database name, (2) table name, or (3) column name
that is not properly handled after an inline-editing operation.
|
| CVE-2011-3591 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
3.4.x before 3.4.5 allow remote authenticated users to inject
arbitrary web script or HTML via a crafted row that triggers an
improperly constructed confirmation message after inline-editing and
save operations, related to (1) js/functions.js and (2)
js/tbl_structure.js.
|
| CVE-2011-3578 |
Cross-site scripting (XSS) vulnerability in
bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote
attackers to inject arbitrary web script or HTML via the action
parameter, related to bug_actiongroup_page.php, a different
vulnerability than CVE-2011-3357.
|
| CVE-2011-3576 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2
allows remote attackers to inject arbitrary web script or HTML via the
PanelIcon parameter in an fmpgPanelHeader ReadForm action to
WebAdmin.nsf.
|
| CVE-2011-3426 |
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before
5 allows remote web servers to inject arbitrary web script or HTML via
a file accompanied by a "Content-Disposition: attachment" HTTP header.
|
| CVE-2011-3423 |
Cross-site scripting (XSS) vulnerability in the Managed File Transfer
server in TIBCO Managed File Transfer Internet Server before 7.1.1 and
Managed File Transfer Command Center before 7.1.1, and the server in
TIBCO Slingshot before 1.8.1, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-3393 |
Multiple cross-site scripting (XSS) vulnerabilities in findagent.php
in MYRE Real Estate Software allow remote attackers to inject
arbitrary web script or HTML via the (1) country1, (2) state1, or (3)
city1 parameter.
|
| CVE-2011-3392 |
Cross-site scripting (XSS) vulnerability in control.php in the
controlcenter in Phorum before 5.2.17 allows remote attackers to
inject arbitrary web script or HTML via the real_name parameter.
|
| CVE-2011-3390 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
IBM OpenAdmin Tool (OAT) before 2.72 for Informix allow remote
attackers to inject arbitrary web script or HTML via the (1)
informixserver, (2) host, or (3) port parameter in a login action.
|
| CVE-2011-3385 |
Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8,
as used in LEPTON and possibly other products, allows remote attackers
to inject arbitrary web script or HTML via unknown vectors, a
different vulnerability than CVE-2006-2307.
|
| CVE-2011-3384 |
Cross-site scripting (XSS) vulnerability in the Sage add-on 1.3.10 and
earlier for Firefox allows remote attackers to inject arbitrary web
script or HTML via a crafted feed, a different vulnerability than
CVE-2009-4102.
|
| CVE-2011-3383 |
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via vectors related to "the web page to be output."
|
| CVE-2011-3382 |
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.16
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-3371 |
Multiple cross-site scripting (XSS) vulnerabilities in
include/functions.php in PunBB before 1.3.6 allow remote attackers to
inject arbitrary web script or HTML via the (1) id, (2) form_sent, (3)
csrf_token, (4) req_confirm, or (5) delete parameter to delete.php,
the (6) id, (7) form_sent, (8) csrf_token, (9) req_message, or (10)
submit parameter to edit.php, the (11) action, (12) form_sent, (13)
csrf_token, (14) req_email, or (15) request_pass parameter to
login.php, the (16) email, (17) form_sent, (18) redirect_url, (19)
csrf_token, (20) req_subject, (21) req_message, or (22) submit
parameter to misc.php, the (23) action, (24) id, (25) form_sent, (26)
csrf_token, (27) req_old_password, (28) req_new_password1, (29)
req_new_password2, or (30) update parameter to profile.php, or the
(31) action, (32) form_sent, (33) csrf_token, (34) req_username, (35)
req_password1, (36) req_password2, (37) req_email1, (38) timezone, or
(39) register parameter to register.php.
|
| CVE-2011-3361 |
Cross-site scripting (XSS) vulnerability in CGI/Browse.pm in BackupPC
3.2.0 and possibly other versions before 3.2.1 allows remote attackers
to inject arbitrary web script or HTML via the num parameter in a
browse action to index.cgi.
|
| CVE-2011-3358 |
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before
1.2.8 allow remote attackers to inject arbitrary web script or HTML
via the (1) os, (2) os_build, or (3) platform parameter to (a)
bug_report_page.php or (b) bug_update_advanced_page.php, related to
use of the Projax library.
|
| CVE-2011-3356 |
Multiple cross-site scripting (XSS) vulnerabilities in
config_defaults_inc.php in MantisBT before 1.2.8 allow remote
attackers to inject arbitrary web script or HTML via the PATH_INFO, as
demonstrated by the PATH_INFO to (1) manage_config_email_page.php, (2)
manage_config_workflow_page.php, or (3) bugs/plugin.php.
|
| CVE-2011-3344 |
Cross-site scripting (XSS) vulnerability in the Lookup Login/Password
form in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite,
allows remote attackers to inject arbitrary web script or HTML via the
URI.
|
| CVE-2011-3339 |
Cross-site scripting (XSS) vulnerability in the Admin Control Center
in Sentinel HASP Run-time Environment 5.95 and earlier in SafeNet
Sentinel HASP (formerly Aladdin HASP SRM) run-time installer before
6.x and SDK before 5.11, as used in 7 Technologies (7T) IGSS 7 and
other products, when Firefox 2.0 is used, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors that
trigger write access to a configuration file.
|
| CVE-2011-3320 |
Cross-site scripting (XSS) vulnerability in the Web Administrator
component in GE Intelligent Platforms Proficy Historian 4.x and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified parameters.
|
| CVE-2011-3317 |
Multiple cross-site scripting (XSS) vulnerabilities in the Solution
Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka Bug ID CSCtr78192.
|
| CVE-2011-3294 |
Cross-site scripting (XSS) vulnerability in the login page in the
administrative interface on Cisco TelePresence Video Communication
Servers (VCS) with software before X7.0 allows remote attackers to
inject arbitrary web script or HTML via the User-Agent HTTP header,
aka Bug ID CSCts80342.
|
| CVE-2011-3293 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow
remote attackers to hijack the authentication of administrators for
requests that insert cross-site scripting (XSS) sequences, aka Bug ID
CSCtr78143.
|
| CVE-2011-3254 |
Cross-site scripting (XSS) vulnerability in Calendar in Apple iOS
before 5 allows remote attackers to inject arbitrary web script or
HTML via an invitation note.
|
| CVE-2011-3243 |
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple
iOS before 5 and Safari before 5.1.1, allows remote attackers to
inject arbitrary web script or HTML via vectors involving inactive DOM
windows.
|
| CVE-2011-3218 |
The "Save for Web" selection in QuickTime Player in Apple Mac OS X
through 10.6.8 exports HTML documents that contain an http link to a
script file, which allows man-in-the-middle attackers to conduct
cross-site scripting (XSS) attacks by spoofing the http server during
local viewing of an exported document.
|
| CVE-2011-3206 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administration interface in RHQ 4.2.0, as used in JBoss Operations
Network (aka JON or JBoss ON) before 3.0, allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-3199 |
Multiple cross-site scripting (XSS) vulnerabilities in Domain
Technologie Control (DTC) before 0.34.1 allow remote authenticated
users to inject arbitrary web script or HTML via the (1) message body
of a support ticket or unspecified vectors to the (2) DNS and (3) MX
form, as demonstrated by the "Domain root TXT record:" field.
|
| CVE-2011-3181 |
Multiple cross-site scripting (XSS) vulnerabilities in the Tracking
feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4
allow remote attackers to inject arbitrary web script or HTML via a
(1) table name, (2) column name, or (3) index name.
|
| CVE-2011-3144 |
Cross-site scripting (XSS) vulnerability in Control Microsystems
ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX
before 67 R4.5 and 68 R3.9, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-3132 |
Cross-site scripting (XSS) vulnerability in TIBCO Spotfire Server
3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x
before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-3058 |
Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP
encoding system, which might allow remote attackers to conduct
cross-site scripting (XSS) attacks via unspecified vectors.
|
| CVE-2011-3046 |
The extension subsystem in Google Chrome before 17.0.963.78 does not
properly handle history navigation, which allows remote attackers to
execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
|
| CVE-2011-3010 |
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before
5.1.0 allow remote attackers to inject arbitrary web script or HTML
via (1) the newtopic parameter in a WebCreateNewTopic action, related
to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string
to SlideShow.pm in the SlideShowPlugin.
|
| CVE-2011-3006 |
The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS
Endpoint Protection 5.2.1 and earlier allows remote attackers to
bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain
execution policy using a cross-site scripting (XSS) attack, execute
arbitrary code using the MyASUtil.InstallInfo.RunUserProgram function,
and possibly conduct other unspecified attacks.
|
| CVE-2011-2999 |
Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before
6.0, and SeaMonkey before 2.3 do not properly handle "location" as the
name of a frame, which allows remote attackers to bypass the Same
Origin Policy via a crafted web site, a different vulnerability than
CVE-2010-0170.
|
| CVE-2011-2976 |
Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through
2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote
attackers to inject arbitrary web script or HTML via vectors involving
a BUGLIST cookie.
|
| CVE-2011-2958 |
Multiple cross-site scripting (XSS) vulnerabilities in Ecava
IntegraXor before 3.60 (Build 4080) allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-2938 |
Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php
in MantisBT before 1.2.7 allow remote attackers to inject arbitrary
web script or HTML via a parameter, as demonstrated by the project_id
parameter to search.php.
|
| CVE-2011-2937 |
Cross-site scripting (XSS) vulnerability in the UI messages
functionality in Roundcube Webmail before 0.5.4 allows remote
attackers to inject arbitrary web script or HTML via the _mbox
parameter to the default URI.
|
| CVE-2011-2932 |
Cross-site scripting (XSS) vulnerability in
activesupport/lib/active_support/core_ext/string/output_safety.rb in
Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before
3.1.0.rc5 allows remote attackers to inject arbitrary web script or
HTML via a malformed Unicode string, related to a "UTF-8 escaping
vulnerability."
|
| CVE-2011-2931 |
Cross-site scripting (XSS) vulnerability in the strip_tags helper in
actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in
Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before
3.1.0.rc5 allows remote attackers to inject arbitrary web script or
HTML via a tag with an invalid name.
|
| CVE-2011-2927 |
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1.6,
as used in Red Hat Network (RHN) Satellite, allow remote attackers to
inject arbitrary web script or HTML via vectors related to Search
forms.
|
| CVE-2011-2920 |
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1.6,
as used in Red Hat Network (RHN) Satellite, allow remote attackers to
inject arbitrary web script or HTML via the "Filter by Synopsis" field
and other unspecified filter forms.
|
| CVE-2011-2919 |
Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in
Red Hat Network (RHN) Satellite, allows remote attackers to inject
arbitrary web script or HTML via the QueryString to the
SystemGroupList.do page.
|
| CVE-2011-2904 |
Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix
before 1.8.6 allows remote attackers to inject arbitrary web script or
HTML via the backurl parameter.
|
| CVE-2011-2771 |
Multiple cross-site scripting (XSS) vulnerabilities in Mahara before
1.4.1 allow remote attackers to inject arbitrary web script or HTML
via vectors related to (1) URI attributes and (2) the External Feed
component, as demonstrated by the guid element in an RSS feed.
|
| CVE-2011-2770 |
Cross-site scripting (XSS) vulnerability in man2html.cgi.c in man2html
1.6, and possibly other version, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors related to error
messages.
|
| CVE-2011-2754 |
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page
Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as
used in IBM Web Content Manager (WCM) and other products, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-2743 |
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the action parameter to (1) the default URI or (2)
includes/javascript.php, or the (3) title or (4) body parameter to
admin/help.php.
|
| CVE-2011-2712 |
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before
1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote
attackers to inject arbitrary web script or HTML via unspecified
parameters.
|
| CVE-2011-2711 |
Cross-site scripting (XSS) vulnerability in the print_fileinfo
function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote
authenticated users to inject arbitrary web script or HTML via the
filename associated with the rename hint.
|
| CVE-2011-2710 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.7.0 allow remote attackers to inject arbitrary web script or HTML
via (1) the URI to includes/application.php, reachable through
index.php; and, when Internet Explorer or Konqueror is used, (2) allow
remote attackers to inject arbitrary web script or HTML via the
searchword parameter in a search action to index.php in the com_search
component. NOTE: vector 2 exists because of an incomplete fix for
CVE-2011-2509.5.
|
| CVE-2011-2694 |
Cross-site scripting (XSS) vulnerability in the chg_passwd function in
web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x
before 3.5.10 allows remote authenticated administrators to inject
arbitrary web script or HTML via the username parameter to the passwd
program (aka the user field to the Change Password page).
|
| CVE-2011-2679 |
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Web
Access 1.4.x before 1.4.0.4 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-2675 |
Cross-site scripting (XSS) vulnerability in Enkai-kun before 110916
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-2673 |
Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-2672 |
Cross-site scripting (XSS) vulnerability in SemanticScuttle before
0.98 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2011-2661 |
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in
Novell GroupWise 8.0 before HP3 allow remote attackers to inject
arbitrary web script or HTML via the (1) Directory.Item.name or (2)
Directory.Item.displayName parameter.
|
| CVE-2011-2652 |
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as
used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to
inject arbitrary web script or HTML via a crafted archive file list
that is used in an overlay file.
|
| CVE-2011-2650 |
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as
used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to
inject arbitrary web script or HTML via a crafted pattern name that is
included in an RPM info display.
|
| CVE-2011-2644 |
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as
used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, related
to an RPM info display.
|
| CVE-2011-2642 |
Multiple cross-site scripting (XSS) vulnerabilities in the table Print
view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3
and 3.4.x before 3.4.3.2 allow remote authenticated users to inject
arbitrary web script or HTML via a crafted table name.
|
| CVE-2011-2609 |
Opera before 11.50 does not properly restrict data: URIs, which makes
it easier for remote attackers to conduct cross-site scripting (XSS)
attacks via a crafted web site.
|
| CVE-2011-2607 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert
(RTC) 3.0 allows remote attackers to inject arbitrary web script or
HTML via an unspecified parameter, aka Work Item 165513.
|
| CVE-2011-2606 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Rational
Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web
script or HTML via an unspecified parameter, aka Work Item 165511.
|
| CVE-2011-2545 |
Cross-site scripting (XSS) vulnerability in the SIP implementation on
the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102
before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote
attackers to inject arbitrary web script or HTML via the FROM field of
an INVITE message, aka Bug IDs CSCtr27277, CSCtr27256, CSCtr27274, and
CSCtr14715.
|
| CVE-2011-2544 |
Cross-site scripting (XSS) vulnerability in the web interface in Cisco
TelePresence System MXP Series F9.1 and earlier allows remote
authenticated users to inject arbitrary web script or HTML via a
crafted Call ID, as demonstrated by resultant cross-site request
forgery (CSRF) attacks that change passwords or cause a denial of
service, aka Bug ID CSCtq46488.
|
| CVE-2011-2510 |
Cross-site scripting (XSS) vulnerability in the RSS embedding feature
in DokuWiki before 2011-05-25a Rincewind allows remote attackers to
inject arbitrary web script or HTML via a link.
|
| CVE-2011-2509 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.6.4 allow remote attackers to inject arbitrary web script or HTML
via (1) the query string to the com_contact component, as demonstrated
by the Itemid parameter to index.php; (2) the query string to the
com_content component, as demonstrated by the filter_order parameter
to index.php; (3) the query string to the com_newsfeeds component, as
demonstrated by an arbitrary parameter to index.php; or (4) the option
parameter in a reset.request action to index.php; and, when Internet
Explorer or Konqueror is used, (5) allow remote attackers to inject
arbitrary web script or HTML via the searchword parameter in a search
action to index.php in the com_search component.
|
| CVE-2011-2505 |
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication
feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1
assigns values to arbitrary parameters referenced in the query string,
which allows remote attackers to modify the SESSION superglobal array
via a crafted request, related to a "remote variable manipulation
vulnerability."
|
| CVE-2011-2477 |
Multiple cross-site scripting (XSS) vulnerabilities in config.c in
config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled,
allow remote attackers to inject arbitrary web script or HTML via a
JavaScript expression, as demonstrated by the onload attribute of a
BODY element located after a check-host-alive! sequence, a different
vulnerability than CVE-2011-2179.
|
| CVE-2011-2476 |
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery
(CPG) before 1.5.12 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2010-4667.
|
| CVE-2011-2470 |
Cross-site scripting (XSS) vulnerability in chat/base/admin/login.php
in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to
inject arbitrary web script or HTML via the arsc_message parameter.
|
| CVE-2011-2463 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0
through 9.0.1 allows remote attackers to inject arbitrary web script
or HTML via vectors involving the cfform tag.
|
| CVE-2011-2461 |
Cross-site scripting (XSS) vulnerability in the Adobe Flex SDK 3.x and
4.x before 4.6 allows remote attackers to inject arbitrary web script
or HTML via vectors related to the loading of modules from different
domains.
|
| CVE-2011-2444 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before
10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before
10.3.186.7 on Android, allows remote attackers to inject arbitrary web
script or HTML via a crafted URL, related to a "universal cross-site
scripting issue," as exploited in the wild in September 2011.
|
| CVE-2011-2410 |
Cross-site scripting (XSS) vulnerability in HP OpenView Performance
Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2011-2409 |
Cross-site scripting (XSS) vulnerability in the Calendar application
in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-2408 |
Cross-site scripting (XSS) vulnerability in the Contacts application
in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-2406 |
Cross-site scripting (XSS) vulnerability in HP OpenView Performance
Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-2402 |
Cross-site scripting (XSS) vulnerability in HP Network Automation
7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-2400 |
Cross-site scripting (XSS) vulnerability in HP SiteScope 9.x, 10.x,
and 11.x allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2011-2379 |
Cross-site scripting (XSS) vulnerability in Bugzilla 2.4 through
2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before
3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3, when
Internet Explorer before 9 or Safari before 5.0.6 is used for Raw
Unified mode, allows remote attackers to inject arbitrary web script
or HTML via a crafted patch, related to content sniffing.
|
| CVE-2011-2369 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x
through 4.0.1 allows remote attackers to inject arbitrary web script
or HTML via an SVG element containing an HTML-encoded entity.
|
| CVE-2011-2227 |
Cross-site scripting (XSS) vulnerability in Novell Identity Manager
(aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and
4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0,
3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary
web script or HTML via the apwaDetail (aka apwaDetailId) parameter,
aka Bug 709603.
|
| CVE-2011-2226 |
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as
used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, related
to a pattern listing.
|
| CVE-2011-2224 |
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through
1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie
header, which makes it easier for remote attackers to conduct
cross-site scripting (XSS) attacks via unspecified vectors.
|
| CVE-2011-2197 |
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x
before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not
properly handle mutation of safe buffers, which makes it easier for
remote attackers to conduct XSS attacks via crafted strings to an
application that uses a problematic string method, as demonstrated by
the sub method.
|
| CVE-2011-2191 |
Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in
Cherokee before 1.2.99 allows remote attackers to hijack the
authentication of administrators for requests that insert cross-site
scripting (XSS) sequences, as demonstrated by a crafted nickname field
to vserver/apply.
|
| CVE-2011-2180 |
Cross-site scripting (XSS) vulnerability in dereferer.php in A Really
Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary
web script or HTML via the arsc_link parameter.
|
| CVE-2011-2179 |
Multiple cross-site scripting (XSS) vulnerabilities in config.c in
config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow
remote attackers to inject arbitrary web script or HTML via the expand
parameter, as demonstrated by an (a) command action or a (b) hosts
action.
|
| CVE-2011-2172 |
Cross-site scripting (XSS) vulnerability in the search center in IBM
WebSphere Portal 7.0.0.1 before CF004 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-2133 |
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9
before 9.0.1.262, and RoboHelp Server 8 and 9, allows remote attackers
to inject arbitrary web script or HTML via the URI, related to
template_stock/whutils.js.
|
| CVE-2011-2107 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before
10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22
and earlier on Android, allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, related to a "universal
cross-site scripting vulnerability."
|
| CVE-2011-2087 |
Multiple cross-site scripting (XSS) vulnerabilities in component
handlers in the javatemplates (aka Java Templates) plugin in Apache
Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web
script or HTML via an arbitrary parameter value to a .action URI,
related to improper handling of value attributes in (1)
FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java,
(4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java,
(7) SubmitHandler.java, and (8) TextFieldHandler.java.
|
| CVE-2011-2083 |
Multiple cross-site scripting (XSS) vulnerabilities in Best Practical
Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2011-2078 |
Multiple cross-site scripting (XSS) vulnerabilities in the New Atlanta
BlueDragon administrative interface in MediaCAST 8 and earlier allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-2023 |
Cross-site scripting (XSS) vulnerability in functions/mime.php in
SquirrelMail before 1.4.22 allows remote attackers to inject arbitrary
web script or HTML via a crafted STYLE element in an e-mail message.
|
| CVE-2011-2020 |
Cross-site scripting (XSS) vulnerability in TIBCO iProcess Engine
before 11.1.3 and iProcess Workspace before 11.3.1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2011-1992 |
The XSS Filter in Microsoft Internet Explorer 8 allows remote
attackers to read content from a different (1) domain or (2) zone via
a "trial and error" attack, aka "XSS Filter Information Disclosure
Vulnerability."
|
| CVE-2011-1976 |
Cross-site scripting (XSS) vulnerability in the Report Viewer Control
in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows
remote attackers to inject arbitrary web script or HTML via a
parameter in a data source, aka "Report Viewer Controls XSS
Vulnerability."
|
| CVE-2011-1953 |
Multiple cross-site scripting (XSS) vulnerabilities in common.php in
Post Revolution before 0.8.0c-2 allow remote attackers to inject
arbitrary web script or HTML via an attribute of a (1) P, a (2)
STRONG, a (3) A, a (4) EM, a (5) I, a (6) IMG, a (7) LI, an (8) OL, a
(9) VIDEO, or a (10) BLOCKQUOTE element.
|
| CVE-2011-1950 |
plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users
to modify the properties of arbitrary accounts via unspecified
vectors, as exploited in the wild in June 2011.
|
| CVE-2011-1949 |
Cross-site scripting (XSS) vulnerability in the safe_html filter in
Products.PortalTransforms in Plone 2.1 through 4.1 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2010-2422.
|
| CVE-2011-1948 |
Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
crafted URL.
|
| CVE-2011-1940 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to
inject arbitrary web script or HTML via a crafted table name that
triggers improper HTML rendering on a Tracking page, related to (1)
libraries/tbl_links.inc.php and (2) tbl_tracking.php.
|
| CVE-2011-1937 |
Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier
allows local users to inject arbitrary web script or HTML via a chfn
command that changes the real (aka Full Name) field, related to
useradmin/index.cgi and useradmin/user-lib.pl.
|
| CVE-2011-1899 |
Multiple cross-site scripting (XSS) vulnerabilities in CA eHealth
6.0.x, 6.1.x, 6.2.1, and 6.2.2 allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters.
|
| CVE-2011-1897 |
Cross-site scripting (XSS) vulnerability in Microsoft Forefront
Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, aka "Default Reflected XSS Vulnerability."
|
| CVE-2011-1896 |
Cross-site scripting (XSS) vulnerability in Microsoft Forefront
Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
|
| CVE-2011-1895 |
CRLF injection vulnerability in Microsoft Forefront Unified Access
Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote
attackers to inject arbitrary HTTP headers, and conduct HTTP response
splitting attacks and cross-site scripting (XSS) attacks, via
unspecified vectors, aka "ExcelTable Response Splitting XSS
Vulnerability."
|
| CVE-2011-1894 |
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3,
Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server
2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not
properly handle a MIME format in a request for embedded content in an
HTML document, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via a crafted EMBED element in a web page that
is visited in Internet Explorer, aka "MHTML Mime-Formatted Request
Vulnerability."
|
| CVE-2011-1893 |
Cross-site scripting (XSS) vulnerability in Microsoft Office
SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2,
and SharePoint Foundation 2010 allows remote attackers to inject
arbitrary web script or HTML via the URI, aka "SharePoint XSS
Vulnerability."
|
| CVE-2011-1891 |
Cross-site scripting (XSS) vulnerability in Microsoft Windows
SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and
SP1, allows remote attackers to inject arbitrary web script or HTML
via unspecified parameters in a request to a script, aka "Contact
Details Reflected XSS Vulnerability."
|
| CVE-2011-1890 |
Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft
Office SharePoint Server 2010 and SharePoint Foundation 2010 allows
remote attackers to inject arbitrary web script or HTML via a post,
aka "Editform Script Injection Vulnerability."
|
| CVE-2011-1862 |
Cross-site scripting (XSS) vulnerability in HP Service Manager 7.02,
7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1856 |
Cross-site scripting (XSS) vulnerability in HP Business Availability
Center (BAC) 8.06 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1841 |
Cross-site scripting (XSS) vulnerability in the link_to helper in
Mojolicious before 1.12 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2011-1838 |
Multiple cross-site scripting (XSS) vulnerabilities in
TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to
inject arbitrary web script or HTML via the origurl parameter to a (1)
view script or (2) login script.
|
| CVE-2011-1825 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Administrative Console in CA Arcot WebFort Versatile Authentication
Server (VAS) before 6.2.5 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2011-1772 |
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache
Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony
WebWork, allow remote attackers to inject arbitrary web script or HTML
via vectors involving (1) an action name, (2) the action attribute of
an s:submit element, or (3) the method attribute of an s:submit
element.
|
| CVE-2011-1765 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5,
when Internet Explorer 6 or earlier is used, allows remote attackers
to inject arbitrary web script or HTML via an uploaded file accessed
with a dangerous extension such as .shtml at the end of the query
string, in conjunction with a modified URI path that has a %2E
sequence in place of the . (dot) character. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2011-1578 and
CVE-2011-1587.
|
| CVE-2011-1743 |
Cross-site scripting (XSS) vulnerability in EMC Captiva eInput 2.1.1
before 2.1.1.37 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2011-1737 |
Multiple cross-site scripting (XSS) vulnerabilities in the Email
application in HP Palm webOS 1.4.5 and 1.4.5.1 allow remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1727 |
Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13,
11.01, and 11.1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, related to an "HTML injection" issue.
|
| CVE-2011-1726 |
Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13,
11.01, and 11.1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2011-1723 |
Cross-site scripting (XSS) vulnerability in
app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows
remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details
are obtained from third party information.
|
| CVE-2011-1716 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in
Xymon before 4.3.1 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2011-1714 |
Cross-site scripting (XSS) vulnerability in
framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3
and possibly other versions, as used in eyeOS 2.2 and 2.3, and
possibly other products allows remote attackers to inject arbitrary
web script or HTML via the callback parameter.
|
| CVE-2011-1696 |
Cross-site scripting (XSS) vulnerability in Novell Identity Manager
(aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and
4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0,
3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary
web script or HTML via the apwaDetail (aka apwaDetailId) parameter,
aka Bug 692972.
|
| CVE-2011-1689 |
Multiple cross-site scripting (XSS) vulnerabilities in Best Practical
Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc
through 4.0.0rc7 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2011-1682 |
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList
2.10.13 and earlier allow remote attackers to hijack the
authentication of administrators for requests that (1) create a list
or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue
exists because of an incomplete fix for CVE-2011-0748. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2011-1671 |
Cross-site scripting (XSS) vulnerability in
app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and
2.0devel allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to todos/tag/. NOTE: some of these details are
obtained from third party information.
|
| CVE-2011-1670 |
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra
Blog Machine 1.84, and possibly earlier versions, allows remote
attackers to inject arbitrary web script or HTML via the subject
parameter to post_url/edit.
|
| CVE-2011-1668 |
Cross-site scripting (XSS) vulnerability in search.php in AR Web
Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows
remote attackers to inject arbitrary web script or HTML via the search
parameter.
|
| CVE-2011-1662 |
Cross-site scripting (XSS) vulnerability in Translation Management
module 6.x before 6.x-1.21 for Drupal allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1660 |
Multiple cross-site scripting (XSS) vulnerabilities in the
DataDynamics.Reports.Web class library in GrapeCity Data Dynamics
Reports before 1.6.2084.14 allow remote attackers to inject arbitrary
web script or HTML via (1) the reportName or (2) uniqueId parameter to
CoreViewerInit.js, or the (3) uniqueId or (4) traceLevel parameter to
CoreController.js, as reachable by CoreHandler.ashx.
|
| CVE-2011-1587 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.4,
when Internet Explorer 6 or earlier is used, allows remote attackers
to inject arbitrary web script or HTML via an uploaded file accessed
with a dangerous extension such as .html located before a ? (question
mark) in a query string, in conjunction with a modified URI path that
has a %2E sequence in place of the . (dot) character. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2011-1578.
|
| CVE-2011-1579 |
The checkCss function in includes/Sanitizer.php in the wikitext parser
in MediaWiki before 1.16.3 does not properly validate Cascading Style
Sheets (CSS) token sequences, which allows remote attackers to conduct
cross-site scripting (XSS) attacks or obtain sensitive information by
using the \2f\2a and \2a\2f hex strings to surround CSS comments.
|
| CVE-2011-1578 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3,
when Internet Explorer 6 or earlier is used, allows remote attackers
to inject arbitrary web script or HTML via an uploaded file accessed
with a dangerous extension such as .html at the end of the query
string, in conjunction with a modified URI path that has a %2E
sequence in place of the . (dot) character.
|
| CVE-2011-1570 |
Cross-site scripting (XSS) vulnerability in Liferay Portal Community
Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows
remote authenticated users to inject arbitrary web script or HTML via
a message title, a different vulnerability than CVE-2004-2030.
|
| CVE-2011-1558 |
Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web
Interface for Content Management (aka WEBi) 1.0.4 before FP3 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2010-1242.
|
| CVE-2011-1542 |
Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager
(SIM) before 6.3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2011-1537 |
Cross-site scripting (XSS) vulnerability in HP Proliant Support Pack
(PSP) before 8.7 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2011-1533 |
Cross-site scripting (XSS) vulnerability on the HP Photosmart D110 and
B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One,
and C510; and ENVY 100 D410 printers allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1524 |
Cross-site scripting (XSS) vulnerability in the management login GUI
page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows
remote attackers to inject arbitrary web script or HTML via the
username field, as demonstrated by injecting an IFRAME element into
the event log, a different vulnerability than CVE-2011-0545.
|
| CVE-2011-1523 |
Cross-site scripting (XSS) vulnerability in statusmap.c in
statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to
inject arbitrary web script or HTML via the layer parameter.
|
| CVE-2011-1518 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket
Request System (OTRS) 2.4.x before 2.4.10 and 3.x before 3.0.7 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-1510 |
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in
ManageEngine ServiceDesk Plus (SDP) before 8012 allows remote
attackers to inject arbitrary web script or HTML via the searchText
parameter.
|
| CVE-2011-1504 |
Cross-site scripting (XSS) vulnerability in Liferay Portal Community
Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated
users to inject arbitrary web script or HTML via a blog title.
|
| CVE-2011-1481 |
Multiple cross-site scripting (XSS) vulnerabilities in Francisco Burzi
PHP-Nuke 8.0 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) sender_name or (2) sender_email
parameter in a Feedback action to modules.php.
|
| CVE-2011-1427 |
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite
5.5.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) Language parameter to Pages/login.aspx, (2) HeaderWarning
parameter to Troubleshooting/DiagnosticReport.asp, or (3) User-Agent
header to troubleshooting/speedtest.asp.
|
| CVE-2011-1423 |
Cross-site scripting (XSS) vulnerability in RSA Data Loss Prevention
(DLP) Enterprise Manager 8.x before 8.5 SP1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1422 |
Cross-site scripting (XSS) vulnerability in an unspecified Shockwave
Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x,
5.7.x, and 6.x allows remote attackers to inject arbitrary web script
or HTML via unknown vectors.
|
| CVE-2011-1414 |
Cross-site scripting (XSS) vulnerability in the tibbr web server, as
used in TIBCO tibbr 1.0.0 through 1.5.0 and tibbr Service 1.0.0
through 1.5.0, allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2011-1405 |
Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows
remote authenticated users to inject arbitrary web script or HTML via
vectors associated with HTML e-mail messages, related to
artefact/comment/lib.php and interaction/forum/lib.php.
|
| CVE-2011-1401 |
ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber
plugin is enabled during processing of the "meta stylesheet"
directive, which allows remote authenticated users to conduct
cross-site scripting (XSS) attacks via crafted Cascading Style Sheets
(CSS) token sequences in (1) the default stylesheet or (2) an
alternate stylesheet.
|
| CVE-2011-1396 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset
Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows
remote attackers to inject arbitrary web script or HTML via the
reportType parameter to an unspecified component.
|
| CVE-2011-1395 |
Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo
Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5
allows remote attackers to inject arbitrary web script or HTML via the
controlid parameter.
|
| CVE-2011-1371 |
Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM
WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to
inject arbitrary web script or HTML via vectors that trigger an
Unknown Error document, a different vulnerability than CVE-2011-4171.
|
| CVE-2011-1362 |
Cross-site scripting (XSS) vulnerability in the Installation
Verification Test (IVT) application in the Install component in IBM
WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before
7.0.0.19 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2011-1308.
|
| CVE-2011-1360 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server
2.0.47 and earlier, as used in WebSphere Application Server and other
products, allow remote attackers to inject arbitrary web script or
HTML via vectors involving unspecified documentation files in (1)
manual/ibm/ and (2) htdocs/*/manual/ibm/.
|
| CVE-2011-1357 |
Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web
UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before
6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote
attackers to inject arbitrary web script or HTML via the User-Agent
HTTP header.
|
| CVE-2011-1340 |
Cross-site scripting (XSS) vulnerability in
skins/plone_templates/default_error_message.pt in Plone before 2.5.3
allows remote attackers to inject arbitrary web script or HTML via the
type_name parameter to Members/ipa/createObject.
|
| CVE-2011-1339 |
Cross-site scripting (XSS) vulnerability in Google Search Appliance
before 5.0 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2011-1335 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, 7, and 8
before 8.1.1 allows remote attackers to inject arbitrary web script or
HTML via vectors related to the "address book and user list
functions."
|
| CVE-2011-1334 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, Cybozu
Garoon 2.0.0 through 2.1.3, Cybozu Dezie before 6.1, Cybozu MailWise
before 3.1, and Cybozu Collaborex before 1.5 allows remote attackers
to inject arbitrary web script or HTML via vectors related to
"downloading graphic files from the mail system."
|
| CVE-2011-1333 |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6 and Cybozu
Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary
web script or HTML via vectors related to "downloading graphic files
from the bulletin board system."
|
| CVE-2011-1332 |
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0
through 2.1.3 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, a different vulnerability than
CVE-2008-6570.
|
| CVE-2011-1330 |
Cross-site scripting (XSS) vulnerability in WeblyGo 5.0 Pro/LE, 5.02
Pro/LE, 5.03 Pro/LE, 5.04 Pro/LE, and 5.10 Pro/LE allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2011-1308 |
Cross-site scripting (XSS) vulnerability in the Installation
Verification Test (IVT) application in the Install component in IBM
WebSphere Application Server (WAS) before 7.0.0.15 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2011-1295 |
WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari
before 5.0.6, does not properly handle node parentage, which allows
remote attackers to cause a denial of service (DOM tree corruption),
conduct cross-site scripting (XSS) attacks, or possibly have
unspecified other impact via unknown vectors.
|
| CVE-2011-1264 |
Cross-site scripting (XSS) vulnerability in Active Directory
Certificate Services Web Enrollment in Microsoft Windows Server 2003
SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers
to inject arbitrary web script or HTML via an unspecified parameter,
aka "Active Directory Certificate Services Vulnerability."
|
| CVE-2011-1263 |
Cross-site scripting (XSS) vulnerability in the logon page in Remote
Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2
and R2 SP1 allows remote attackers to inject arbitrary web script or
HTML via the URI, aka "Remote Desktop Web Access Vulnerability."
|
| CVE-2011-1252 |
Cross-site scripting (XSS) vulnerability in the SafeHTML function in
the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office
SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and
SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0
SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote
attackers to inject arbitrary web script or HTML via unspecified
strings, aka "toStaticHTML Information Disclosure Vulnerability" or
"HTML Sanitization Vulnerability."
|
| CVE-2011-1168 |
Cross-site scripting (XSS) vulnerability in the KHTMLPart::htmlError
function in khtml/khtml_part.cpp in Konqueror in KDE SC 4.4.0 through
4.6.1 allows remote attackers to inject arbitrary web script or HTML
via the URI in a URL corresponding to an unavailable web site.
|
| CVE-2011-1158 |
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal
Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1
allows remote attackers to inject arbitrary web script or HTML via an
unexpected URI scheme, as demonstrated by a javascript: URI.
|
| CVE-2011-1157 |
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal
Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1
allows remote attackers to inject arbitrary web script or HTML via
malformed XML comments.
|
| CVE-2011-1129 |
Cross-site scripting (XSS) vulnerability in the EditNews function in
ManageNews.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x
before 2.0 RC5, might allow remote authenticated users to inject
arbitrary web script or HTML via a save_items action.
|
| CVE-2011-1106 |
Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server
in IBM Lotus Sametime allows remote attackers to inject arbitrary web
script or HTML via the authReasonCode parameter in an OpenDatabase
action.
|
| CVE-2011-1105 |
Multiple cross-site scripting (XSS) vulnerabilities in Mutare EVM
allow remote attackers to inject arbitrary web script or HTML via (1)
a delivery address and possibly (2) a PIN.
|
| CVE-2011-1102 |
Cross-site scripting (XSS) vulnerability in the WebReporting module in
F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix
3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on
Windows and hotfix 2 on Linux, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1077 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva
1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1066 |
Cross-site scripting (XSS) vulnerability in the Messaging module
6.x-2.x before 6.x-2.4 and 6.x-4.x before 6.x-4.0-beta8 for Drupal
allows remote attackers with administer messaging permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1063 |
Multiple cross-site scripting (XSS) vulnerabilities in Cherry-Design
Photopad 1.2.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) id or (2) data[title] parameters in an edit action
to files.php, or (3) id parameter in a view action to gallery.php.
|
| CVE-2011-1062 |
Multiple cross-site scripting (XSS) vulnerabilities in
include/html/header.php in TaskFreak! 0.6.4 allow remote attackers to
inject arbitrary web script or HTML via the (1) sContext, (2) sort,
(3) dir, and (4) show parameters in a save action to index.php; the
(5) dir and (6) show parameters to print_list.php; and the (7) HTTP
referer header to rss.php. NOTE: some of these details are obtained
from third party information.
|
| CVE-2011-1058 |
Cross-site scripting (XSS) vulnerability in the reStructuredText (rst)
parser in parser/text_rst.py in MoinMoin before 1.9.3, when docutils
is installed or when "format rst" is set, allows remote attackers to
inject arbitrary web script or HTML via a javascript: URL in the
refuri attribute. NOTE: some of these details are obtained from third
party information.
|
| CVE-2011-1038 |
Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in
the server in IBM Lotus Sametime 8.0.1 allow remote attackers to
inject arbitrary web script or HTML via (1) the messageString
parameter in a WebMessage action or (2) the PATH_INFO.
|
| CVE-2011-1034 |
Cross-site scripting (XSS) vulnerability in the UI in IBM Rational
Build Forge 7.0.2 allows remote attackers to inject arbitrary web
script or HTML via the mod parameter to the fullcontrol program. NOTE:
some of these details are obtained from third party information.
|
| CVE-2011-1030 |
Cross-site scripting (XSS) vulnerability in the Wikis component in IBM
Lotus Connections 3.0 allows remote attackers to inject arbitrary web
script or HTML via vectors related to the "Confirm New Page scene."
|
| CVE-2011-1029 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert
(RTC) 2.0.0.x allows remote authenticated users to inject arbitrary
web script or HTML via the name of a shared report.
|
| CVE-2011-0962 |
Cross-site scripting (XSS) vulnerability in
CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common
Services Device Center in Cisco Unified Operations Manager (CUOM)
before 8.6 allows remote attackers to inject arbitrary web script or
HTML via the tag parameter, aka Bug ID CSCto12712.
|
| CVE-2011-0961 |
Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in
the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
device parameter, aka Bug ID CSCto12704.
|
| CVE-2011-0959 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified
Operations Manager (CUOM) before 8.6 allow remote attackers to inject
arbitrary web script or HTML via (1) the extn parameter to
iptm/advancedfind.do, (2) the deviceInstanceName parameter to
iptm/ddv.do, the (3) cmd or (4) group parameter to iptm/eventmon, the
(5) clusterName or (6) deviceName parameter to
iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp, or the (7) ccmName or
(8) clusterName parameter to iptm/logicalTopo.do, aka Bug ID
CSCtn61716.
|
| CVE-2011-0911 |
Cross-site scripting (XSS) vulnerability in the Users module in Zikula
before 1.2.5 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors. NOTE: it is possible that this overlaps
CVE-2011-0535.
|
| CVE-2011-0909 |
Cross-site scripting (XSS) vulnerability in Vanilla Forums before
2.0.17.6 allows remote attackers to inject arbitrary web script or
HTML via the p parameter to an unspecified component, a different
vulnerability than CVE-2011-0526.
|
| CVE-2011-0898 |
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i
(NNMi) 9.00 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2011-0893 |
Cross-site scripting (XSS) vulnerability in HP Operations 9.10 on UNIX
platforms allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2011-0892 |
Cross-site scripting (XSS) vulnerability in HP Diagnostics 7.5x and
8.0x before 8.05.54.225 allows remote attackers to inject arbitrary
web script or HTML via unknown vectors.
|
| CVE-2011-0773 |
Cross-site scripting (XSS) vulnerability in
pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote
attackers to inject arbitrary web script or HTML via the image
parameter.
|
| CVE-2011-0772 |
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0,
and possibly other versions before 2.2.2, allow remote attackers to
inject arbitrary web script or HTML via the (1) color parameter to
includes/blogroll.php or (2) src parameter to includes/timwrapper.php.
|
| CVE-2011-0771 |
The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not
validate the file for a profile image, which allows remote
authenticated users to conduct cross-site scripting (XSS) attacks and
possibly execute arbitrary PHP code by causing a crafted avatar to be
downloaded from an external login provider site.
|
| CVE-2011-0770 |
Cross-site scripting (XSS) vulnerability in Windows Event Log
SmartConnector in HP ArcSight Connector Appliance before 6.1 allows
remote attackers to inject arbitrary web script or HTML via the
Windows XP variable in a file.
|
| CVE-2011-0767 |
Cross-site scripting (XSS) vulnerability in the management GUI in the
MX Management Server in Imperva SecureSphere Web Application Firewall
6.2, 7.x, and 8.x allows remote attackers to inject arbitrary web
script or HTML via an HTTP request to a firewalled server, aka Bug ID
31759.
|
| CVE-2011-0760 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
configuration screen in wp-relatedposts.php in the WP Related Posts
plugin 1.0 for WordPress allow remote attackers to hijack the
authentication of administrators for requests that insert cross-site
scripting (XSS) sequences via the (1) wp_relatedposts_title, (2)
wp_relatedposts_num, or (3) wp_relatedposts_type parameter.
|
| CVE-2011-0759 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
configuration page in the Recaptcha (aka WP-reCAPTCHA) plugin 2.9.8.2
for WordPress allow remote attackers to hijack the authentication of
administrators for requests that disable the CAPTCHA requirement or
insert cross-site scripting (XSS) sequences via the (1)
recaptcha_opt_pubkey, (2) recaptcha_opt_privkey, (3) re_tabindex, (4)
error_blank, (5) error_incorrect, (6) mailhide_pub, (7) mailhide_priv,
(8) mh_replace_link, or (9) mh_replace_title parameter.
|
| CVE-2011-0746 |
Cross-site request forgery (CSRF) vulnerability in
Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows
remote attackers to hijack the authentication of administrators for
requests that insert cross-site scripting (XSS) sequences via the
PortRule_Name parameter.
|
| CVE-2011-0741 |
Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution
before 1.0.5 allow remote attackers to inject arbitrary web script or
HTML via the (1) installer or (2) image editor.
|
| CVE-2011-0740 |
Cross-site scripting (XSS) vulnerability in
magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the rss_url parameter.
|
| CVE-2011-0735 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before
9.0.1 CHF1 allows remote attackers to inject arbitrary web script or
HTML via vectors involving a "tag script."
|
| CVE-2011-0734 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before
9.0.1 CHF1 allows remote attackers to inject arbitrary web script or
HTML via an id parameter containing a JavaScript onLoad event handler
for a BODY element, related to a "tag body" attack. NOTE: this was
originally reported as affecting 9.0.1 CHF1 and earlier.
|
| CVE-2011-0733 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before
9.0.1 CHF1 allows remote attackers to inject arbitrary web script or
HTML via the User-Agent HTTP header in an id=- query to a .cfm file.
|
| CVE-2011-0728 |
Cross-site scripting (XSS) vulnerability in templatefunctions.py in
Loggerhead before 1.18.1 allows remote authenticated users to inject
arbitrary web script or HTML via a filename, which is not properly
handled in a revision view.
|
| CVE-2011-0707 |
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py
in GNU Mailman 2.1.14 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) full name or (2) username
field in a confirmation message.
|
| CVE-2011-0700 |
Multiple cross-site scripting (XSS) vulnerabilities in WordPress
before 3.0.5 allow remote authenticated users to inject arbitrary web
script or HTML via vectors related to (1) the Quick/Bulk Edit title
(aka post title or post_title), (2) post_status, (3) comment_status,
(4) ping_status, and (5) escaping of tags within the tags meta box.
|
| CVE-2011-0697 |
Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4
and 1.2.x before 1.2.5 might allow remote attackers to inject
arbitrary web script or HTML via a filename associated with a file
upload.
|
| CVE-2011-0653 |
Cross-site scripting (XSS) vulnerability in Microsoft Office
SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010,
allows remote attackers to inject arbitrary web script or HTML via the
URI, aka "XSS in SharePoint Calendar Vulnerability."
|
| CVE-2011-0641 |
Multiple cross-site scripting (XSS) vulnerabilities in
wp-admin/admin.php in the StatPressCN plugin 1.9.0 for WordPress allow
remote attackers to inject arbitrary web script or HTML via the (1)
what1, (2) what2, (3) what3, (4) what4, and (5) what5 parameters.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2011-0613 |
Multiple cross-site scripting (XSS) vulnerabilities in RoboHelp 7 and
8, and RoboHelp Server 7 and 8, allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to (1)
wf_status.htm and (2) wf_topicfs.htm in
RoboHTML/WildFireExt/TemplateStock/.
|
| CVE-2011-0604 |
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat
10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows
and Mac OS X allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, a different vulnerability than
CVE-2011-0587.
|
| CVE-2011-0587 |
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat
10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows
and Mac OS X allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, a different vulnerability than
CVE-2011-0604.
|
| CVE-2011-0583 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0
through 9.0.1 allows remote attackers to inject arbitrary web script
or HTML via the cfform tag.
|
| CVE-2011-0580 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrator console in Adobe ColdFusion 8.0 through 9.0.1 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-0552 |
Multiple cross-site scripting (XSS) vulnerabilities in the management
console in Symantec IM Manager before 8.4.18 allow remote attackers to
inject arbitrary web script or HTML via the (1) refreshRateSetting
parameter to IMManager/Admin/IMAdminSystemDashboard.asp, the (2) nav
or (3) menuitem parameter to IMManager/Admin/IMAdminTOC_simple.asp, or
the (4) action parameter to IMManager/Admin/IMAdminEdituser.asp.
|
| CVE-2011-0550 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web
Interface in the Endpoint Protection Manager in Symantec Endpoint
Protection (SEP) 11.0.600x through 11.0.6300 allow remote attackers to
inject arbitrary web script or HTML via (1) the token parameter to
portal/Help.jsp or (2) the URI in a console/apps/sepm request.
|
| CVE-2011-0533 |
Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1
through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through
1.3.3 and 1.0 through 1.22 allows remote attackers to inject arbitrary
web script or HTML via a crafted parameter, related to the
autoIncludeParameters setting for the extremecomponents table.
|
| CVE-2011-0526 |
Cross-site scripting (XSS) vulnerability in index.php in Vanilla
Forums before 2.0.17 allows remote attackers to inject arbitrary web
script or HTML via the Target parameter in a /entry/signin action.
|
| CVE-2011-0509 |
Cross-site scripting (XSS) vulnerability in Vaadin before 6.4.9 allows
remote attackers to inject arbitrary web script or HTML via unknown
vectors related to the index page.
|
| CVE-2011-0508 |
Cross-site scripting (XSS) vulnerability in
system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly
other versions before 2.9.3, allows remote attackers to inject
arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header,
which is stored by system/libraries/Environment.php but not properly
handled by a comments action to main.php.
|
| CVE-2011-0504 |
Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6,
1.6.1, and probably earlier versions llow remote attackers to inject
arbitrary web script or HTML via the (1) status parameter to
admin/orders.php, (2) search parameter to admin/customers.php, or (3)
STORE_NAME parameter to admin/configuration.php.
|
| CVE-2011-0486 |
Cross-site scripting (XSS) vulnerability in cognos.cgi in IBM Cognos 8
Business Intelligence (BI) 8.4.1 before FP1 allows remote attackers to
inject arbitrary web script or HTML via the pathinfo parameter.
|
| CVE-2011-0462 |
Multiple cross-site scripting (XSS) vulnerabilities in the login page
in the webui component in SUSE openSUSE Build Service (OBS) before
2.1.6 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2011-0459 |
Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault
Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0
through 6.0 patch 2 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2011-0457 |
Cross-site scripting (XSS) vulnerability in e107 0.7.22 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2011-0455 |
Cross-site scripting (XSS) vulnerability in Things BBS before 2.0.3
and BBS Thread before 2.0.3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-0451 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
data/Smarty/templates/default/list.tpl and (2)
data/Smarty/templates/default/campaign/bloc/cart_tag.tpl in EC-CUBE
before 2.4.4 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2011-0446 |
Multiple cross-site scripting (XSS) vulnerabilities in the mail_to
helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when
javascript encoding is used, allow remote attackers to inject
arbitrary web script or HTML via a crafted (1) name or (2) email
value.
|
| CVE-2011-0439 |
Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7
and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web
script or HTML via the Pieforms select box.
|
| CVE-2011-0315 |
Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web
Container component in IBM WebSphere Application Server (WAS) 6.1
before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to
inject arbitrary web script or HTML via vectors related to the lack of
an error page for an application.
|
| CVE-2011-0286 |
Cross-site scripting (XSS) vulnerability in webdesktop/app in the
BlackBerry Web Desktop Manager component in Research In Motion (RIM)
BlackBerry Enterprise Server (BES) software before 5.0.2 MR5 and 5.0.3
before MR1, and BlackBerry Enterprise Server Express software 5.0.1
and 5.0.2, allows remote attackers to inject arbitrary web script or
HTML via the displayErrorMessage parameter in a ManageDevices action.
|
| CVE-2011-0280 |
Multiple cross-site scripting (XSS) vulnerabilities in HP Power
Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) the logType parameter to
Contents/exportlogs.asp, (2) the Id parameter to
Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to
Contents/applicationlogs.asp. NOTE: some of these details are obtained
from third party information.
|
| CVE-2011-0274 |
Cross-site scripting (XSS) vulnerability in HP Business Availability
Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business
Service Management (BSM) through 9.01, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-0242 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 5.0.6 allows remote attackers to inject arbitrary web script or
HTML via vectors involving a URL that contains a username.
|
| CVE-2011-0169 |
WebKit in Apple Safari before 5.0.4, when the Web Inspector is used,
does not properly handle the window.console._inspectorCommandLineAPI
property, which allows user-assisted remote attackers to bypass the
Same Origin Policy and conduct cross-site scripting (XSS) attacks via
a crafted web site.
|
| CVE-2011-0096 |
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3,
Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server
2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not
properly handle a MIME format in a request for content blocks in a
document, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via a crafted web site that is visited in
Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
|
| CVE-2011-0050 |
Cross-site scripting (XSS) vulnerability in the nonjs interface
(interfaces/nonjs.pm) in CGI:IRC before 0.5.10 allows remote attackers
to inject arbitrary web script or HTML via the R parameter.
|
| CVE-2011-0048 |
Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and
4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or
(2) data: URI in the URL (aka bug_file_loc) field, which allows remote
attackers to conduct cross-site scripting (XSS) attacks against
logged-out users via a crafted URI.
|
| CVE-2011-0047 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2
allows remote attackers to inject arbitrary web script or HTML via
crafted Cascading Style Sheets (CSS) comments, aka "CSS injection
vulnerability."
|
| CVE-2011-0013 |
Multiple cross-site scripting (XSS) vulnerabilities in the HTML
Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before
6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject
arbitrary web script or HTML, as demonstrated via the display-name
tag.
|
| CVE-2011-0005 |
Cross-site scripting (XSS) vulnerability in the com_search module for
Joomla! 1.0.x through 1.0.15 allows remote attackers to inject
arbitrary web script or HTML via the ordering parameter to index.php.
|
| CVE-2011-0004 |
Multiple cross-site scripting (XSS) vulnerabilities in Piwik before
1.1 allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-5322 |
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
search parameter in a search action to index.php.
|
| CVE-2010-5316 |
Cross-site scripting (XSS) vulnerability in as/index.php in SweetRice
CMS before 0.6.7.1 allows remote attackers to inject arbitrary web
script or HTML via a top_height cookie.
|
| CVE-2010-5314 |
Cross-site scripting (XSS) vulnerability in
controllers/home_controller.php in BEdita before 3.1 allows remote
attackers to inject arbitrary web script or HTML via the searchstring
parameter to news/index.
|
| CVE-2010-5312 |
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the
Dialog widget in jQuery UI before 1.10.0 allows remote attackers to
inject arbitrary web script or HTML via the title option.
|
| CVE-2010-5303 |
Cross-site scripting (XSS) vulnerability in the displayError function
in timthumb.php in TimThumb before 1.15 (r85), as used in multiple
products, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors related to $errorString.
|
| CVE-2010-5302 |
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb
before 1.15 as of 20100908 (r88), as used in multiple products, allows
remote attackers to inject arbitrary web script or HTML via the
QUERY_STRING.
|
| CVE-2010-5295 |
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in
WordPress before 3.0.2 might allow remote attackers to inject
arbitrary web script or HTML via a plugin's author field, which is not
properly handled during a Delete Plugin action.
|
| CVE-2010-5294 |
Multiple cross-site scripting (XSS) vulnerabilities in the
request_filesystem_credentials function in wp-admin/includes/file.php
in WordPress before 3.0.2 allow remote servers to inject arbitrary web
script or HTML by providing a crafted error message for a (1) FTP or
(2) SSH connection attempt.
|
| CVE-2010-5284 |
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive
0.6.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) User parameter in the edit user profile feature to
manageuser.php, (2) y parameter in a newcal action to manageajax.php,
and the (3) pic parameter to thumb.php.
|
| CVE-2010-5283 |
Cross-site request forgery (CSRF) vulnerability in OpenText ECM
(formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the
authentication of administrators for requests that change folder and
resource permissions.
|
| CVE-2010-5282 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM
(formerly Livelink ECM) 9.7.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) viewType and (2) sort
parameters in a browse action to livelink/livelink; and the (3)
nodeid, (4) setctx, and (5) support parameters to
livelinkdav/nodes/OOB_DAVWindow.html.
|
| CVE-2010-5275 |
Cross-site scripting (XSS) vulnerability in memcache_admin in the
Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-5192 |
Cross-site scripting (XSS) vulnerability in the Java Management
Console in Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS
5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-5100 |
Multiple cross-site scripting (XSS) vulnerabilities in the Install
Tool in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x
before 4.4.5 allow remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-5098 |
Cross-site scripting (XSS) vulnerability in the FORM content object in
TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5,
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2010-5097 |
Cross-site scripting (XSS) vulnerability in the click enlarge
functionality in TYPO3 4.3.x before 4.3.9 and 4.4.x before 4.4.5 when
the caching framework is enabled, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-5095 |
Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x before
2.3.6 allows remote attackers to inject arbitrary web script or HTML
via vectors related to DataObjectSet pagination.
|
| CVE-2010-5064 |
Multiple cross-site scripting (XSS) vulnerabilities in Virtual War
(aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web
script or HTML via (1) the Additional Information field to
challenge.php, the (2) Additional Information or (3) Contact
information field to joinus.php, (4) the War Report field to
admin/admin.php in a finishwar action, or (5) the Nick field to
profile.php.
|
| CVE-2010-5054 |
Cross-site scripting (XSS) vulnerability in Special:Login in JAMWiki
before 0.8.4 allows remote attackers to inject arbitrary web script or
HTML via the message parameter.
|
| CVE-2010-5052 |
Cross-site scripting (XSS) vulnerability in admin/components.php in
GetSimple CMS 2.01 allows remote attackers to inject arbitrary web
script or HTML via the val[] parameter.
|
| CVE-2010-5051 |
Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php
in razorCMS 1.0 stable allows remote attackers to inject arbitrary web
script or HTML via the content parameter in an edit action to
admin/index.php.
|
| CVE-2010-5050 |
Cross-site scripting (XSS) vulnerability in
jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0
allows remote attackers to inject arbitrary web script or HTML via the
computerName parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2010-5048 |
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the
JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla!
allows remote authenticated users to inject arbitrary web script or
HTML via the name parameter to index.php.
|
| CVE-2010-5046 |
Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows
remote attackers to inject arbitrary web script or HTML via the p
parameter.
|
| CVE-2010-5045 |
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart
ASP Survey allows remote attackers to inject arbitrary web script or
HTML via the catid parameter.
|
| CVE-2010-5042 |
Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery
(com_djartgallery) component 0.9.1 for Joomla! allows remote attackers
to inject arbitrary web script or HTML via the cid[] parameter in an
editItem action to administrator/index.php. NOTE: some of these
details are obtained from third party information.
|
| CVE-2010-5035 |
Cross-site scripting (XSS) vulnerability in search.php in iScripts
eSwap 2.0 allows remote attackers to inject arbitrary web script or
HTML via the txtHomeSearch parameter (aka the search field). NOTE:
some of these details are obtained from third party information.
|
| CVE-2010-5031 |
Cross-site scripting (XSS) vulnerability in index.php in fileNice 1.1
allows remote attackers to inject arbitrary web script or HTML via the
sstring parameter (aka the Search Box). NOTE: some of these details
are obtained from third party information.
|
| CVE-2010-5030 |
Cross-site scripting (XSS) vulnerability in index.php in Ecomat CMS
5.0 allows remote attackers to inject arbitrary web script or HTML via
the lang parameter in a web action.
|
| CVE-2010-5027 |
Cross-site scripting (XSS) vulnerability in winners.php in Science
Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to
inject arbitrary web script or HTML via the type parameter. NOTE: some
of these details are obtained from third party information.
|
| CVE-2010-5025 |
Cross-site scripting (XSS) vulnerability in manage/main.php in
CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject
arbitrary web script or HTML via the fld_path parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-5018 |
Cross-site scripting (XSS) vulnerability in
products/classified/headersearch.php in 2daybiz Online Classified
Script allows remote attackers to inject arbitrary web script or HTML
via the sid parameter.
|
| CVE-2010-5010 |
Cross-site scripting (XSS) vulnerability in
schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote
attackers to inject arbitrary web script or HTML via the session
parameter.
|
| CVE-2010-5007 |
Cross-site scripting (XSS) vulnerability in pages/match_report.php in
UTStats Beta 4 and earlier allows remote attackers to inject arbitrary
web script or HTML via the mid parameter.
|
| CVE-2010-5005 |
Cross-site scripting (XSS) vulnerability in
members/profileCommentsResponse.php in Rayzz Photoz allows remote
attackers to inject arbitrary web script or HTML via the
profileCommentTextArea parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2010-5002 |
Cross-site scripting (XSS) vulnerability in
modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows
remote attackers to inject arbitrary web script or HTML via the u
parameter.
|
| CVE-2010-4985 |
Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam
Notes Management System allows remote attackers to inject arbitrary
web script or HTML via vectors involving the "Enter Reference Number
Below" text box.
|
| CVE-2010-4978 |
Cross-site scripting (XSS) vulnerability in image/view.php in CANDID
allows remote attackers to inject arbitrary web script or HTML via the
image_id parameter.
|
| CVE-2010-4976 |
Cross-site scripting (XSS) vulnerability in search/search.php in
MetInfo 3.0 allows remote attackers to inject arbitrary web script or
HTML via the searchword parameter (aka Search Box field). NOTE: some
of these details are obtained from third party information.
|
| CVE-2010-4973 |
Cross-site scripting (XSS) vulnerability in the search feature in
Campsite 3.4.0 allows remote attackers to inject arbitrary web script
or HTML via the f_search_keywords parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2010-4971 |
Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way
Video Chat component for Joomla! allows remote attackers to inject
arbitrary web script or HTML via the r parameter to index.php.
|
| CVE-2010-4966 |
Cross-site scripting (XSS) vulnerability in default.asp in ATCOM
Netvolution allows remote attackers to inject arbitrary web script or
HTML via the query parameter in a Search action.
|
| CVE-2010-4960 |
Cross-site scripting (XSS) vulnerability in the Branchenbuch (aka
Yellow Pages or mh_branchenbuch) extension before 0.9.1 for TYPO3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-4958 |
SQL injection vulnerability in index.php in Prado Portal 1.2.0 allows
remote attackers to execute arbitrary SQL commands via the page
parameter.
|
| CVE-2010-4956 |
Cross-site scripting (XSS) vulnerability in the Questionnaire
(ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-4951 |
Cross-site scripting (XSS) vulnerability in the xaJax Shoutbox
(vx_xajax_shoutbox) extension before 1.0.1 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-4949 |
Cross-site scripting (XSS) vulnerability in the (1) FreiChat component
before 2.1.2 for Joomla! and the (2) FreiChatPure component before
1.2.2 for Joomla! allows remote attackers to inject arbitrary web
script or HTML by entering it in an unspecified window.
|
| CVE-2010-4947 |
Cross-site scripting (XSS) vulnerability in advanced_search_result.php
in ALLPC 2.5 allows remote attackers to inject arbitrary web script or
HTML via the keywords parameter.
|
| CVE-2010-4932 |
Cross-site scripting (XSS) vulnerability in search.php in Entrans
before 0.3.3 allows remote attackers to inject arbitrary web script or
HTML via the query parameter.
|
| CVE-2010-4930 |
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail
before 6.2.0 allows remote attackers to inject arbitrary web script or
HTML via the MailType parameter in a mail/auth/processlogin action.
|
| CVE-2010-4928 |
Cross-site scripting (XSS) vulnerability in the Restaurant Guide
(com_restaurantguide) component 1.0.0 for Joomla! allows remote
attackers to inject arbitrary web script or HTML by placing it after a
> (greater than) character.
|
| CVE-2010-4913 |
Cross-site scripting (XSS) vulnerability in the search feature in
ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary
web script or HTML via the Keywords parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2010-4909 |
Multiple cross-site scripting (XSS) vulnerabilities in
PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) q parameter to search.php or the (2) image
parameter to image.php.
|
| CVE-2010-4907 |
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in
Zenphoto 1.3 allows remote attackers to inject arbitrary web script or
HTML via the user parameter. NOTE: the from parameter is already
covered by CVE-2009-4562.
|
| CVE-2010-4903 |
SQL injection vulnerability in index.php in CubeCart 4.3.3 allows
remote attackers to execute arbitrary SQL commands via the searchStr
parameter.
|
| CVE-2010-4901 |
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in
MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web
script or HTML via the (1) height or (2) width parameter.
|
| CVE-2010-4896 |
Cross-site scripting (XSS) vulnerability in admin/index.asp in Member
Management System 4.0 allows remote attackers to inject arbitrary web
script or HTML via the REF_URL parameter.
|
| CVE-2010-4895 |
Cross-site scripting (XSS) vulnerability in core/showsite.php in
chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script
or HTML via the name parameter (aka the username field). NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-4893 |
Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS
2.3b allows remote attackers to inject arbitrary web script or HTML
via the category parameter in a details action.
|
| CVE-2010-4892 |
Cross-site scripting (XSS) vulnerability in the powermail extension
before 1.5.5 for TYPO3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-4890 |
Cross-site scripting (XSS) vulnerability in the Yet Another Calendar
(ke_yac) extension before 1.1.2 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4886 |
Cross-site scripting (XSS) vulnerability in the "official twitter
tweet button for your page" (tweetbutton) extension before 1.0.5 for
TYPO3 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2010-4885 |
Cross-site scripting (XSS) vulnerability in the XING Button (xing)
extension before 1.0.2 for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4883 |
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx
Revolution 2.0.2-pl allows remote attackers to inject arbitrary web
script or HTML via the modhash parameter.
|
| CVE-2010-4882 |
Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS
1.6 allows remote attackers to inject arbitrary web script or HTML via
the sitetitle parameter.
|
| CVE-2010-4881 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote
attackers to hijack the authentication of unspecified victims for
requests that use the (1) category_name, (2) category_description, (3)
event_name, or (4) event_description parameter.
|
| CVE-2010-4880 |
Multiple cross-site scripting (XSS) vulnerabilities in
calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote
attackers to inject arbitrary web script or HTML via the (1)
category_name, (2) category_description, (3) event_name, or (4)
event_description parameter.
|
| CVE-2010-4877 |
Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1
allows remote attackers to inject arbitrary web script or HTML via the
view parameter.
|
| CVE-2010-4875 |
Cross-site scripting (XSS) vulnerability in
vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video
Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the gid parameter.
|
| CVE-2010-4874 |
Multiple cross-site scripting (XSS) vulnerabilities in users.php in
NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script
or HTML via the (1) first_name, (2) last_name, (3) msn, or (4) aim
parameter.
|
| CVE-2010-4873 |
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5
P1 allows remote attackers to inject arbitrary web script or HTML via
the id parameter.
|
| CVE-2010-4868 |
Cross-site scripting (XSS) vulnerability in search.php3 (aka
search.php) in W-Agora 4.2.1 and earlier allows remote attackers to
inject arbitrary web script or HTML via the bn parameter.
|
| CVE-2010-4863 |
Cross-site scripting (XSS) vulnerability in admin/changedata.php in
GetSimple CMS 2.01 allows remote attackers to inject arbitrary web
script or HTML via the post-title parameter.
|
| CVE-2010-4852 |
Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b
allows remote attackers to inject arbitrary web script or HTML via the
reason parameter in a fail action.
|
| CVE-2010-4850 |
Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03
allow remote attackers to inject arbitrary web script or HTML via the
(1) post_content parameter to post/edit/2/p1.html, related to
views/post.php; the (2) slogan parameter to admin/site/2.html, related
to views/admin.php; or the (3) subcatname or (4) description parameter
to admin/forum/create_sub.html, related to views/admin.php.
|
| CVE-2010-4848 |
Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in
AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web
script or HTML via the (1) url or (2) title parameter.
|
| CVE-2010-4841 |
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine
EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile,
(5) load, (6) type, or (7) tab parameter to INDEX.do, the (8) reported
parameter to INDEX2.do, the (9) gId parameter to hostlist.do, the (10)
newWindow parameter to globalSettings.do, or the (11) STATUS parameter
to enableHost.do.
|
| CVE-2010-4837 |
Cross-site scripting (XSS) vulnerability in the JSupport
(com_jsupport) component 1.5.6 for Joomla! allows remote attackers to
inject arbitrary web script or HTML via the subject parameter (title
field) in a saveTicket action to index2.php. NOTE: some of these
details are obtained from third party information.
|
| CVE-2010-4836 |
Cross-site scripting (XSS) vulnerability in register.html in PHPShop
2.1 EE and earlier allows remote attackers to inject arbitrary web
script or HTML via the name_new parameter.
|
| CVE-2010-4828 |
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds
Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to
inject arbitrary web script or HTML via the (1) Title parameter to
MapView.aspx; NetObject parameter to (2) NodeDetails.aspx and (3)
InterfaceDetails.aspx; and the (4) ChartName parameter to
CustomChart.aspx.
|
| CVE-2010-4827 |
Cross-site scripting (XSS) vulnerability in members.asp in Snitz
Forums 2000 3.4.07 allows remote attackers to inject arbitrary web
script or HTML via the M_NAME parameter. NOTE: some of these details
are obtained from third party information.
|
| CVE-2010-4825 |
Cross-site scripting (XSS) vulnerability in magpie_debug.php in the
Twitter Feed plugin (wp-twitter-feed) 0.3.1 for WordPress allows
remote attackers to inject arbitrary web script or HTML via the url
parameter.
|
| CVE-2010-4823 |
Cross-site scripting (XSS) vulnerability in the httpError method in
sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before
2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used,
allows remote attackers to inject arbitrary web script or HTML via
"missing URL actions."
|
| CVE-2010-4821 |
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to index.php.
|
| CVE-2010-4813 |
Cross-site scripting (XSS) vulnerability in the Category Tokens module
6.x before 6.x-1.1 for Drupal allows remote authenticated users with
administer taxonomy permissions to inject arbitrary web script or HTML
by editing or creating vocabulary names, which are not properly
handled in token help.
|
| CVE-2010-4811 |
Multiple cross-site scripting (XSS) vulnerabilities in ajaxmember.php
in 6kbbs 8.0 build 20100901 allow remote attackers to inject arbitrary
web script or HTML via the (1) user[msn], (2) user[email], and (3)
user[phone] parameters in a modifyDetails action.
|
| CVE-2010-4794 |
Multiple cross-site scripting (XSS) vulnerabilities in the
JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4
for Joomla! allow remote attackers to inject arbitrary web script or
HTML via the (1) month and (2) year parameters in a jscalendar action
to index.php. NOTE: some of these details are obtained from third
party information.
|
| CVE-2010-4792 |
Cross-site scripting (XSS) vulnerability in title.php in OPEN IT
OverLook 5.0 allows remote attackers to inject arbitrary web script or
HTML via the frame parameter.
|
| CVE-2010-4783 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is
disabled, allow remote attackers to inject arbitrary web script or
HTML via the (1) siteurl and (2) urlbanner parameters.
|
| CVE-2010-4779 |
Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php
in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the
wptouch_settings parameter to include/adsense-new.php. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-4778 |
Multiple cross-site scripting (XSS) vulnerabilities in
fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware
Webmail Edition before 1.2.7, allow remote attackers to inject
arbitrary web script or HTML via the (1) username (aka fmusername),
(2) password (aka fmpassword), or (3) server (aka fmserver) field in a
fetchmail_prefs_save action, related to the Fetchmail configuration, a
different issue than CVE-2010-3695. NOTE: some of these details are
obtained from third party information.
|
| CVE-2010-4772 |
Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS
2.5 allows remote attackers to inject arbitrary web script or HTML via
the id parameter to viewforum.php.
|
| CVE-2010-4762 |
Cross-site scripting (XSS) vulnerability in the rich-text-editor
component in Open Ticket Request System (OTRS) before 3.0.0-beta2
allows remote authenticated users to inject arbitrary web script or
HTML by using the "source code" feature in the customer interface.
|
| CVE-2010-4757 |
Cross-site scripting (XSS) vulnerability in submitnews.php in e107
before 0.7.23 allows remote attackers to inject arbitrary web script
or HTML via the submitnews_title parameter, a different vector than
CVE-2008-6208. NOTE: some of these details are obtained from third
party information. NOTE: this might be the same as CVE-2009-4083.1 or
CVE-2011-0457.
|
| CVE-2010-4753 |
Cross-site scripting (XSS) vulnerability in LightNEasy.php in
LightNEasy 3.2.1 allows remote attackers to inject arbitrary web
script or HTML via the id parameter, which is not properly handled in
a forced SQL error message.
|
| CVE-2010-4749 |
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS
4.2.1.e, and possibly earlier, allow remote attackers to inject
arbitrary web script or HTML via the (1) body parameter to action.php
and the (2) amount and (3) action parameters to admin/index.php.
|
| CVE-2010-4748 |
Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki
2.2.20 allows remote attackers to inject arbitrary web script or HTML
via the from parameter to Main/WikiSandbox. NOTE: some of these
details are obtained from third party information.
|
| CVE-2010-4747 |
Cross-site scripting (XSS) vulnerability in
wordpress-processing-embed/data/popup.php in the Processing Embed
plugin 0.5 for WordPress allows remote attackers to inject arbitrary
web script or HTML via the pluginurl parameter.
|
| CVE-2010-4745 |
Cross-site scripting (XSS) vulnerability in nav.html in PHPXref before
0.7.1 allows remote attackers to inject arbitrary web script or HTML
via the query string.
|
| CVE-2010-4734 |
Multiple cross-site scripting (XSS) vulnerabilities in the comment
feature in Skeletonz CMS 1.0, when the Blog plugin is enabled, allow
remote attackers to inject arbitrary web script or HTML via the (1)
Name, (2) Website, and (3) Email parameters. NOTE: some of these
details are obtained from third party information.
|
| CVE-2010-4718 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Lyftenbloggie (com_lyftenbloggie) component 1.1.0 for Joomla! allow
remote attackers to inject arbitrary web script or HTML via the (1)
tag and (2) category parameters to index.php.
|
| CVE-2010-4716 |
Cross-site scripting (XSS) vulnerability in the WebPublisher component
in Novell GroupWise before 8.02HP allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4710 |
Cross-site scripting (XSS) vulnerability in the addItem method in the
Menu widget in YUI before 2.9.0 allows remote attackers to inject
arbitrary web script or HTML via a field that is added to a menu,
related to documentation that specifies this field as a text field
rather than an HTML field, a similar issue to CVE-2010-4569 and
CVE-2010-4570.
|
| CVE-2010-4693 |
Multiple cross-site scripting (XSS) vulnerabilities in Coppermine
Photo Gallery 1.5.10 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) h and (2) t parameters to
help.php, or (3) picfile_XXX parameter to searchnew.php.
|
| CVE-2010-4667 |
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery
(CPG) before 1.4.27 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-4647 |
Multiple cross-site scripting (XSS) vulnerabilities in the Help
Contents web application (aka the Help Server) in Eclipse IDE before
3.6.2 allow remote attackers to inject arbitrary web script or HTML
via the query string to (1) help/index.jsp or (2)
help/advanced/content.jsp.
|
| CVE-2010-4646 |
Cross-site scripting (XSS) vulnerability in Hastymail2 before 1.01
allows remote attackers to inject arbitrary web script or HTML via a
crafted background attribute within a cell in a TABLE element, related
to improper use of the htmLawed filter.
|
| CVE-2010-4642 |
Cross-site scripting (XSS) vulnerability in XWiki Enterprise before
2.5 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-4640 |
Multiple cross-site scripting (XSS) vulnerabilities in XWiki Watch 1.0
allow remote attackers to inject arbitrary web script or HTML via the
rev parameter to (1) bin/viewrev/Main/WebHome and (2) bin/view/Blog,
and the (3) register_first_name and (4) register_last_name parameters
to bin/register/XWiki/Register. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2010-4637 |
Cross-site scripting (XSS) vulnerability in feedlist/handler_image.php
in the FeedList plugin 2.61.01 for WordPress allows remote attackers
to inject arbitrary web script or HTML via the i parameter.
|
| CVE-2010-4631 |
Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot
Cart 7.3 allow remote attackers to inject arbitrary web script or HTML
via the (1) countrycode parameter to contact.asp, USERNAME parameter
to (2) gateway.asp and (3) cart.asp, and the specific parameter to (4)
quote.asp and (5) buyitnow.
|
| CVE-2010-4630 |
Cross-site scripting (XSS) vulnerability in
pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin
1.2.1 for WordPress allows remote attackers to inject arbitrary web
script or HTML via the action parameter.
|
| CVE-2010-4618 |
Cross-site scripting (XSS) vulnerability in the Algis Info
aiContactSafe component before 2.0.14 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-4616 |
Cross-site scripting (XSS) vulnerability in
modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and
possibly other versions before 1.2.4, allows remote attackers to
inject arbitrary web script or HTML via the quicksearch_ContentContent
parameter.
|
| CVE-2010-4610 |
Cross-site scripting (XSS) vulnerability in index.php in Html-edit CMS
3.1.8 allows remote attackers to inject arbitrary web script or HTML
via the error parameter.
|
| CVE-2010-4607 |
Multiple cross-site scripting (XSS) vulnerabilities in Habari 0.6.5,
when register_globals is enabled, allow remote attackers to inject
arbitrary web script or HTML via the (1) additem_form parameter to
system/admin/dash_additem.php and the (2) status_data[] parameter to
system/admin/dash_status.php. NOTE: some of these details are obtained
from third party information.
|
| CVE-2010-4590 |
Cross-site scripting (XSS) vulnerability in HTTP Access Services
(HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC)
before 6.1.4 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2010-4589 |
Cross-site scripting (XSS) vulnerability in IBM ENOVIA 6 allows remote
attackers to inject arbitrary web script or HTML via vectors related
to the emxFramework.FilterParameterPattern property.
|
| CVE-2010-4570 |
Cross-site scripting (XSS) vulnerability in the duplicate-detection
functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows
remote attackers to inject arbitrary web script or HTML via the
summary field, related to the DataTable widget in YUI.
|
| CVE-2010-4569 |
Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2,
3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web
script or HTML via the real name field of a user account, related to
the AutoComplete widget in YUI.
|
| CVE-2010-4567 |
Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and
4.0.x before 4.0rc2 does not properly handle whitespace preceding a
(1) javascript: or (2) data: URI, which allows remote attackers to
conduct cross-site scripting (XSS) attacks via the URL (aka
bug_file_loc) field.
|
| CVE-2010-4555 |
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail
1.4.21 and earlier allow remote attackers to inject arbitrary web
script or HTML via vectors involving (1) drop-down selection lists,
(2) the > (greater than) character in the SquirrelSpell spellchecking
plugin, and (3) errors associated with the Index Order (aka
options_order) page.
|
| CVE-2010-4544 |
Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus
Notes Traveler before 8.5.1.3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4536 |
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used
in WordPress before 3.0.4, allow remote attackers to inject arbitrary
web script or HTML via vectors related to (1) the & (ampersand)
character, (2) the case of an attribute name, (3) a padded entity, and
(4) an entity that is not in normalized form.
|
| CVE-2010-4524 |
Cross-site scripting (XSS) vulnerability in lib/mhtxthtml.pl in
MHonArc 2.6.16 allows remote attackers to inject arbitrary web script
or HTML via a malformed start tag and end tag for a SCRIPT element, as
demonstrated by <scr<body>ipt> and </scr<body>ipt> sequences.
|
| CVE-2010-4522 |
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka
MyBulletinBoard) 1.4.14, and 1.6.x before 1.6.1, allow remote
attackers to inject arbitrary web script or HTML via vectors related
to (1) editpost.php, (2) member.php, and (3) newreply.php.
|
| CVE-2010-4521 |
Cross-site scripting (XSS) vulnerability in the Views module 6.x
before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary
web script or HTML via a page path.
|
| CVE-2010-4520 |
Multiple cross-site scripting (XSS) vulnerabilities in the Views
module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject
arbitrary web script or HTML via (1) a URL or (2) an aggregator feed
title.
|
| CVE-2010-4519 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x
before 6.x-2.11 for Drupal allow remote attackers to hijack the
authentication of administrators for requests that (1) enable all
Views or (2) disable all Views.
|
| CVE-2010-4518 |
Cross-site scripting (XSS) vulnerability in
wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the v1 parameter.
|
| CVE-2010-4516 |
Multiple cross-site scripting (XSS) vulnerabilities in the JXtended
Comments component before 1.3.1 for Joomla allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4515 |
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0,
5.1, and 5.3 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, a different vulnerability than
CVE-2007-6477 and CVE-2009-2454.
|
| CVE-2010-4514 |
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx
in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject
arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some
of these details are obtained from third party information.
|
| CVE-2010-4513 |
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS
3.0, and possibly earlier, allow remote attackers to inject arbitrary
web script or HTML via the (1) file parameter in a load action to
zimplit.php and (2) client parameter to English_manual_version_2.php.
|
| CVE-2010-4504 |
Multiple cross-site scripting (XSS) vulnerabilities in eSyndiCat
Directory 2.3 allow remote attackers to inject arbitrary web script or
HTML via the title parameter to (1) suggest-category.php and (2)
suggest-listing.php.
|
| CVE-2010-4497 |
Cross-site scripting (XSS) vulnerability in Collaborative Information
Manager server, as used in TIBCO Collaborative Information Manager
before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4480 |
error.php in PhpMyAdmin 3.3.8.1, and other versions before
3.4.0-beta1, allows remote attackers to conduct cross-site scripting
(XSS) attacks via a crafted BBcode tag containing "@" characters, as
demonstrated using "[a@url@page]".
|
| CVE-2010-4412 |
Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta
4 allow remote attackers to inject arbitrary web script or HTML via
(1) the id parameter in an olsrd.xml action to pkg_edit.php, (2) the
xml parameter to pkg.php, or the if parameter to (3) status_graph.php
or (4) interfaces.php, a different vulnerability than CVE-2008-1182
and CVE-2010-4246.
|
| CVE-2010-4407 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
AlGuest 1.1c-patched allow remote attackers to inject arbitrary web
script or HTML via the (1) nome (nickname), (2) messaggio (message),
and (3) link (homepage) parameters.
|
| CVE-2010-4405 |
Cross-site scripting (XSS) vulnerability in the Yannick Gaultier
sh404SEF component before 2.1.8.777 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-4402 |
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in
the Register Plus plugin 3.5.1 and earlier for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1)
firstname, (2) lastname, (3) website, (4) aim, (5) yahoo, (6) jabber,
(7) about, (8) pass1, and (9) pass2 parameters in a register action.
|
| CVE-2010-4366 |
Multiple cross-site scripting (XSS) vulnerabilities in
forum_new_topic.php in Chameleon Social Networking allow remote
attackers to inject arbitrary web script or HTML via the (1)
thread_title and (2) thread_description parameters in a message.
|
| CVE-2010-4364 |
DaDaBIK 4.3 beta3, when running in a case-sensitive environment, does
not include the htmLawed library, which allows remote attackers to
bypass the protection mechanism for CVE-2010-4355 and conduct
cross-site scripting (XSS) attacks via the (1) html content and (2)
rich_editor fields. NOTE: some of these details are obtained from
third party information.
|
| CVE-2010-4361 |
Cross-site scripting (XSS) vulnerability in url-gateway.php in
Jurpopage 0.2.0 allows remote attackers to inject arbitrary web script
or HTML via the url parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2010-4358 |
Multiple cross-site scripting (XSS) vulnerabilities in gb.cgi in
MRCGIGUY (MCG) Guestbook 1.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) name, (2) email, (3) website,
and (4) message parameters.
|
| CVE-2010-4355 |
Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2,
when the insert or edit feature is enabled, allows remote
authenticated users to inject arbitrary web script or HTML via the
select_single parameter.
|
| CVE-2010-4348 |
Cross-site scripting (XSS) vulnerability in
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote
attackers to inject arbitrary web script or HTML via the db_type
parameter, related to an unsafe call by MantisBT to a function in the
ADOdb Library for PHP.
|
| CVE-2010-4339 |
Cross-site scripting (XSS) vulnerability in Hypermail 2.2.0 allows
remote attackers to inject arbitrary web script or HTML via a crafted
From address, which is not properly handled when indexing messages.
|
| CVE-2010-4331 |
Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel 2.2.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) default_news or (2) sponsors cookies, which are not properly
handled by (a) controllers/index.ctrl.php or (b)
controllers/settings.ctrl.php.
|
| CVE-2010-4329 |
Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton
function in libraries/common.lib.php in the database (db) search
script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1
allows remote attackers to inject arbitrary web script or HTML via a
crafted request.
|
| CVE-2010-4324 |
Cross-site scripting (XSS) vulnerability in the Approval Form in the
User Application in the Roles Based Provisioning Module 3.7.0 before
370D in Novell Identity Manager (aka IDM) allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4322 |
Cross-site scripting (XSS) vulnerability in gwtTeaming.rpc in Novell
Vibe OnPrem 3 BETA allows remote authenticated users to inject
arbitrary web script or HTML via the Micro Blog (aka What Are You
Working On?) field.
|
| CVE-2010-4312 |
The default configuration of Apache Tomcat 6.x does not include the
HTTPOnly flag in a Set-Cookie header, which makes it easier for remote
attackers to hijack a session via script access to a cookie.
|
| CVE-2010-4277 |
Cross-site scripting (XSS) vulnerability in lembedded-video.php in the
Embedded Video plugin 4.1 for WordPress allows remote attackers to
inject arbitrary web script or HTML via the content parameter to
wp-admin/post.php.
|
| CVE-2010-4276 |
Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid
function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows
remote attackers to inject arbitrary web script or HTML via the
livezilla parameter in a track action to server.php.
|
| CVE-2010-4275 |
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager
3.8.0 allow remote authenticated administrators to inject arbitrary
web script or HTML via the (1) name or (2) descr parameter in an (a)
update_usergroup or a (b) store_nas action to admin.php.
|
| CVE-2010-4246 |
Multiple cross-site scripting (XSS) vulnerabilities in graph.php in
pfSense 1.2.3 and 2 beta 4 allow remote attackers to inject arbitrary
web script or HTML via the (1) ifnum or (2) ifname parameter, a
different vulnerability than CVE-2008-1182.
|
| CVE-2010-4220 |
Cross-site scripting (XSS) vulnerability in the Integrated Solution
Console in the Administrative Console component in IBM WebSphere
Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors,
related in part to "URL injection."
|
| CVE-2010-4219 |
Cross-site scripting (XSS) vulnerability in SemanticTagService.js in
IBM WebSphere Portal 6.1.0.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-4209 |
Cross-site scripting (XSS) vulnerability in the Flash component
infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1
through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web
script or HTML via vectors related to swfstore/swfstore.swf.
|
| CVE-2010-4208 |
Cross-site scripting (XSS) vulnerability in the Flash component
infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla,
Moodle, and other products, allows remote attackers to inject
arbitrary web script or HTML via vectors related to
uploader/assets/uploader.swf.
|
| CVE-2010-4207 |
Cross-site scripting (XSS) vulnerability in the Flash component
infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla,
Moodle, and other products, allows remote attackers to inject
arbitrary web script or HTML via vectors related to
charts/assets/charts.swf.
|
| CVE-2010-4183 |
Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier
before 4.1.0, when Internet Explorer is used, allow remote attackers
to inject arbitrary web script or HTML via a crafted (1)
background-image, (2) background, or (3) font-family Cascading Style
Sheets (CSS) property, a different vulnerability than CVE-2010-2479.
|
| CVE-2010-4172 |
Multiple cross-site scripting (XSS) vulnerabilities in the Manager
application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through
7.0.4 allow remote attackers to inject arbitrary web script or HTML
via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or
unspecified input to (3) sessionDetail.jsp or (4)
java/org/apache/catalina/manager/JspHelper.java, related to use of
untrusted web applications.
|
| CVE-2010-4155 |
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10
allow remote attackers to inject arbitrary web script or HTML via the
(1) rssfeedURL parameter to manual/caferss/example.php and the sumb
parameter to (2) modules/news/archive.php, (3)
modules/news/topics.php, and (4) modules/contact/index.php, different
vectors than CVE-2007-1965.
|
| CVE-2010-4146 |
Cross-site scripting (XSS) vulnerability in Attachmate Reflection for
the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2010-4120 |
Multiple cross-site scripting (XSS) vulnerabilities in the TAM console
in IBM Tivoli Access Manager for e-business 6.1.0 before
6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web
script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the
method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6)
gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in
ibm/wpm/.
|
| CVE-2010-4114 |
Cross-site scripting (XSS) vulnerability in HP Discovery & Dependency
Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.6x allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4111 |
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics
Online Edition before 8.5.1.3712 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4109 |
Cross-site scripting (XSS) vulnerability in the Contacts Application
in HP Palm webOS before 2.0 allows remote attackers to inject
arbitrary web script or HTML via a crafted vCard file.
|
| CVE-2010-4101 |
Cross-site scripting (XSS) vulnerability in HP Insight Recovery before
6.2 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-4097 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Aardvark Topsites PHP 5.2.0 and 5.2.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) mail, (2) title, (3) u, and
(4) url parameters. NOTE: the q parameter is already covered by
CVE-2009-2302.
|
| CVE-2010-4071 |
Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS
2.4.x before 2.4.9, when RichText is enabled, allows remote attackers
to inject arbitrary web script or HTML via JavaScript in an HTML
e-mail.
|
| CVE-2010-4047 |
Opera before 10.63 does not properly select the security context of
JavaScript code associated with an error page, which allows
user-assisted remote attackers to conduct cross-site scripting (XSS)
attacks via a crafted web site.
|
| CVE-2010-4045 |
Opera before 10.63 does not properly restrict web script in
unspecified circumstances involving reloads and redirects, which
allows remote attackers to spoof the Address Bar, conduct cross-site
scripting (XSS) attacks, and possibly execute arbitrary code by
leveraging the ability of a script to interact with a web page from
(1) a different domain or (2) a different security context.
|
| CVE-2010-4030 |
Cross-site scripting (XSS) vulnerability in HP Insight Control
Performance Management before 6.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-4023 |
Cross-site scripting (XSS) vulnerability in HP Insight Control Power
Management before 6.2 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-3994 |
Cross-site scripting (XSS) vulnerability in HP Version Control
Repository Manager (VCRM) before 6.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-3991 |
Cross-site scripting (XSS) vulnerability in HP Insight Control Server
Migration before 6.2 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-3987 |
Cross-site scripting (XSS) vulnerability in HP Insight Control Virtual
Machine Management before 6.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-3985 |
Cross-site scripting (XSS) vulnerability in HP Operations
Orchestration before 9.0, when Internet Explorer 6.0 is used, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-3981 |
Cross-site scripting (XSS) vulnerability in SAP BusinessObjects
Enterprise XI 3.2 allows remote attackers to inject arbitrary web
script or HTML via the ServiceClass field to the Edit Service
Parameters page.
|
| CVE-2010-3977 |
Multiple cross-site scripting (XSS) vulnerabilities in
wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) rs and (2) rsargs[] parameters.
|
| CVE-2010-3936 |
Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft
Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and
2010 Update 2 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, aka "XSS in Signurl.asp
Vulnerability."
|
| CVE-2010-3931 |
Cross-site scripting (XSS) vulnerability in multiple Rocomotion
products, including P board 1.18 and other versions, P forum 1.30 and
earlier, P up board 1.38 and other versions, P diary R 1.13 and
earlier, P link 1.11 and earlier, P link compact 1.04 and earlier,
pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and
earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier,
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2010-3926 |
Multiple cross-site scripting (XSS) vulnerabilities in Shop.cgi in
SGX-SP Final before 11.00 and SGX-SP Final NE before 11.00 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-3921 |
Cross-site scripting (XSS) vulnerability in Movable Type 4.x before
4.35 and 5.x before 5.04 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2010-3911 |
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM
before 5.2.1 allow remote attackers to inject arbitrary web script or
HTML via (1) the username (aka default_user_name) field or (2) the
password field in a Users Login action to index.php, or (3) the label
parameter in a Settings GetFieldInfo action to index.php, related to
modules/Settings/GetFieldInfo.php.
|
| CVE-2010-3906 |
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
(1) f and (2) fp parameters.
|
| CVE-2010-3890 |
Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise
Edition before 9.1 allows remote attackers to inject arbitrary web
script or HTML via the command parameter to the administration
interface, as demonstrated by the command parameter to
ESAdmin/collection.do.
|
| CVE-2010-3882 |
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple
1.7.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via input to the (1) Add Pages, (2) Add Global Content,
(3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add
Field Definition, or (7) Add Shortcut module.
|
| CVE-2010-3871 |
Cross-site scripting (XSS) vulnerability in
blocktype/groupviews/theme/raw/groupviews.tpl in Mahara before 1.3.3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: some of these details are obtained from
third party information.
|
| CVE-2010-3870 |
The utf8_decode function in PHP before 5.3.4 does not properly handle
non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8
data, which makes it easier for remote attackers to bypass cross-site
scripting (XSS) and SQL injection protection mechanisms via a crafted
string.
|
| CVE-2010-3854 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
administration interface (aka Futon) in Apache CouchDB 0.8.0 through
1.0.1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2010-3841 |
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in
TWiki before 5.0.1 allow remote attackers to inject arbitrary web
script or HTML via (1) the rev parameter to the view script or (2) the
query string to the login script.
|
| CVE-2010-3797 |
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac
OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-3770 |
Multiple cross-site scripting (XSS) vulnerabilities in the rendering
engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and
SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary
web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3)
x-mac-hebrew characters that may be converted to angle brackets during
rendering.
|
| CVE-2010-3763 |
Cross-site scripting (XSS) vulnerability in core/summary_api.php in
MantisBT before 1.2.3 allows remote attackers to inject arbitrary web
script or HTML via the Summary field, a different vector than
CVE-2010-3303.
|
| CVE-2010-3715 |
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x
before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote
attackers to inject arbitrary web script or HTML via vectors related
to (1) the RemoveXSS function, and allow remote authenticated users to
inject arbitrary web script or HTML via vectors related to (2) the
backend.
|
| CVE-2010-3712 |
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before
1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject
arbitrary web script or HTML via vectors involving "multiple encoded
entities," as demonstrated by the query string to index.php in the
com_weblinks or com_content component.
|
| CVE-2010-3695 |
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in
Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before
1.2.7, allows remote attackers to inject arbitrary web script or HTML
via the fm_id parameter in a fetchmail_prefs_save action, related to
the Fetchmail configuration.
|
| CVE-2010-3693 |
Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP)
before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows
remote attackers to inject arbitrary web script or HTML via vectors
related to displaying mailbox names.
|
| CVE-2010-3692 |
Directory traversal vulnerability in the callback function in
client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows
remote attackers to create or overwrite arbitrary files via directory
traversal sequences in a Proxy Granting Ticket IOU (PGTiou) parameter.
|
| CVE-2010-3691 |
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is
enabled, allows local users to overwrite arbitrary files via a symlink
attack on an unspecified file.
|
| CVE-2010-3690 |
Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before
1.1.3, when proxy mode is enabled, allow remote attackers to inject
arbitrary web script or HTML via (1) a crafted Proxy Granting Ticket
IOU (PGTiou) parameter to the callback function in client.php, (2)
vectors involving functions that make getCallbackURL calls, or (3)
vectors involving functions that make getURL calls.
|
| CVE-2010-3659 |
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x
before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x
before 4.4.1 allow remote authenticated backend users to inject
arbitrary web script or HTML via unspecified parameters to the
extension manager, or unspecified parameters to unknown backend forms.
|
| CVE-2010-3607 |
Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt
MEDIA Real Estate Portal 2.0 allows remote authenticated users to
inject arbitrary web script or HTML via the id parameter.
|
| CVE-2010-3605 |
Cross-site scripting (XSS) vulnerability in the powermail extension
1.5.3 and earlier for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-3602 |
Cross-site scripting (XSS) vulnerability in ProfileView.aspx in
mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject
arbitrary web script or HTML via the User ID parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-3489 |
Cross-site scripting (XSS) vulnerability in
netautor/napro4/home/login2.php in CMS Digital Workroom (formerly
Netautor Professional) 5.5.0 allows remote attackers to inject
arbitrary web script or HTML via the goback parameter.
|
| CVE-2010-3472 |
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace
(aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1
before 3.5.1-021 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2010-3470 |
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace
(aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1
before 3.5.1-021 and 4.0.2.x before 4.0.2.7-P8AE-FP007 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-3466 |
Cross-site scripting (XSS) vulnerability in index.php in the
hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote
attackers to inject arbitrary web script or HTML via the tmpl
parameter. NOTE: some of these details are obtained from third party
information.
|
| CVE-2010-3465 |
Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping
Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary
web script or HTML via the (1) id parameter to Default.aspx and the
(2) type parameter to SearchResults.aspx.
|
| CVE-2010-3463 |
Cross-site scripting (XSS) vulnerability in
modules/search/search.class.php in SantaFox 2.02, and possibly
earlier, allows remote attackers to inject arbitrary web script or
HTML via the search parameter to search.html.
|
| CVE-2010-3462 |
Cross-site scripting (XSS) vulnerability in
backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and
possibly other versions allows remote attackers to inject arbitrary
web script or HTML via the confirm parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2010-3459 |
Cross-site scripting (XSS) vulnerability in the Ajax WebMail interface
in AXIGEN Mail Server before 7.4.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-3457 |
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS
2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script
or HTML via the (1) fields[website] parameter in the post comments
feature in articles/a-primer-to-symphony-2s-default-theme/ or (2)
send-email[recipient] parameter to about/. NOTE: some of these details
are obtained from third party information.
|
| CVE-2010-3455 |
Cross-site scripting (XSS) vulnerability in index.php in AChecker 1.0
allows remote attackers to inject arbitrary web script or HTML via the
uri parameter.
|
| CVE-2010-3447 |
Cross-site scripting (XSS) vulnerability in view.php in the file
viewer in Horde Gollem before 1.1.2 allows remote attackers to inject
arbitrary web script or HTML via the file parameter in a view_file
action.
|
| CVE-2010-3427 |
Multiple cross-site scripting (XSS) vulnerabilities in Open
Classifieds 1.7.0.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) desc, (2) price, (3) title, and (4) place
parameters to index.php and the (5) subject parameter to contact.htm,
related to content/contact.php.
|
| CVE-2010-3425 |
Cross-site scripting (XSS) vulnerability in
UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and
possibly other 5.3 versions, allows remote attackers to inject
arbitrary web script or HTML via the url parameter.
|
| CVE-2010-3424 |
Cross-site scripting (XSS) vulnerability in
admin/sources/classes/bbcode/custom/defaults.php in Invision Power
Board (IP.Board) 3.1.2 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-3421 |
Cross-site scripting (XSS) vulnerability in AffiliateLogin.asp in
ProductCart 3, 4.1 SP1, and possibly other versions allows remote
attackers to inject arbitrary web script or HTML via the redirectUrl
parameter, a different vector than CVE-2004-2174 and CVE-2005-0995.
NOTE: some of these details are obtained from third party information.
|
| CVE-2010-3420 |
Cross-site scripting (XSS) vulnerability in Products_Results.php in
PowerStore 3.0 allows remote attackers to inject arbitrary web script
or HTML via the totalRows_WADAProducts parameter.
|
| CVE-2010-3418 |
Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media
Car Portal 2.0 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) car_id parameter to index.php and (2) y
parameter to include/images.php.
|
| CVE-2010-3324 |
The toStaticHTML function in Microsoft Internet Explorer 8, and the
SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2,
SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove
Server 2010, and Office Web Apps, allows remote attackers to bypass
the cross-site scripting (XSS) protection mechanism and conduct XSS
attacks via a crafted use of the Cascading Style Sheets (CSS) @import
rule, aka "HTML Sanitization Vulnerability," a different vulnerability
than CVE-2010-1257.
|
| CVE-2010-3317 |
Cross-site scripting (XSS) vulnerability in IBM Records Manager (RM)
4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-3314 |
Cross-site scripting (XSS) vulnerability in login.php in EGroupware
1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003;
and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows
remote attackers to inject arbitrary web script or HTML via the lang
parameter.
|
| CVE-2010-3313 |
phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php
in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions
before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before
9.2.20100309; allows remote attackers to execute arbitrary commands
via shell metacharacters in the (1) aspell_path or (2)
spellchecker_lang parameters.
|
| CVE-2010-3303 |
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before
1.2.3 allow remote authenticated administrators to inject arbitrary
web script or HTML via (1) a plugin name, related to
manage_plugin_uninstall.php; (2) an enumeration value or (3) a String
value of a custom field, related to core/cfdefs/cfdef_standard.php; or
a (4) project or (5) category name to print_all_bug_page_word.php.
|
| CVE-2010-3294 |
Cross-site scripting (XSS) vulnerability in apc.php in the Alternative
PHP Cache (APC) extension before 3.1.4 for PHP allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-3291 |
Cross-site scripting (XSS) vulnerability in HP AssetCenter 5.0x
through AC_5.03, and AssetManager 5.1x through AM_5.12 and 5.2x
through AM_5.22, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-3289 |
Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager
(SIM) before 6.2 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-3274 |
Multiple cross-site scripting (XSS) vulnerabilities in
EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine
ADSelfService Plus before 4.5 Build 4500 allow remote attackers to
inject arbitrary web script or HTML via the searchString parameter in
a (1) showList or (2) Search action.
|
| CVE-2010-3266 |
Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET
before 3.4.5 allow remote authenticated users to inject arbitrary web
script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the
bug_id parameter to edit_comment.aspx, (3) the id parameter to
edit_user_permissions2.aspx, or (4) the default_name parameter to
edit_customfield.aspx. NOTE: some of these details are obtained from
third party information.
|
| CVE-2010-3263 |
Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php
in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote
attackers to inject arbitrary web script or HTML via a server name.
|
| CVE-2010-3262 |
Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before
3.0.0.4114 allows remote attackers to inject arbitrary web script or
HTML via a crafted RSS feed.
|
| CVE-2010-3243 |
Cross-site scripting (XSS) vulnerability in the toStaticHTML function
in Microsoft Internet Explorer 8, and the SafeHTML function in
Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint
Server 2007 SP2, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, aka "HTML Sanitization
Vulnerability."
|
| CVE-2010-3208 |
Cross-site scripting (XSS) vulnerability in ajax.php in Wiccle Web
Builder (WWB) 1.00 and 1.0.1 allows remote attackers to inject
arbitrary web script or HTML via the post_text parameter in a site
custom_search action to index.php. NOTE: some of these details are
obtained from third party information.
|
| CVE-2010-3202 |
Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989
allows remote attackers to inject arbitrary web script or HTML via a
crafted bookmark.
|
| CVE-2010-3201 |
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before
4.3g allows remote attackers to inject arbitrary web script or HTML
via the username_ex parameter to the surgeweb program.
|
| CVE-2010-3177 |
Multiple cross-site scripting (XSS) vulnerabilities in the Gopher
parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and
SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web
script or HTML via a crafted name of a (1) file or (2) directory on a
Gopher server.
|
| CVE-2010-3094 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x
before 6.18 allow remote authenticated users with certain privileges
to inject arbitrary web script or HTML via (1) an action description,
(2) an action message, (3) a node, or (4) a taxonomy term, related to
the actions feature and the trigger module.
|
| CVE-2010-3089 |
Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman
before 2.1.14rc1 allow remote authenticated users to inject arbitrary
web script or HTML via vectors involving (1) the list information
field or (2) the list description field.
|
| CVE-2010-3082 |
Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2
allows remote attackers to inject arbitrary web script or HTML via a
csrfmiddlewaretoken (aka csrf_token) cookie.
|
| CVE-2010-3077 |
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in
the Horde Application Framework before 3.3.9 allows remote attackers
to inject arbitrary web script or HTML via the subdir parameter.
|
| CVE-2010-3070 |
Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in
MantisBT and other products, allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO to an arbitrary PHP
script that uses NuSOAP classes.
|
| CVE-2010-3056 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers
to inject arbitrary web script or HTML via vectors related to (1)
db_search.php, (2) db_sql.php, (3) db_structure.php, (4)
js/messages.php, (5) libraries/common.lib.php, (6)
libraries/database_interface.lib.php, (7)
libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php,
(9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11)
libraries/sqlparser.lib.php, (12) server_databases.php, (13)
server_privileges.php, (14) setup/config.php, (15) sql.php, (16)
tbl_replace.php, and (17) tbl_sql.php.
|
| CVE-2010-3025 |
Multiple cross-site scripting (XSS) vulnerabilities in Tomaz Muraus
Open Blog 1.2.1, and possibly earlier, allow remote attackers to
inject arbitrary web script or HTML via the (1) excerpt parameter to
application/modules/admin/controllers/posts.php, as reachable by
admin/posts/edit; and the (2) content parameter to
application/modules/admin/controllers/pages.php, as reachable by
admin/posts/edit.
|
| CVE-2010-3023 |
Multiple cross-site scripting (XSS) vulnerabilities in DiamondList
0.1.6, and possibly earlier, allow remote attackers to inject
arbitrary web script or HTML via the (1) category[description]
parameter to user/main/update_category, which is not properly handled
by _app/views/categories/index.html.erb; and the (2)
setting[site_title] parameter to user/main/update_settings, which is
not properly handled by _app/views/settings/_list_settings.rhtml.
|
| CVE-2010-3022 |
Cross-site scripting (XSS) vulnerability in the Performance logging
module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21
for Drupal allows remote authenticated users, with add url aliases and
report access permissions, to inject arbitrary web script or HTML via
crafted node paths in a URL.
|
| CVE-2010-3012 |
Cross-site scripting (XSS) vulnerability in HP System Management
Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors. NOTE: this issue was
originally assigned CVE-2010-3010 due to a CNA error.
|
| CVE-2010-3010 |
Cross-site scripting (XSS) vulnerability on the HP 3Com OfficeConnect
Gigabit VPN Firewall 3CREVF100-73 with firmware before 1.0.13 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: a separate XSS issue for HP System
Management Homepage (SMH) was originally assigned CVE-2010-3010 due to
a CNA error, but CVE-2010-3012 is the appropriate identifier for the
SMH issue.
|
| CVE-2010-3003 |
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics
Online Edition before 8.5.0-11 on Linux allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-2988 |
Cross-site scripting (XSS) vulnerability in Cisco Unified Wireless
Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka Bug
ID CSCtf35333.
|
| CVE-2010-2987 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Wireless
Control System (WCS) 7.x before 7.0.164, as used in Cisco Unified
Wireless Network (UWN) Solution 7.x before 7.0.98.0, allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, aka Bug ID CSCtg33854.
|
| CVE-2010-2986 |
Cross-site scripting (XSS) vulnerability in
webacs/QuickSearchAction.do in the search feature in the web interface
in Cisco Wireless Control System (WCS) before 6.0(194.0) and 7.x
before 7.0.164 allows remote attackers to inject arbitrary web script
or HTML via the searchText parameter, aka Bug ID CSCtf14288.
|
| CVE-2010-2985 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere
Service Registry and Repository (WSRR) 6.3 allow remote attackers to
inject arbitrary web script or HTML via (1) the searchTerm parameter
to ServiceRegistry/HelpSearch.do or (2) the queryItems[0].value
parameter to ServiceRegistry/QueryWizardProcessStep1.do.
|
| CVE-2010-2970 |
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x
before 1.9.3 allow remote attackers to inject arbitrary web script or
HTML via crafted content, related to (1) action/SlideShow.py, (2)
action/anywikidraw.py, and (3) action/language_setup.py, a similar
issue to CVE-2010-2487.
|
| CVE-2010-2969 |
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3
and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject
arbitrary web script or HTML via crafted content, related to (1)
action/LikePages.py, (2) action/chart.py, and (3)
action/userprofile.py, a similar issue to CVE-2010-2487.
|
| CVE-2010-2958 |
Cross-site scripting (XSS) vulnerability in libraries/Error.class.php
in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject
arbitrary web script or HTML via vectors related to a PHP backtrace
and error messages (aka debugging messages), a different vulnerability
than CVE-2010-3056.
|
| CVE-2010-2957 |
Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4,
when "Remember me" logins are enabled, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-2917 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ
Square AJ Article 3.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company,
(5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10)
phone, and (11) fax parameters in an update action. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-2914 |
Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in
the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-2904 |
Multiple cross-site scripting (XSS) vulnerabilities in the System
Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver
allow remote attackers to inject arbitrary web script or HTML via the
(1) action parameter to testsdic and the (2) helpstring parameter to
paramhelp.jsp.
|
| CVE-2010-2886 |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp
7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-2885 |
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 7 and 8,
and RoboHelp Server 7 and 8, allows remote attackers to inject
arbitrary web script or HTML via vectors related to WebHelp generation
with RoboHelp for Word.
|
| CVE-2010-2858 |
Multiple cross-site scripting (XSS) vulnerabilities in news.php in
SimpNews 2.47.03 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) layout and (2) sortorder
parameters.
|
| CVE-2010-2856 |
Cross-site scripting (XSS) vulnerability in admin/currencies.php in
osCSS 1.2.2, and probably earlier versions, allows remote attackers to
inject arbitrary web script or HTML via the page parameter.
|
| CVE-2010-2854 |
Multiple cross-site scripting (XSS) vulnerabilities in modfile.php in
Event Horizon (EVH) 1.1.10, when magic_quotes_gpc is disabled, allow
remote attackers to inject arbitrary web script or HTML via the (1)
YourEmail and (2) VerificationNumber parameters, which are not
properly handled in a forced SQL error message. NOTE: some of these
details are obtained from third party information.
|
| CVE-2010-2852 |
Cross-site scripting (XSS) vulnerability in
modules/headlines/magpierss/scripts/magpie_debug.php in RunCms 2.1,
when the Headlines module is enabled, allows remote attackers to
inject arbitrary web script or HTML via the url parameter.
|
| CVE-2010-2849 |
Cross-site scripting (XSS) vulnerability in productionnu2/nuedit.php
in nuBuilder 10.04.20, and possibly other versions before 10.07.12,
allows remote attackers to inject arbitrary web script or HTML via the
f parameter.
|
| CVE-2010-2846 |
Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms
(com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via the afmsg
parameter to index.php.
|
| CVE-2010-2844 |
Cross-site scripting (XSS) vulnerability in news_show.php in Newanz
NewsOffice 2.0.18 allows remote attackers to inject arbitrary web
script or HTML via the n-cat parameter.
|
| CVE-2010-2802 |
Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.2
allows remote authenticated users to inject arbitrary web script or
HTML via an HTML document with a .gif filename extension, related to
inline attachments.
|
| CVE-2010-2796 |
Cross-site scripting (XSS) vulnerability in phpCAS before 1.1.2, when
proxy mode is enabled, allows remote attackers to inject arbitrary web
script or HTML via a callback URL.
|
| CVE-2010-2790 |
Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery
function in frontends/php/include/classes/class.curl.php in Zabbix
before 1.8.3rc1 allow remote attackers to inject arbitrary web script
or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or
(4) txt_select parameters to the triggers page (tr_status.php). NOTE:
some of these details are obtained from third party information.
|
| CVE-2010-2788 |
Cross-site scripting (XSS) vulnerability in profileinfo.php in
MediaWiki before 1.15.5, when wgEnableProfileInfo is enabled, allows
remote attackers to inject arbitrary web script or HTML via the filter
parameter.
|
| CVE-2010-2779 |
Cross-site scripting (XSS) vulnerability in WebAccess in Novell
GroupWise 8.x before 8.0 SP2 allows remote attackers to inject
arbitrary web script or HTML via a crafted message, related to
"replies."
|
| CVE-2010-2778 |
Cross-site scripting (XSS) vulnerability in WebAccess in Novell
GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows
remote attackers to inject arbitrary web script or HTML via a crafted
message, related to a "Javascript XSS exploit."
|
| CVE-2010-2769 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before
3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x
before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote
attackers to inject arbitrary web script or HTML via a selection that
is added to a document in which the designMode property is enabled.
|
| CVE-2010-2768 |
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird
before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not
properly restrict use of the type attribute of an OBJECT element to
set a document's charset, which allows remote attackers to bypass
cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
|
| CVE-2010-2763 |
The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW)
implementation in Mozilla Firefox before 3.5.12, Thunderbird before
3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted
functions, which allows remote attackers to bypass the Same Origin
Policy and conduct cross-site scripting (XSS) attacks via a crafted
function.
|
| CVE-2010-2734 |
Cross-site scripting (XSS) vulnerability in the mobile portal in
Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010
Update 1, and 2010 Update 2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, aka "XSS Issue
on UAG Mobile Portal Website in Forefront Unified Access Gateway
Vulnerability."
|
| CVE-2010-2733 |
Cross-site scripting (XSS) vulnerability in the Web Monitor in
Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010
Update 1, and 2010 Update 2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, aka "UAG XSS
Allows EOP Vulnerability."
|
| CVE-2010-2724 |
Cross-site scripting (XSS) vulnerability in the Hierarchical Select
module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows
remote authenticated users, with administer taxonomy permissions, to
inject arbitrary web script or HTML via unspecified vectors in the
hierarchical_select form.
|
| CVE-2010-2723 |
Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows
remote attackers to inject arbitrary web script or HTML via the T
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2010-2722 |
Cross-site scripting (XSS) vulnerability in index.php in RightInPoint
Lyrics Script 3.0 allows remote attackers to inject arbitrary web
script or HTML via the artist_id parameter, which is not properly
handled in a forced SQL error message. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2010-2718 |
Multiple cross-site scripting (XSS) vulnerabilities in CruxSoftware
CruxPA 2.00, and possibly earlier, allow remote attackers to inject
arbitrary web script or HTML via the (1) txtusername parameter to
login.php, (2) todo parameter to newtodo.php, and unspecified vectors
to (3) newtelephone.php and (4) newappointment.php.
|
| CVE-2010-2717 |
Cross-site scripting (XSS) vulnerability in manager/login.php in
CruxSoftware CruxCMS 3.0, and possibly earlier, allows remote
attackers to inject arbitrary web script or HTML via the txtusername
parameter.
|
| CVE-2010-2715 |
Cross-site scripting (XSS) vulnerability in photos/index.php in TCW
PHP Album 1.0 allows remote attackers to inject arbitrary web script
or HTML via the album parameter.
|
| CVE-2010-2700 |
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP
Clickbank Affiliate Marketplace Script (CBQuick) allows remote
attackers to inject arbitrary web script or HTML via the search
parameter.
|
| CVE-2010-2698 |
Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community
Software allow remote authenticated users to inject arbitrary web
script or HTML via the title parameter when (1) editing a new blog,
(2) adding an album, or (3) editing an album. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2010-2697 |
Cross-site scripting (XSS) vulnerability in Sijio Community Software
allows remote authenticated users to inject arbitrary web script or
HTML via the title parameter when adding a new blog, related to
edit_blog/index.php. NOTE: some of these details are obtained from
third party information.
|
| CVE-2010-2692 |
Cross-site scripting (XSS) vulnerability in 2daybiz Custom T-Shirt
Design Script allows remote attackers to inject arbitrary web script
or HTML via a review comment.
|
| CVE-2010-2675 |
Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS
1.1, 1.9, and 2.0 allows remote attackers to inject arbitrary web
script or HTML via the id parameter in an articolo action.
|
| CVE-2010-2671 |
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ
Publish 3.7.0 through 4.2.0 allows remote attackers to inject
arbitrary web script or HTML via the subTreeItem parameter.
|
| CVE-2010-2669 |
Cross-site scripting (XSS) vulnerability in
admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote
attackers to inject arbitrary web script or HTML via the s parameter.
|
| CVE-2010-2665 |
Cross-site scripting (XSS) vulnerability in Opera before 10.54 on
Windows and Mac OS X, and before 10.11 on UNIX platforms, allows
remote attackers to inject arbitrary web script or HTML via a data:
URI, related to incorrect detection of the "opening site."
|
| CVE-2010-2654 |
Multiple cross-site scripting (XSS) vulnerabilities on the IBM
BladeCenter with Advanced Management Module (AMM) firmware build ID
BPET48L, and possibly other versions before 4.7 and 5.0, allow remote
attackers to inject arbitrary web script or HTML via the (1) INDEX or
(2) IPADDR parameter to private/cindefn.php, (3) the domain parameter
to private/power_management_policy_options.php, the slot parameter to
(4) private/pm_temp.php or (5) private/power_module.php, (6) the
WEBINDEX parameter to private/blade_leds.php, or (7) the SLOT
parameter to private/ipmi_bladestatus.php.
|
| CVE-2010-2636 |
Multiple cross-site scripting (XSS) vulnerabilities in sample store
pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote
attackers to inject arbitrary web script or HTML via a crafted URL.
|
| CVE-2010-2617 |
Cross-site scripting (XSS) vulnerability in bible.php in PHP Bible
Search allows remote attackers to inject arbitrary web script or HTML
via the chapter parameter.
|
| CVE-2010-2615 |
Multiple cross-site scripting (XSS) vulnerabilities in admin/admin.php
in Grafik CMS 1.1.2, and possibly earlier, allow remote attackers to
inject arbitrary web script or HTML via the (1) page_menu and (2)
description parameters in an edit_page action.
|
| CVE-2010-2613 |
Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd
Song (com_awd_song) component for Joomla! allows remote attackers to
inject arbitrary web script or HTML via the song review field, which
is not properly handled in a view action to index.php.
|
| CVE-2010-2574 |
Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in
MantisBT 1.2.2 allows remote authenticated administrators to inject
arbitrary web script or HTML via the name parameter in an Add Category
action.
|
| CVE-2010-2545 |
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before
0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution
and other products, allow remote attackers to inject arbitrary web
script or HTML via (1) the name element in an XML template to
templates_import.php; and allow remote authenticated administrators to
inject arbitrary web script or HTML via vectors related to (2)
cdef.php, (3) data_input.php, (4) data_queries.php, (5)
data_sources.php, (6) data_templates.php, (7) gprint_presets.php, (8)
graph.php, (9) graphs_new.php, (10) graphs.php, (11)
graph_templates_inputs.php, (12) graph_templates_items.php, (13)
graph_templates.php, (14) graph_view.php, (15) host.php, (16)
host_templates.php, (17) lib/functions.php, (18) lib/html_form.php,
(19) lib/html_form_template.php, (20) lib/html.php, (21)
lib/html_tree.php, (22) lib/rrd.php, (23) rra.php, (24) tree.php, and
(25) user_admin.php.
|
| CVE-2010-2544 |
Cross-site scripting (XSS) vulnerability in utilities.php in Cacti
before 0.8.7g, as used in Red Hat High Performance Computing (HPC)
Solution and other products, allows remote attackers to inject
arbitrary web script or HTML via the filter parameter.
|
| CVE-2010-2543 |
Cross-site scripting (XSS) vulnerability in
include/top_graph_header.php in Cacti before 0.8.7g allows remote
attackers to inject arbitrary web script or HTML via the graph_start
parameter to graph.php. NOTE: this vulnerability exists because of an
incorrect fix for CVE-2009-4032.2.b.
|
| CVE-2010-2536 |
Multiple cross-site scripting (XSS) vulnerabilities in rekonq 0.5 and
earlier allow remote attackers to inject arbitrary web script or HTML
via (1) a URL associated with a nonexistent domain name, related to
webpage.cpp, aka a "universal XSS" issue; (2) unspecified vectors
related to webview.cpp; and the about: views for (3) favorites, (4)
bookmarks, (5) closed tabs, and (6) history.
|
| CVE-2010-2535 |
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in
Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject
arbitrary web script or HTML via administrator screens.
|
| CVE-2010-2514 |
Cross-site scripting (XSS) vulnerability in the JFaq (com_jfaq)
component 1.2 for Joomla! allows remote attackers to inject arbitrary
web script or HTML via the question parameter in an add2 action to
index.php.
|
| CVE-2010-2509 |
Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web
Template Software allow remote attackers to inject arbitrary web
script or HTML via the (1) keyword parameter to category.php and the
(2) password parameter to memberlogin.php.
|
| CVE-2010-2506 |
Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys
WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to
inject arbitrary web script or HTML via the data1 parameter.
|
| CVE-2010-2503 |
Multiple cross-site scripting (XSS) vulnerabilities in Splunk 4.0
through 4.0.10 and 4.1 through 4.1.1 allow remote attackers to inject
arbitrary web script or HTML via (1) redirects, aka SPL-31067; (2)
unspecified "user->user or user->admin" vectors, aka SPL-31084; or (3)
unspecified "user input," aka SPL-31085.
|
| CVE-2010-2491 |
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup
before 1.4.14 allows remote attackers to inject arbitrary web script
or HTML via the template argument to the /issue program.
|
| CVE-2010-2487 |
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3
and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote
attackers to inject arbitrary web script or HTML via crafted content,
related to (1) Page.py, (2) PageEditor.py, (3) PageGraphicalEditor.py,
(4) action/CopyPage.py, (5) action/Load.py, (6) action/RenamePage.py,
(7) action/backup.py, (8) action/login.py, (9) action/newaccount.py,
and (10) action/recoverpass.py.
|
| CVE-2010-2480 |
Mako before 0.3.4 relies on the cgi.escape function in the Python
standard library for cross-site scripting (XSS) protection, which
makes it easier for remote attackers to conduct XSS attacks via
vectors involving single-quote characters and a JavaScript onLoad
event handler for a BODY element.
|
| CVE-2010-2479 |
Cross-site scripting (XSS) vulnerability in HTML Purifier before
4.1.1, as used in Mahara and other products, when the browser is
Internet Explorer, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-2477 |
Multiple cross-site scripting (XSS) vulnerabilities in the
paste.httpexceptions implementation in Paste before 1.7.4 allow remote
attackers to inject arbitrary web script or HTML via vectors involving
a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2)
paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4)
HTTPNotFound.
|
| CVE-2010-2464 |
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments
(com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote
attackers to inject arbitrary web script or HTML via the (1) website
and (2) name parameters to index.php.
|
| CVE-2010-2463 |
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom
before 4.1.9 allows remote attackers to inject arbitrary web script or
HTML via the post_id parameter in a modify action.
|
| CVE-2010-2458 |
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video
Community Portal Script 1.0 allows remote attackers to inject
arbitrary web script or HTML via the videoid parameter.
|
| CVE-2010-2457 |
Cross-site scripting (XSS) vulnerability in index.php in K-Search
allows remote attackers to inject arbitrary web script or HTML via the
term parameter.
|
| CVE-2010-2453 |
Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk
Station 2.x before DSM3.0-1337 allow remote attackers to inject
arbitrary web script or HTML by connecting to the FTP server and
providing a crafted (1) USER or (2) PASS command, which is written by
the FTP logging module to a web-interface log window, related to a
"web commands injection" issue.
|
| CVE-2010-2437 |
Cross-site scripting (XSS) vulnerability in class/tools.class.php in
AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject
arbitrary web script or HTML via the comment variable to
modules/blog/index.php.
|
| CVE-2010-2433 |
Multiple cross-site scripting (XSS) vulnerabilities in
content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow
remote attackers to inject arbitrary web script or HTML via an RTS URL
to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp
in faces/.
|
| CVE-2010-2429 |
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.1.2,
when Internet Explorer is used, allows remote attackers to inject
arbitrary web script or HTML via the HTTP Referer in a "404 Not Found"
response.
|
| CVE-2010-2428 |
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the
Administrator web interface in Wing FTP Server for Windows 3.5.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via a crafted POST request.
|
| CVE-2010-2422 |
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone
2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to
inject arbitrary web script or HTML via the safe_html transform.
|
| CVE-2010-2367 |
Cross-site scripting (XSS) vulnerability in search.cgi in AD-EDIT2
before 3.0.9 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2010-2366 |
Cross-site scripting (XSS) vulnerability in futomi CGI Cafe Access
Analyzer CGI Professional, and Standard 4.0.2 and earlier, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-2365 |
Cross-site scripting (XSS) vulnerability in Free CGI Moo moobbs2
before 1.03 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2010-2364 |
Cross-site scripting (XSS) vulnerability in Free CGI Moo moobbs before
1.03 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2010-2356 |
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot
Group (PG) eLMS Pro allows remote attackers to inject arbitrary web
script or HTML via the course_id parameter.
|
| CVE-2010-2355 |
Cross-site scripting (XSS) vulnerability in error.php in Pilot Group
(PG) eLMS Pro allows remote attackers to inject arbitrary web script
or HTML via the message parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2010-2344 |
Multiple cross-site scripting (XSS) vulnerabilities in odCMS 1.06, and
possibly earlier, allow remote attackers to inject arbitrary web
script or HTML via the Page parameter to (1) _main/index.php, (2)
_members/index.php, (3) _forum/index.php, (4) _docs/index.php, and (5)
_announcements/index.php.
|
| CVE-2010-2325 |
Cross-site scripting (XSS) vulnerability in the administrative console
in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, related in part to "URL injection."
|
| CVE-2010-2318 |
Cross-site scripting (XSS) vulnerability in cms_data.php in
PHPCityPortal 1.3 allows remote attackers to inject arbitrary web
script or HTML via the page parameter.
|
| CVE-2010-2316 |
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in
WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) search, (2) sbr, (3) p, and (4) sbl
parameters, different vectors than CVE-2007-3137.
|
| CVE-2010-2301 |
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in
WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote
attackers to inject arbitrary web script or HTML via vectors related
to the node.innerHTML property of a TEXTAREA element. NOTE: this might
overlap CVE-2010-1762.
|
| CVE-2010-2293 |
The Ping tools web interface in Dlink Di-604 router allows remote
authenticated users to cause a denial of service via a large "ip
textfield" size.
|
| CVE-2010-2292 |
Cross-site scripting (XSS) vulnerability in the Ping tools web
interface in Dlink Di-604 router allows remote attackers to inject
arbitrary web script or HTML via the IP field.
|
| CVE-2010-2290 |
Cross-site scripting (XSS) vulnerability in cgi-bin/cgix/help in
McAfee Unified Threat Management (UTM) Firewall (formerly SnapGear)
firmware 3.0.0 through 4.0.6 allows remote attackers to inject
arbitrary web script or HTML via the page parameter.
|
| CVE-2010-2289 |
Open redirect vulnerability in dana/home/homepage.cgi in Juniper
Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote
attackers to redirect users to arbitrary web sites and conduct
phishing attacks via a URL in the Location parameter.
|
| CVE-2010-2288 |
Cross-site scripting (XSS) vulnerability in dana/nc/ncrun.cgi in
Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951)
allows remote attackers to inject arbitrary web script or HTML via the
DSSignInURL cookie.
|
| CVE-2010-2281 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
TomatoCMS 2.0.6 allow remote attackers to inject arbitrary web script
or HTML via the (1) keyword or (2) bannerid parameter in conjunction
with a /admin/ad/banner/list PATH_INFO; and allow remote authenticated
users, with certain privileges, to inject arbitrary web script or HTML
via the (3) title or (4) answers parameter in conjunction with a
/admin/poll/add PATH_INFO, or the (5) name parameter in conjunction
with a /admin/category/add PATH_INFO.
|
| CVE-2010-2277 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus
Connections 2.5.x before 2.5.0.2 allow remote attackers to inject
arbitrary web script or HTML via the (1) create or (2) edit form in
the Communities component, the (3) verbiage field in the Bookmarks
component, or (4) unspecified vectors related to the Mobile Blogs
component.
|
| CVE-2010-2275 |
Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js
in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject
arbitrary web script or HTML via the theme parameter, as demonstrated
by an attack against dijit/tests/form/test_Button.html.
|
| CVE-2010-2273 |
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x
before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before
1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors, possibly related
to dojo/resources/iframe_history.html, dojox/av/FLAudio.js,
dojox/av/FLVideo.js, dojox/av/resources/audio.swf,
dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, and
util/buildscripts/jslib/buildUtil.js, as demonstrated by the (1)
dojoUrl and (2) testUrl parameters to util/doh/runner.html.
|
| CVE-2010-2267 |
Multiple cross-site scripting (XSS) vulnerabilities in Accoria Web
Server (aka Rock Web Server) 1.4.7 allow remote attackers to inject
arbitrary web script or HTML via (1) the query string to the getenv
sample program, (2) the desc parameter to loadstatic.cgi, (3) the name
parameter to httpdcfg.cgi, or (4) the dns parameter to servercfg.cgi.
|
| CVE-2010-2265 |
Cross-site scripting (XSS) vulnerability in the GetServerName function
in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center
for Windows XP and Windows Server 2003 allows remote attackers to
inject arbitrary web script or HTML via the svr parameter to
sysinfo/sysinfomain.htm. NOTE: this can be leveraged with
CVE-2010-1885 to execute arbitrary commands without user interaction.
|
| CVE-2010-2260 |
Multiple cross-site scripting (XSS) vulnerabilities in Gambit Design
Bandwidth Meter, 0.72 and possibly 1.2, allow remote attackers to
inject arbitrary web script or HTML via the PATH_INFO to (1)
view_by_name.php or (2) view_by_ip.php in admin/. NOTE: some sources
report that the affected product is ShaPlus Bandwidth Meter, but this
is incorrect.
|
| CVE-2010-2258 |
Cross-site scripting (XSS) vulnerability in signupconfirm.php in
phpBannerExchange 1.2 Arabic allows remote attackers to inject
arbitrary web script or HTML via the bannerurl parameter.
|
| CVE-2010-2256 |
Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute
Video Chat Script 2.0 and 2.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) id parameter to
admin/memberviewdetails.php and the (2) model parameter to videos.php.
|
| CVE-2010-2230 |
The KSES text cleaning filter in lib/weblib.php in Moodle before
1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs,
which allows remote authenticated users to conduct cross-site
scripting (XSS) attacks via HTML input.
|
| CVE-2010-2229 |
Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php
in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers
to inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2010-2228 |
Cross-site scripting (XSS) vulnerability in the MNET access-control
interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote
attackers to inject arbitrary web script or HTML via vectors involving
extended characters in a username.
|
| CVE-2010-2179 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before
9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before
2.0.2.12610, when Firefox or Chrome is used, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors related
to URL parsing.
|
| CVE-2010-2158 |
Multiple cross-site scripting (XSS) vulnerabilities in the Storm
module 5.x and 6.x before 6.x-1.33 for Drupal allow remote
authenticated users, with certain module privileges, to inject
arbitrary web script or HTML via the (1) fullname, (2) phone, or (3)
im parameter in a stormperson action to index.php. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2010-2155 |
Multiple cross-site scripting (XSS) vulnerabilities in
zc/publisher/html.rb in ZoneCheck 2.1.0 allow remote attackers to
inject arbitrary web script or HTML via vectors related to (1)
xmlnode.value, (2) zc-error text, (3) $zc_version, (4) domainname in a
zc-title row, different vulnerabilities than CVE-2009-4882.
|
| CVE-2010-2154 |
Cross-site scripting (XSS) vulnerability in the Search Site in CMScout
2.09, and possibly other versions, allows remote attackers to inject
arbitrary web script or HTML via the search parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-2150 |
Cross-site scripting (XSS) vulnerability Fujitsu e-Pares V01 L01
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-2147 |
Cross-site scripting (XSS) vulnerability in the My Car (com_mycar)
component 1.0 for Joomla! allows remote attackers to inject arbitrary
web script or HTML via the modveh parameter to index.php.
|
| CVE-2010-2144 |
Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways
eBay Clone Auction Script allows remote attackers to inject arbitrary
web script or HTML via the msg parameter. NOTE: some of these details
are obtained from third party information.
|
| CVE-2010-2130 |
Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global
ARISg 5.0 allows remote attackers to inject arbitrary web script or
HTML via the errmsg parameter.
|
| CVE-2010-2125 |
Multiple cross-site scripting (XSS) vulnerabilities in the Rotor
Banner module 5.x before 5.x-1.8 and 6.x before 6.x-2.5 for Drupal
allow remote authenticated users, with "create rotor item" or "edit
any rotor item" privileges, to inject arbitrary web script or HTML via
the (1) srs, (2) title, or (3) alt image attribute.
|
| CVE-2010-2123 |
Multiple cross-site scripting (XSS) vulnerabilities in the Storm
module 5.x and 6.x before 6.x-1.33 for Drupal allow remote
authenticated users, with certain module privileges, to inject
arbitrary web script or HTML via the (1) fullname, (2) address, (3)
city, (4) provstate (aka state), (5) phone, or (6) taxid parameter in
a stormorganization action to index.php; the (7) name parameter in a
stormperson action to index.php; the (8) stepno (aka Step no.) or (9)
title parameter in a stormtask action to index.php; the (10) title
(aka Project) parameter in a stormticket action to index.php; or (11)
unspecified parameters in a stormproject action to index.php. NOTE:
some of these details are obtained from third party information.
|
| CVE-2010-2103 |
Cross-site scripting (XSS) vulnerability in
axis2-admin/axis2-admin/engagingglobally in the administration console
in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as
used in SAP Business Objects 12, 3com IMC, and possibly other
products, allows remote attackers to inject arbitrary web script or
HTML via the modules parameter. NOTE: some of these details are
obtained from third party information.
|
| CVE-2010-2091 |
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7
on Windows Server 2003 is used, does not properly handle the id
parameter in a Folder IPF.Note action to the default URI, which might
allow remote attackers to obtain sensitive information or conduct
cross-site scripting (XSS) attacks via an invalid value.
|
| CVE-2010-2088 |
ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted
view state, which allows remote attackers to conduct cross-site
scripting (XSS) attacks against the form control via the __VIEWSTATE
parameter.
|
| CVE-2010-2087 |
Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application
Server, Caucho Resin, and other applications, does not properly handle
an unencrypted view state, which allows remote attackers to conduct
cross-site scripting (XSS) attacks or execute arbitrary Expression
Language (EL) statements via vectors that involve modifying the
serialized view object.
|
| CVE-2010-2086 |
Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application
Server and other applications, does not properly handle an unencrypted
view state, which allows remote attackers to conduct cross-site
scripting (XSS) attacks or execute arbitrary Expression Language (EL)
statements via vectors that involve modifying the serialized view
object.
|
| CVE-2010-2085 |
The default configuration of ASP.NET in Microsoft .NET before 1.1 has
a value of FALSE for the EnableViewStateMac property, which allows
remote attackers to conduct cross-site scripting (XSS) attacks via the
__VIEWSTATE parameter.
|
| CVE-2010-2084 |
Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property
on a control that inherits from HtmlContainerControl, which allows
remote attackers to conduct cross-site scripting (XSS) attacks via
vectors related to an attribute.
|
| CVE-2010-2080 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket
Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 allow
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-2049 |
Cross-site scripting (XSS) vulnerability in
jsp/audit/reports/ExportReport.jsp in ManageEngine ADAudit Plus 4.0.0
build 4043 allows remote attackers to inject arbitrary web script or
HTML via the reportList parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2010-2048 |
Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat
module 6.x before 6.x-4.9 for Drupal allow remote authenticated users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-2046 |
Multiple cross-site scripting (XSS) vulnerabilities in the
ActiveHelper LiveHelp (com_activehelper_livehelp) component 2.0.3 for
Joomla! allow remote attackers to inject arbitrary web script or HTML
via (1) the DOMAINID parameter to server/cookies.php or (2) the SERVER
parameter to server/index.php.
|
| CVE-2010-2043 |
Cross-site scripting (XSS) vulnerability in Home.aspx in DataTrack
System 3.5 and 3.5.8019.4 allows remote attackers to inject arbitrary
web script or HTML via the Work_Order_Summary parameter (aka the
request summary). NOTE: some of these details are obtained from third
party information.
|
| CVE-2010-2041 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
PHP-Calendar before 2.0 Beta7 allow remote attackers to inject
arbitrary web script or HTML via the (1) description and (2)
lastaction parameters.
|
| CVE-2010-2040 |
Cross-site scripting (XSS) vulnerability in search.php in V-EVA
Shopzilla Affiliate Script PHP allows remote attackers to inject
arbitrary web script or HTML via the s parameter.
|
| CVE-2010-2038 |
Cross-site scripting (XSS) vulnerability in
include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote
authenticated users, with Edit privileges, to inject arbitrary web
script or HTML via the gpcontent parameter to index.php. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-2032 |
Multiple cross-site scripting (XSS) vulnerabilities in
resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5,
3.1.10, 4.0.6, and possibly other versions allow remote attackers to
inject arbitrary web script or HTML via the (1) digest_realm or (2)
digest_username parameters. NOTE: some of these details are obtained
from third party information.
|
| CVE-2010-2030 |
Cross-site scripting (XSS) vulnerability in the External Link Page
module 5.x before 5.x-1.0 and 6.x before 6.x-1.2 for Drupal allows
remote attackers to inject arbitrary web script or HTML via vectors
related to the administration and redirect pages.
|
| CVE-2010-2017 |
Cross-site scripting (XSS) vulnerability in hasil-pencarian.html in
Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to inject
arbitrary web script or HTML via the kata parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-2014 |
Cross-site scripting (XSS) vulnerability in cp/list_content.php in
LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or
HTML via the cl or possibly id parameter.
|
| CVE-2010-2013 |
Cross-site scripting (XSS) vulnerability in cp/edit_email.php in LiSK
CMS 4.4 allows remote attackers to inject arbitrary web script or HTML
via the id parameter.
|
| CVE-2010-2010 |
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool
Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote
attackers to inject arbitrary web script or HTML via a node title.
|
| CVE-2010-2003 |
Cross-site scripting (XSS) vulnerability in misc/get_admin.php in
Advanced Poll 2.08 allows remote attackers to inject arbitrary web
script or HTML via the mysql_host parameter.
|
| CVE-2010-2002 |
Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x
before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote
authenticated users, with "administer words filtered" privileges, to
inject arbitrary web script or HTML via the word list.
|
| CVE-2010-2001 |
Cross-site scripting (XSS) vulnerability in the CiviRegister module
before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary
web script or HTML via the URI.
|
| CVE-2010-2000 |
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio)
module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows
remote authenticated users, with "administer biblio" privileges, to
inject arbitrary web script or HTML via unspecified vectors, a
different vulnerability than CVE-2010-1358.
|
| CVE-2010-1998 |
Cross-site scripting (XSS) vulnerability in the CCK TableField module
6.x before 6.x-1.2 for Drupal allows remote authenticated users, with
certain node creation or editing privileges, to inject arbitrary web
script or HTML via table headers.
|
| CVE-2010-1997 |
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus
CMS 4.7.0 allows remote authenticated users, with "Article list" edit
privileges, to inject arbitrary web script or HTML via the pealkiri
parameter.
|
| CVE-2010-1996 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
TomatoCMS before 2.0.5 allow remote authenticated users, with certain
creation privileges, to inject arbitrary web script or HTML via the
(1) content parameter in conjunction with a /admin/poll/add PATH_INFO,
the (2) meta parameter in conjunction with a /admin/category/add
PATH_INFO, and the (3) keyword parameter in conjunction with a
/admin/tag/add PATH_INFO.
|
| CVE-2010-1995 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
TomatoCMS before 2.0.5 allow remote authenticated users, with "Add new
article" privileges, to inject arbitrary web script or HTML via the
(1) title, (2) subTitle, and (3) author parameters in conjunction with
a /admin/news/article/add PATH_INFO.
|
| CVE-2010-1985 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative user interface in Six Apart Movable Type 5.0 and 5.01
allow remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2010-1984 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb
module 5.x before 5.x-1.5 and 6.x before 6.x-1.1 for Drupal allows
remote authenticated users, with administer taxonomy permissions, to
inject arbitrary web script or HTML via the taxonomy term name in a
Breadcrumb display.
|
| CVE-2010-1976 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb
module 6.x before 6.x-1.1 for Drupal allows remote authenticated
users, with administer taxonomy permissions, to inject arbitrary web
script or HTML via the node title in a Breadcrumb display.
|
| CVE-2010-1969 |
Cross-site scripting (XSS) vulnerability in HP Virtual Connect
Enterprise Manager for Windows before 6.1 allows remote attackers to
inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2010-1963 |
Cross-site scripting (XSS) vulnerability in HP ServiceCenter allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-1958 |
Cross-site scripting (XSS) vulnerability in the FileField module 5.x
before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote
authenticated users, with create or edit permissions and 'Path to
File' or 'URL to File' display enabled, to inject arbitrary web script
or HTML via the file name (filepath parameter).
|
| CVE-2010-1905 |
Multiple cross-site scripting (XSS) vulnerabilities in Consona Live
Assistance, Dynamic Agent, and Subscriber Assistance allow remote
attackers to inject arbitrary web script or HTML via crafted input to
ASP pages, as demonstrated using the backurl parameter to
sdccommon/verify/asp/n6plugindestructor.asp.
|
| CVE-2010-1872 |
Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard
2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script
or HTML via the id parameter. NOTE: some of these details are obtained
from third party information.
|
| CVE-2010-1856 |
Cross-site scripting (XSS) vulnerability in index.php in RepairShop2
1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote
attackers to inject arbitrary web script or HTML via the prod
parameter in a products.details action.
|
| CVE-2010-1854 |
Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per
Watch & Bid Auktions System allows remote attackers to inject
arbitrary web script or HTML via the id_auk parameter, which is not
properly handled in a forced SQL error message. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information. NOTE: this might be resultant from
CVE-2010-1855.
|
| CVE-2010-1778 |
Cross-site scripting (XSS) vulnerability in Apple Safari before 5.0.1
on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS
X 10.4, allows remote attackers to inject arbitrary web script or HTML
via an RSS feed.
|
| CVE-2010-1762 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1
on Mac OS X 10.4, allows remote attackers to inject arbitrary web
script or HTML via vectors involving HTML in a TEXTAREA element.
|
| CVE-2010-1746 |
Multiple cross-site scripting (XSS) vulnerabilities in the Table JX
(com_grid) component for Joomla! allow remote attackers to inject
arbitrary web script or HTML via the (1) data_search and (2) rpp
parameters to index.php.
|
| CVE-2010-1742 |
Cross-site scripting (XSS) vulnerability in projects.php in Scratcher
allows remote attackers to inject arbitrary web script or HTML via the
show parameter.
|
| CVE-2010-1724 |
Multiple cross-site scripting (XSS) vulnerabilities in Zikula
Application Framework 1.2.2, and possibly earlier, allow remote
attackers to inject arbitrary web script or HTML via the (1) func
parameter to index.php, or the (2) lang parameter to index.php, which
is not properly handled by ZLanguage.php.
|
| CVE-2010-1712 |
Multiple cross-site scripting (XSS) vulnerabilities in
base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to
inject arbitrary web script or HTML via the (1) name and possibly (2)
message parameters. NOTE: some of these details are obtained from
third party information.
|
| CVE-2010-1711 |
Cross-site scripting (XSS) vulnerability in carga_foto_al.php in
Siestta 2.0, when register_globals is enabled, allows remote attackers
to inject arbitrary web script or HTML via the usuario parameter.
|
| CVE-2010-1709 |
Multiple cross-site scripting (XSS) vulnerabilities in upload.cgi in
G5-Scripts Auto-Img-Gallery 1.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) user and (2) pass parameters.
|
| CVE-2010-1707 |
Multiple cross-site scripting (XSS) vulnerabilities in register.php in
Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) login and (2) mail_address parameters.
|
| CVE-2010-1703 |
Multiple cross-site scripting (XSS) vulnerabilities in
index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow
remote attackers to inject arbitrary web script or HTML via the (1)
category parameter or (2) search field.
|
| CVE-2010-1667 |
Multiple cross-site scripting (XSS) vulnerabilities in Mahara before
1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-1662 |
Cross-site scripting (XSS) vulnerability in acpmoderate.php in
PHP-Quick-Arcade (PHPQA) 3.0.21 allows remote attackers to inject
arbitrary web script or HTML via the serv parameter.
|
| CVE-2010-1655 |
Cross-site scripting (XSS) vulnerability in User/User_ChkLogin.asp in
PowerEasy 2006 and PowerEasy SiteWeaver 6.8 allows remote attackers to
inject arbitrary web script or HTML via the ComeUrl parameter.
|
| CVE-2010-1649 |
Multiple cross-site scripting (XSS) vulnerabilities in the back end in
Joomla! 1.5 through 1.5.17 allow remote attackers to inject arbitrary
web script or HTML via unknown vectors related to "various
administrator screens," possibly the search parameter in
administrator/index.php.
|
| CVE-2010-1647 |
Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before
1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject
arbitrary web script or HTML via crafted Cascading Style Sheets (CSS)
strings that are processed as script by Internet Explorer.
|
| CVE-2010-1644 |
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before
0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution
and other products, allow remote attackers to inject arbitrary web
script or HTML via the (1) hostname or (2) description parameter to
host.php, or (3) the host_id parameter to data_sources.php.
|
| CVE-2010-1629 |
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.15
allows remote attackers to inject arbitrary web script or HTML via an
invalid email address.
|
| CVE-2010-1625 |
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer
before 0.9.7 allows remote attackers to inject arbitrary web script or
HTML via vectors related to the search body and the results page for a
search, a different vulnerability than CVE-2009-4497 and
CVE-2010-1448.
|
| CVE-2010-1619 |
Cross-site scripting (XSS) vulnerability in the
fix_non_standard_entities function in the KSES HTML text cleaning
library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x
before 1.9.8, allows remote attackers to inject arbitrary web script
or HTML via crafted HTML entities.
|
| CVE-2010-1618 |
Cross-site scripting (XSS) vulnerability in the phpCAS client library
before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before
1.9.8, allows remote attackers to inject arbitrary web script or HTML
via a crafted URL, which is not properly handled in an error message.
|
| CVE-2010-1614 |
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x
before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject
arbitrary web script or HTML via vectors related to (1) the Login-As
feature or (2) when the global search feature is enabled, unspecified
global search forms in the Global Search Engine. NOTE: vector 1 might
be resultant from a cross-site request forgery (CSRF) vulnerability.
|
| CVE-2010-1609 |
Cross-site scripting (XSS) vulnerability in SAP NetWeaver 2004 before
SP21 and 2004s before SP13 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2010-1606 |
Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal
Script allow remote attackers to inject arbitrary web script or HTML
via the (1) search, (2) Keywords, (3) Tags, or (4) Desired City field.
|
| CVE-2010-1594 |
Multiple cross-site scripting (XSS) vulnerabilities in
ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers
to inject arbitrary web script or HTML via (1) the query string, (2)
the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2010-1593 |
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe
before 2.3.5 allow remote attackers to inject arbitrary web script or
HTML via (1) the CommenterURL parameter to PostCommentForm, and in the
Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote
attackers to inject arbitrary web script or HTML via (2) the Search
parameter to forums/search (aka the search script).
|
| CVE-2010-1590 |
Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in
Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might
allow remote attackers to inject arbitrary web script or HTML via the
client's DNS hostname (aka the REMOTE_HOST variable), related to the
CookielessGenerateFilename and CookielessReadFile functions.
|
| CVE-2010-1584 |
Cross-site scripting (XSS) vulnerability in the Context module before
6.x-2.0-rc4 for Drupal allows remote authenticated users, with
Administer Blocks privileges, to inject arbitrary web script or HTML
via a block description.
|
| CVE-2010-1557 |
Multiple cross-site scripting (XSS) vulnerabilities in HP Insight
Control Server Migration before 6.0 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1543 |
Cross-site scripting (XSS) vulnerability in the eTracker module before
6.x-1.2 for Drupal allows remote attackers to inject arbitrary web
script or HTML by appending a crafted string to an arbitrary URL
associated with the Drupal site.
|
| CVE-2010-1542 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
admin/configure.php in DFD Cart 1.198, 1.197, and earlier allow remote
attackers to hijack the authentication of administrators for requests
that (1) conduct cross-site scripting (XSS) attacks or (2) change
unspecified settings.
|
| CVE-2010-1541 |
Multiple cross-site scripting (XSS) vulnerabilities in DFD Cart 1.198,
1.197, and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) category and (2) list_quantity parameters
to index.php, and the (3) category parameter to your.order.php.
|
| CVE-2010-1539 |
Cross-site scripting (XSS) vulnerability in the Workflow module
5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when
used with the Token module, might allow remote authenticated users to
inject arbitrary web script or HTML via a certain Comment field.
|
| CVE-2010-1536 |
Cross-site scripting (XSS) vulnerability in the AddThis Button module
5.x before 5.x-2.2 and 6.x before 6.x-2.9 for Drupal allows remote
authenticated users, with administer addthis privileges, to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1530 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Internationalization module 6.x before 6.x-1.4 for Drupal allow remote
authenticated users, with translate interface or administer blocks
privileges, to inject arbitrary web script or HTML via (1) strings
used in block translation or (2) the untranslated input.
|
| CVE-2010-1520 |
Cross-site scripting (XSS) vulnerability in logout.php in TaskFreak!
Original multi user before 0.6.4 allows remote attackers to inject
arbitrary web script or HTML via the tznMessage parameter.
|
| CVE-2010-1515 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
TomatoCMS 2.0.6 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) keyword or (2) article-id parameter in
conjunction with a /admin/news/article/list PATH_INFO; the (3) keyword
parameter in conjunction with a /admin/multimedia/set/list PATH_INFO;
the (4) keyword or (5) fileId parameter in conjunction with a
/admin/multimedia/file/list PATH_INFO; or the (6) name, (7) email, or
(8) address parameter in conjunction with a /admin/ad/client/list
PATH_INFO.
|
| CVE-2010-1504 |
Cross-site scripting (XSS) vulnerability in Google Chrome before
4.1.249.1059 allows remote attackers to inject arbitrary web script or
HTML via vectors related to a chrome://downloads URI.
|
| CVE-2010-1503 |
Cross-site scripting (XSS) vulnerability in Google Chrome before
4.1.249.1059 allows remote attackers to inject arbitrary web script or
HTML via vectors related to a chrome://net-internals URI.
|
| CVE-2010-1497 |
Cross-site scripting (XSS) vulnerability in download_proc.php in
dl_stats before 2.0 allows remote attackers to inject arbitrary web
script or HTML via the id parameter.
|
| CVE-2010-1489 |
The XSS Filter in Microsoft Internet Explorer 8 does not properly
perform neutering for the SCRIPT tag, which allows remote attackers to
conduct cross-site scripting (XSS) attacks against web sites that have
no inherent XSS vulnerabilities, a different issue than CVE-2009-4074.
|
| CVE-2010-1486 |
Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in
CactuShop before 6.155 allow remote attackers to inject arbitrary web
script or HTML via the (1) billing address or (2) shipping address.
|
| CVE-2010-1482 |
Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the
backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote
attackers to inject arbitrary web script or HTML via the
date_format_string parameter.
|
| CVE-2010-1481 |
Cross-site scripting (XSS) vulnerability in the table feature in
PmWiki 2.2.15 allows remote authenticated users to inject arbitrary
web script or HTML via the width attribute.
|
| CVE-2010-1464 |
Multiple cross-site scripting (XSS) vulnerabilities in WebAsyst
Shop-Script FREE allow remote attackers to inject arbitrary web script
or HTML via the (1) currency_id_left, (2) currency_id_right, (3)
darkcolor, (4) lightcolor, (5) middlecolor, and (6) w parameters.
|
| CVE-2010-1459 |
The default configuration of ASP.NET in Mono before 2.6.4 has a value
of FALSE for the EnableViewStateMac property, which allows remote
attackers to conduct cross-site scripting (XSS) attacks, as
demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in
the XSP sample project.
|
| CVE-2010-1453 |
Cross-site scripting (XSS) vulnerability in the Login form in Piwik
0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web
script or HTML via the form_url parameter.
|
| CVE-2010-1448 |
Cross-site scripting (XSS) vulnerability in lib/LXR/Common.pm in LXR
Cross Referencer before 0.9.8 allows remote attackers to inject
arbitrary web script or HTML via vectors related to a string in the
search page's TITLE element, a different vulnerability than
CVE-2009-4497 and CVE-2010-1625.
|
| CVE-2010-1427 |
Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin
in MODx Evolution before 1.0.3 allows remote attackers to inject
arbitrary web script or HTML via unknown vectors related to
AjaxSearch.
|
| CVE-2010-1420 |
Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari
before 5.0.6 allows remote attackers to inject arbitrary web script or
HTML via a crafted text/plain file.
|
| CVE-2010-1418 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1
on Mac OS X 10.4, allows remote attackers to inject arbitrary web
script or HTML via a FRAME element with a SRC attribute composed of a
javascript: sequence preceded by spaces.
|
| CVE-2010-1395 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1
on Mac OS X 10.4, allows remote attackers to inject arbitrary web
script or HTML via vectors involving DOM constructor objects, related
to a "scope management issue."
|
| CVE-2010-1394 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1
on Mac OS X 10.4, allows remote attackers to inject arbitrary web
script or HTML via vectors involving HTML document fragments.
|
| CVE-2010-1390 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1
on Mac OS X 10.4, allows remote attackers to inject arbitrary web
script or HTML via vectors related to improper UTF-7 canonicalization,
and lack of termination of a quoted string in an HTML document.
|
| CVE-2010-1389 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1
on Mac OS X 10.4, allows user-assisted remote attackers to inject
arbitrary web script or HTML via vectors involving a (1) paste or (2)
drag-and-drop operation for a selection.
|
| CVE-2010-1382 |
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac
OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users
to inject arbitrary web script or HTML via crafted Wiki content,
related to lack of a charset field.
|
| CVE-2010-1373 |
Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac
OS X 10.6 before 10.6.4 allows remote attackers to inject arbitrary
web script or HTML via a crafted help: URL, related to "URL parameters
in HTML content."
|
| CVE-2010-1371 |
Cross-site scripting (XSS) vulnerability in signup.asp in Pre
Classified Listings ASP allows remote attackers to inject arbitrary
web script or HTML via the address parameter.
|
| CVE-2010-1367 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/admin_login.php in Uiga Fan Club, as downloaded on 20100310,
allow remote attackers to inject arbitrary web script or HTML via the
(1) admin_name and (2) admin_password parameters. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2010-1362 |
Cross-site scripting (XSS) vulnerability in the Own Term module
6.x-1.0 for Drupal allows remote authenticated users, with "create
additional terms" privileges, to inject arbitrary web script or HTML
via the term description field in a term listing page.
|
| CVE-2010-1361 |
Cross-site scripting (XSS) vulnerability in
shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows
remote attackers to inject arbitrary web script or HTML via the
darstellen parameter.
|
| CVE-2010-1358 |
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio)
module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows
remote authenticated users, with "administer biblio" privileges, to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1357 |
Cross-site scripting (XSS) vulnerability in editors/logindialogue.php
in SBD Directory Software 4.0 allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2010-1355 |
Cross-site scripting (XSS) vulnerability on the TANDBERG Video
Communication Server (VCS) before X5.0 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka
Reference ID 66316.
|
| CVE-2010-1339 |
Cross-site scripting (XSS) vulnerability in ts_other.php in the
Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows
remote attackers to inject arbitrary web script or HTML via the userid
parameter in a modboard action, which is not properly handled in a
forced SQL error message. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2010-1333 |
Multiple cross-site scripting (XSS) vulnerabilities in Almas Inc.
Compiere J300_A02 and earlier allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1332 |
Cross-site scripting (XSS) vulnerability in PrettyBook PrettyFormMail
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-1330 |
The regular expression engine in JRuby before 1.4.1, when $KCODE is
set to 'u', does not properly handle characters immediately after a
UTF-8 character, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via a crafted string.
|
| CVE-2010-1328 |
Multiple cross-site scripting (XSS) vulnerabilities in TornadoStore
1.4.3 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) tipo or (2) destino parameter to
login_registrese.php3 in the Services section, (3) the rubro parameter
to precios.php3 in the Products section, (4) the arti parameter to
recomenda_articulo.php3 in the Products section, (5) the descrip
parameter in a profile action to control/abm_det.php3 in the
e-Commerce section, (6) the tit parameter in a delivery_courier action
to control/abm_list.php3 in the e-Commerce section, or (7) the tit
parameter in an usuario action to control/abm_det.php3 in the
e-Commerce section.
|
| CVE-2010-1303 |
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy
Filter module 6.x before 6.x-1.1 for Drupal allow remote authenticated
users, with administer taxonomy permissions or create node permissions
when free tagging is enabled, to inject arbitrary web script or HTML
via vocabulary (1) names, (2) terms, and (3) filter menus.
|
| CVE-2010-1293 |
Cross-site scripting (XSS) vulnerability in the Administrator page in
Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1276 |
Multiple cross-site scripting (XSS) vulnerabilities in BBSXP 2008 SP2
allow remote attackers to inject arbitrary web script or HTML via the
URI in a request to (1) AddPost.asp, (2) AddTopic.asp, (3)
Admin_Default.asp, (4) Bank.asp, (5) Manage.asp, and (6) ShowPost.asp.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2010-1275 |
Cross-site scripting (XSS) vulnerability in ShowPost.asp in BBSXP 2008
allows remote attackers to inject arbitrary web script or HTML via the
ThreadID parameter.
|
| CVE-2010-1274 |
Cross-site scripting (XSS) vulnerability in Emweb Wt before 3.1.1
allows remote attackers to inject arbitrary web script or HTML via
vectors related to "insertions of the URL" that occur during a
redirection.
|
| CVE-2010-1257 |
Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as
used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2;
Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1
and SP2; and Internet Explorer 8 allows remote attackers to inject
arbitrary web script or HTML via vectors related to sanitization.
|
| CVE-2010-1242 |
Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web
Interface for Content Management (aka WEBi) before 1.0.4 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-1236 |
The protocolIs function in platform/KURLGoogle.cpp in WebCore in
WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and
Flock Browser 3.x before 3.0.0.4112, does not properly handle
whitespace at the beginning of a URL, which allows remote attackers to
conduct cross-site scripting (XSS) attacks via a crafted javascript:
URL, as demonstrated by a \x00javascript:alert sequence.
|
| CVE-2010-1227 |
Cross-site scripting (XSS) vulnerability in Sun Java System
Communications Express 6.2 and 6.3 allows remote attackers to inject
arbitrary web script or HTML via the subject field of a message, as
demonstrated by a subject containing an IMG element with a SRC
attribute that performs a cross-site request forgery (CSRF) attack
involving the cmd and argv parameters to cmd.msc.
|
| CVE-2010-1218 |
Cross-site scripting (XSS) vulnerability in the mm_forum extension
1.8.2 and earlier for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1210 |
intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before
3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text
in certain circumstances involving undefined positions, which might
make it easier for remote attackers to conduct cross-site scripting
(XSS) attacks via crafted 8-bit text.
|
| CVE-2010-1197 |
Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and
SeaMonkey before 2.0.5, does not properly handle situations in which
both "Content-Disposition: attachment" and "Content-Type: multipart"
are present in HTTP headers, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via an uploaded HTML document.
|
| CVE-2010-1195 |
Cross-site scripting (XSS) vulnerability in the htmlscrubber component
in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote
attackers to inject arbitrary web script or HTML via a crafted
data:image/svg+xml URI.
|
| CVE-2010-1193 |
Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server
2.0 allows remote attackers to inject arbitrary web script or HTML via
vectors related to JSON error messages.
|
| CVE-2010-1186 |
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the
NextGEN Gallery plugin before 1.5.2 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the mode
parameter.
|
| CVE-2010-1164 |
Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA
3.12 through 4.1 allow remote attackers to inject arbitrary web script
or HTML via the (1) element or (2) defaultColor parameter to the
Colour Picker page; the (3) formName parameter, (4) element parameter,
or (5) full name field to the User Picker page; the (6) formName
parameter, (7) element parameter, or (8) group name field to the Group
Picker page; the (9) announcement_preview_banner_st parameter to
unspecified components, related to the Announcement Banner Preview
page; unspecified vectors involving the (10) groupnames.jsp, (11)
indexbrowser.jsp, (12) classpath-debug.jsp, (13) viewdocument.jsp, or
(14) cleancommentspam.jsp page; the (15) portletKey parameter to
runportleterror.jsp; the (16) URI to issuelinksmall.jsp; the (17)
afterURL parameter to screenshot-redirecter.jsp; or the (18) HTTP
Referrer header to 500page.jsp, as exploited in the wild in April
2010.
|
| CVE-2010-1143 |
Cross-site scripting (XSS) vulnerability in VMware View (formerly
Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 build 252693 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-1137 |
Cross-site scripting (XSS) vulnerability in WebAccess in VMware
VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the
Server Console in VMware Server 1.0, allows remote attackers to inject
arbitrary web script or HTML via the name of a virtual machine.
|
| CVE-2010-1113 |
Cross-site scripting (XSS) vulnerability in the forum page in Web
Server Creator - Web Portal 0.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors to index.php.
|
| CVE-2010-1112 |
Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0
allows remote attackers to inject arbitrary web script or HTML via the
cat parameter.
|
| CVE-2010-1111 |
Multiple cross-site scripting (XSS) vulnerabilities in Jokes Complete
Website allow remote attackers to inject arbitrary web script or HTML
via the (1) id parameter to joke.php and the (2) searchingred
parameter to results.php.
|
| CVE-2010-1108 |
Cross-site scripting (XSS) vulnerability in the Control Panel module
5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote
authenticated users, with "administer blocks" privileges, to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1107 |
Cross-site scripting (XSS) vulnerability in the Recent Comments module
5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via a
"custom block title interface."
|
| CVE-2010-1105 |
Cross-site scripting (XSS) vulnerability in cgi/index.php in
AdvertisementManager 3.1.0 and 3.6 allows remote attackers to inject
arbitrary web script or HTML via the usr parameter.
|
| CVE-2010-1104 |
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12,
2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and
2.12.x before 2.12.3 allows remote attackers to inject arbitrary web
script or HTML via vectors related to error messages.
|
| CVE-2010-1095 |
Cross-site scripting (XSS) vulnerability in
login_reset_password_page.php in Tracking Requirements & Use Cases
(TRUC) 0.11.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the error parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2010-1091 |
Multiple cross-site scripting (XSS) vulnerabilities in contact.php in
phpMySite allow remote attackers to inject arbitrary web script or
HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message
parameters.
|
| CVE-2010-1080 |
Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS
1.2.2 allows remote attackers to inject arbitrary web script or HTML
via the f parameter.
|
| CVE-2010-1079 |
Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-1076 |
Cross-site scripting (XSS) vulnerability in index.php in Entry Level
CMS (EL CMS) allows remote attackers to inject arbitrary web script or
HTML via the subj parameter, which is not properly handled in a forced
SQL error message. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2010-1074 |
Cross-site scripting (XSS) vulnerability in the Currency Exchange
module before 6.x-1.2 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to
watchdog logging.
|
| CVE-2010-1072 |
Cross-site scripting (XSS) vulnerability in search.php in Sniggabo CMS
2.21 allows remote attackers to inject arbitrary web script or HTML
via the q parameter.
|
| CVE-2010-1068 |
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi
in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary
web script or HTML via the (1) domainid or (2) classid parameter in a
class action.
|
| CVE-2010-1052 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
AudiStat 1.3 allow remote attackers to inject arbitrary web script or
HTML via the (1) year and (2) mday parameters. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2010-1048 |
Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga
Business Portal allows remote attackers to inject arbitrary web script
or HTML via the textcomment parameter (aka the Comment Box) in a
noentryid action. NOTE: some of these details are obtained from third
party information.
|
| CVE-2010-1036 |
Cross-site scripting (XSS) vulnerability in HP System Insight Manager
before 6.0 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2010-1025 |
Cross-site scripting (XSS) vulnerability in the TGM-Newsletter
(tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1023 |
Cross-site scripting (XSS) vulnerability in the UserTask Center,
Recent (taskcenter_recent) extension 0.1.0 and earlier for TYPO3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-1021 |
Cross-site scripting (XSS) vulnerability in the Typo3 Quixplorer
(t3quixplorer) extension before 1.7.1 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-1020 |
Cross-site scripting (XSS) vulnerability in the Simple Gallery
(sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-1014 |
Cross-site scripting (XSS) vulnerability in the Reports Logfile View
(reports_logview) extension 1.2.1 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-1011 |
Cross-site scripting (XSS) vulnerability in the myDashboard
(mydashboard) extension 0.1.13 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-1008 |
Cross-site scripting (XSS) vulnerability in the Sellector.com Widget
Integration (chsellector) extension before 0.1.2 for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-1005 |
Cross-site scripting (XSS) vulnerability in the Yet another TYPO3
search engine (YATSE) extension before 0.3.2 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-0997 |
Cross-site scripting (XSS) vulnerability in
107_plugins/content/content_manager.php in the Content Management
plugin in e107 before 0.7.20, when the personal content manager is
enabled, allows user-assisted remote authenticated users to inject
arbitrary web script or HTML via the content_heading parameter.
|
| CVE-2010-0979 |
Cross-site scripting (XSS) vulnerability in display.php in
Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to
inject arbitrary web script or HTML via the folder parameter.
|
| CVE-2010-0971 |
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4
allow remote authenticated users, with Instructor privileges, to
inject arbitrary web script or HTML via the (1) Question and (2)
Choice fields in tools/polls/add.php, the (3) Type and (4) Title
fields in tools/groups/create_manual.php, and the (5) Title field in
assignments/add_assignment.php. NOTE: some of these details are
obtained from third party information.
|
| CVE-2010-0963 |
Cross-site scripting (XSS) vulnerability in index.php in dl Download
Ticket Service before 0.7 allows remote attackers to inject arbitrary
web script or HTML via the t parameter, related to an invalid ticket
ID. NOTE: some of these details are obtained from third party
information.
|
| CVE-2010-0959 |
Cross-site scripting (XSS) vulnerability in
WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5
allows remote attackers to inject arbitrary web script or HTML via the
errMsg parameter.
|
| CVE-2010-0949 |
Multiple cross-site scripting (XSS) vulnerabilities in Natychmiast CMS
allow remote attackers to inject arbitrary web script or HTML via the
id_str parameter to (1) index.php and (2) a_index.php.
|
| CVE-2010-0947 |
Cross-site scripting (XSS) vulnerability in post.aspx in Max Network
Technology BBSMAX 3.0, 4.1, and 4.2 allows remote attackers to inject
arbitrary web script or HTML via the action parameter.
|
| CVE-2010-0941 |
Multiple cross-site scripting (XSS) vulnerabilities in eTek Systems
Hit Counter 2.0 allow remote attackers to inject arbitrary web script
or HTML via the PATH_INFO to (1) index.php, (2) inc/login.php, (3)
admin/index.php, and (4) admin/forgot.php.
|
| CVE-2010-0940 |
Cross-site scripting (XSS) vulnerability in guestbook.php in Simple
PHP Guestbook 1.0 allows remote attackers to inject arbitrary web
script or HTML via the action parameter.
|
| CVE-2010-0938 |
Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo
Forum 2.0 allows remote attackers to inject arbitrary web script or
HTML via the id_forum parameter in a post action.
|
| CVE-2010-0936 |
Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK
DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote
attackers to inject arbitrary web script or HTML via the nickname
parameter.
|
| CVE-2010-0927 |
Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in
the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before
8.0.2 allows remote attackers to inject arbitrary web script or HTML
via the BaseTarget parameter in an OpenPage action. NOTE: this may
overlap CVE-2010-0920.
|
| CVE-2010-0921 |
Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes
(aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4
allows remote attackers to hijack the authentication of unspecified
victims via vectors related to lack of "XSS/CSRF Get Filter and
Referer Check fixes."
|
| CVE-2010-0920 |
Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka
Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows
remote attackers to inject arbitrary web script or HTML via vectors
related to lack of "XSS/CSRF Get Filter and Referer Check fixes."
|
| CVE-2010-0828 |
Cross-site scripting (XSS) vulnerability in action/Despam.py in the
Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote
authenticated users to inject arbitrary web script or HTML by creating
a page with a crafted URI.
|
| CVE-2010-0817 |
Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in
Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and
SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers
to inject arbitrary web script or HTML via the cid0 parameter.
|
| CVE-2010-0804 |
Cross-site scripting (XSS) vulnerability in index.php in iBoutique 4.0
allows remote attackers to inject arbitrary web script or HTML via the
key parameter in a products action.
|
| CVE-2010-0797 |
Cross-site scripting (XSS) vulnerability in the T3BLOG extension 0.6.2
and earlier for TYPO3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2010-0784 |
Cross-site scripting (XSS) vulnerability in the Administrative Console
in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-0783 |
Cross-site scripting (XSS) vulnerability in the Administrative Console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0
before 7.0.0.13 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2010-0779 |
Cross-site scripting (XSS) vulnerability in the Administration Console
in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1
before 6.1.0.33, and 7.0 before 7.0.0.11 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-0778 |
Cross-site scripting (XSS) vulnerability in the Administration Console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0
before 7.0.0.11 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2010-0768 |
Cross-site scripting (XSS) vulnerability in the Administration Console
in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1
before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to
inject arbitrary web script or HTML via the URI.
|
| CVE-2010-0754 |
Cross-site scripting (XSS) vulnerability in
index.php/Special/Main/Templates in WikyBlog 1.7.2 and 1.7.3 rc2
allows remote attackers to inject arbitrary web script or HTML via the
which parameter in a copy action.
|
| CVE-2010-0736 |
Cross-site scripting (XSS) vulnerability in the view_queryform
function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before
1.1.4, allows remote attackers to inject arbitrary web script or HTML
via "user-provided input."
|
| CVE-2010-0726 |
Cross-site scripting (XSS) vulnerability in the tb-send.rb (TrackBack
transmission) plugin in tDiary 2.2.2 and earlier allows remote
attackers to inject arbitrary web script or HTML via unknown vectors,
possibly related to the (1) plugin_tb_url and (2) plugin_tb_excerpt
parameters.
|
| CVE-2010-0725 |
Cross-site scripting (XSS) vulnerability in showimg.php in Arab Cart
1.0.2.0 allows remote attackers to inject arbitrary web script or HTML
via the id parameter.
|
| CVE-2010-0716 |
_layouts/Upload.aspx in the Documents module in Microsoft SharePoint
before 2010 uses URLs with the same hostname and port number for a web
site's primary files and individual users' uploaded files (aka
attachments), which allows remote authenticated users to leverage
same-origin relationships and conduct cross-site scripting (XSS)
attacks by uploading TXT files, a related issue to CVE-2008-5026.
NOTE: the vendor disputes the significance of this issue, because
cross-domain isolation can be implemented when needed.
|
| CVE-2010-0715 |
Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM
Lotus Web Content Management (WCM), and IBM Lotus Workplace Web
Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4,
6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM
Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for
WebSphere Portal; allows remote attackers to redirect users to
arbitrary web sites and conduct phishing attacks via the query string.
|
| CVE-2010-0714 |
Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere
Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus
Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0
through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and
6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and
8.1.1.1 for WebSphere Portal; allows remote attackers to inject
arbitrary web script or HTML via the query string.
|
| CVE-2010-0706 |
Cross-site scripting (XSS) vulnerability in the login/prompt component
in Subex Nikira Fraud Management System allows remote attackers to
inject arbitrary web script or HTML via the message parameter.
|
| CVE-2010-0704 |
Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM
WebSphere Portal 6.0.1.5 wp6015_008_01 allows remote attackers to
inject arbitrary web script or HTML via the search field.
|
| CVE-2010-0703 |
Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL
VPN 4.6 allows remote attackers to inject arbitrary web script or HTML
via the reloadFrame parameter.
|
| CVE-2010-0700 |
Cross-site scripting (XSS) vulnerability in index.php in WampServer
2.0i allows remote attackers to inject arbitrary web script or HTML
via the lang parameter.
|
| CVE-2010-0699 |
Cross-site scripting (XSS) vulnerability in index.php in
VideoSearchScript Pro 3.5 allows remote attackers to inject arbitrary
web script or HTML via the q parameter.
|
| CVE-2010-0697 |
Cross-site scripting (XSS) vulnerability in the iTweak Upload module
6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows
remote authenticated users, with create content and upload file
permissions, to inject arbitrary web script or HTML via the file name
of an uploaded file.
|
| CVE-2010-0695 |
Cross-site scripting (XSS) vulnerability in pages/index.php in
BASIC-CMS allows remote attackers to inject arbitrary web script or
HTML via the nav_id parameter.
|
| CVE-2010-0684 |
Cross-site scripting (XSS) vulnerability in createDestination.action
in Apache ActiveMQ before 5.3.1 allows remote authenticated users to
inject arbitrary web script or HTML via the JMSDestination parameter
in a queue action.
|
| CVE-2010-0675 |
Cross-site scripting (XSS) vulnerability in index.php in BGSvetionik
BGS CMS 2.2.1 allows remote attackers to inject arbitrary web script
or HTML via the search parameter in a search action. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-0641 |
Cross-site scripting (XSS) vulnerability in
webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server
(CCS) 5 allows remote attackers to inject arbitrary web script or HTML
via the dest parameter.
|
| CVE-2010-0640 |
Cross-site scripting (XSS) vulnerability in CA eHealth Performance
Manager 6.0.x through 6.2.x, when malicious HTML detection is
disabled, allows remote attackers to inject arbitrary web script or
HTML via a crafted request.
|
| CVE-2010-0636 |
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar
1.2.0, and other versions before 1.2.5, allow remote attackers to
inject arbitrary web script or HTML via the (1) tab parameter to
users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4)
week.php. NOTE: some of these details are obtained from third party
information.
|
| CVE-2010-0617 |
Cross-site scripting (XSS) vulnerability in ajax.php in evalSMSI
2.1.03 allows remote attackers to inject arbitrary web script or HTML
via the return parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2010-0615 |
Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI
2.1.03 allows remote attackers to inject arbitrary web script or HTML
via the reports comment box in a continue_assess action. NOTE: some of
these details are obtained from third party information.
|
| CVE-2010-0607 |
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1
in the Sterlite SAM300 AX Router allows remote attackers to inject
arbitrary web script or HTML via the Stat_Radio parameter.
|
| CVE-2010-0606 |
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket
before 1.6.0 Stable allows remote authenticated users to inject
arbitrary web script or HTML via the f parameter, possibly related to
an error message generated by scp/admin.php.
|
| CVE-2010-0594 |
Cross-site scripting (XSS) vulnerability in Cisco Router and Security
Device Manager (SDM) allows remote attackers to inject arbitrary web
script or HTML via unknown vectors, aka Bug ID CSCtb38467.
|
| CVE-2010-0544 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1
on Mac OS X 10.4, allows remote attackers to inject arbitrary web
script or HTML via vectors related to a malformed URL.
|
| CVE-2010-0541 |
Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in
Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote
attackers to inject arbitrary web script or HTML via a crafted URI
that triggers a UTF-7 error page.
|
| CVE-2010-0494 |
Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7,
and 8 allows user-assisted remote attackers to bypass the Same Origin
Policy and conduct cross-site scripting (XSS) attacks via a crafted
HTML document in a situation where the client user drags one browser
window across another browser window, aka "HTML Element Cross-Domain
Vulnerability."
|
| CVE-2010-0475 |
Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the
Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1
allows remote attackers to inject arbitrary web script or HTML via the
role parameter.
|
| CVE-2010-0470 |
Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend
CT-507IT ADSL Router allows remote attackers to inject arbitrary web
script or HTML via the srvName parameter.
|
| CVE-2010-0468 |
Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in
PaperThin CommonSpot Content Server allows remote attackers to inject
arbitrary web script or HTML via the url parameter.
|
| CVE-2010-0465 |
Cross-site scripting (XSS) vulnerability in the online Documents
functionality in SugarCRM 5.2.x before 5.2.0l and 5.5.x before 5.5.0a
allows remote authenticated users to inject arbitrary web script or
HTML via the Document Name field.
|
| CVE-2010-0460 |
Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php
in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated
users to inject arbitrary web script or HTML via the (1) subject
parameter and (2) contents parameter (aka body) in an insertquestion
action. NOTE: some of these details are obtained from third party
information.
|
| CVE-2010-0455 |
Cross-site scripting (XSS) vulnerability in forum/viewtopic.php in
PunBB 1.3 allows remote attackers to inject arbitrary web script or
HTML via the pid parameter.
|
| CVE-2010-0452 |
Multiple cross-site scripting (XSS) vulnerabilities in HP Project and
Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1
through SP10 and 7.5 through SP3 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-0449 |
Cross-site scripting (XSS) vulnerability in HP SOA Registry Foundation
6.63 and 6.64 allows remote attackers to inject arbitrary web script
or HTML via unknown vectors.
|
| CVE-2010-0440 |
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in
Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used
in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows
remote attackers to inject arbitrary web script or HTML via a crafted
POST parameter, which is not properly handled by an eval statement in
binary/mainv.js that writes to start.html.
|
| CVE-2010-0432 |
Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open
For Business Project (aka OFBiz) 09.04 and earlier, as used in
Opentaps, Neogia, and Entente Oya, allow remote attackers to inject
arbitrary web script or HTML via (1) the productStoreId parameter to
control/exportProductListing, (2) the partyId parameter to
partymgr/control/viewprofile (aka partymgr/control/login), (3) the
start parameter to myportal/control/showPortalPage, (4) an invalid URI
beginning with /facility/control/ReceiveReturn (aka
/crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the
contentId parameter (aka the entityName variable) to
ecommerce/control/ViewBlogArticle, (6) the entityName parameter to
webtools/control/FindGeneric, or the (7) subject or (8) content
parameter to an unspecified component under
ecommerce/control/contactus.
|
| CVE-2010-0376 |
Cross-site scripting (XSS) vulnerability in product_list.php in
JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers
to inject arbitrary web script or HTML via the cat parameter. NOTE:
this issue is reportedly resultant from a forced SQL error message
that occurs from exploitation of CVE-2010-0375.
|
| CVE-2010-0374 |
Cross-site scripting (XSS) vulnerability in the Marketplace
(com_marketplace) component 1.2 for Joomla! allows remote attackers to
inject arbitrary web script or HTML via the catid parameter in a
show_category action to index.php.
|
| CVE-2010-0371 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Hitmaaan Gallery 1.3 allow remote attackers to inject arbitrary web
script or HTML via the (1) gall and (2) levela parameters.
|
| CVE-2010-0370 |
Cross-site scripting (XSS) vulnerability in the Node Blocks module
5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal,
allows remote authenticated users, with permissions to create or edit
content and administer blocks, to inject arbitrary web script or HTML
via the edit-title parameter (aka block title).
|
| CVE-2010-0365 |
Cross-site scripting (XSS) vulnerability in search.php in BitScripts
Bits Video Script 2.04 and 2.05 Gold Beta allows remote attackers to
inject arbitrary web script or HTML via the order parameter.
|
| CVE-2010-0363 |
Cross-site scripting (XSS) vulnerability in Zeus Web Server before
4.3r5, when SSL is enabled for the admin server, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, a different vulnerability than CVE-2002-1785.
|
| CVE-2010-0357 |
Cross-site scripting (XSS) vulnerability in the Login page in IBM
Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6
before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere
Portal allows remote attackers to inject arbitrary web script or HTML
via unspecified parameters.
|
| CVE-2010-0349 |
Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3
0.32 and earlier allows remote attackers to inject arbitrary web
script or HTML via unknown vectors. NOTE: this issue could not be
reproduced by the vendor, but a patch was provided anyway. The
original researcher is reliable.
|
| CVE-2010-0347 |
Cross-site scripting (XSS) vulnerability in the VD / Geomap
(vd_geomap) extension 0.3.1 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-0346 |
Cross-site scripting (XSS) vulnerability in the Tip many friends
(mimi_tipfriends) extension 0.0.2 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-0345 |
Cross-site scripting (XSS) vulnerability in the Majordomo extension
1.1.3 and earlier for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-0335 |
Cross-site scripting (XSS) vulnerability in the Vote rank for news
(vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-0331 |
Cross-site scripting (XSS) vulnerability in the TV21 Talkshow
(tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2010-0328 |
Cross-site scripting (XSS) vulnerability in the Unit Converter
(cs2_unitconv) extension 1.0.4 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-0327 |
Cross-site scripting (XSS) vulnerability in the KJ: Imagelightbox
(kj_imagelightbox2) extension 2.0.0 and earlier for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2008-2490.
|
| CVE-2010-0326 |
Cross-site scripting (XSS) vulnerability in the Developer log (devlog)
extension 2.9.1 and earlier for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-0321 |
Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit
Job Board 3.0 allows remote attackers to inject arbitrary web script
or HTML via the post_id parameter.
|
| CVE-2010-0320 |
Cross-site scripting (XSS) vulnerability in submitlink.php in Glitter
Central Script allows remote attackers to inject arbitrary web script
or HTML via the catid parameter.
|
| CVE-2010-0319 |
Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0
and 2.1 allows remote attackers to inject arbitrary web script or HTML
via the id parameter. NOTE: some of these details are obtained from
third party information.
|
| CVE-2010-0190 |
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat
9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-0171 |
Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x
before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3
allow remote attackers to perform cross-origin keystroke capture, and
possibly conduct cross-site scripting (XSS) attacks, by using the
addEventListener and setTimeout functions in conjunction with a
wrapped object. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2007-3736.
|
| CVE-2010-0170 |
Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected
window.location protection mechanism, which might allow remote
attackers to bypass the Same Origin Policy and conduct cross-site
scripting (XSS) attacks via vectors that are specific to each affected
plugin.
|
| CVE-2010-0162 |
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and
SeaMonkey before 2.0.3, does not properly support the
application/octet-stream content type as a protection mechanism
against execution of web script in certain circumstances involving SVG
and the EMBED element, which allows remote attackers to bypass the
Same Origin Policy and conduct cross-site scripting (XSS) attacks via
an embedded SVG document.
|
| CVE-2010-0152 |
Multiple cross-site scripting (XSS) vulnerabilities in the Local
Management Interface (LMI) on the IBM Proventia Network Mail Security
System (PNMSS) appliance with firmware before 2.5.0.2 allow remote
attackers to inject arbitrary web script or HTML via (1) the date1
parameter to pvm_messagestore.php, (2) the userfilter parameter to
pvm_user_management.php, (3) the ping parameter to sys_tools.php in a
sys_ping.php action, (4) the action parameter to
pvm_cert_commaction.php, (5) the action parameter to
pvm_cert_serveraction.php, (6) the action parameter to
pvm_smtpstore.php, (7) the l parameter to sla/index.php, or (8)
unspecified stored data; and allow remote authenticated users to
inject arbitrary web script or HTML via (9) saved search filters.
|
| CVE-2010-0132 |
Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5
and 1.0 before 1.0.11, when the regular expression search
functionality is enabled, allows remote attackers to inject arbitrary
web script or HTML via vectors related to "search_re input," a
different vulnerability than CVE-2010-0736.
|
| CVE-2009-5145 |
Cross-site scripting (XSS) vulnerability in ZMI pages that use the
manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6,
2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.
|
| CVE-2009-5142 |
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb
1.09 and earlier, as used in Mimbo Pro 2.3.1 and other products,
allows remote attackers to inject arbitrary web script or HTML via the
src parameter.
|
| CVE-2009-5120 |
The default configuration of Apache Tomcat in Websense Manager in
Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP
port 1812 from arbitrary source IP addresses, which makes it easier
for remote attackers to conduct cross-site scripting (XSS) attacks via
UTF-7 text to the 404 error page of a Project Woodstock service on
this port.
|
| CVE-2009-5113 |
Cross-site scripting (XSS) vulnerability in wgarcmin.cgi in WebGlimpse
2.18.7 and earlier allows remote attackers to inject arbitrary web
script or HTML via the DOC parameter.
|
| CVE-2009-5103 |
Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP
allows remote attackers to inject arbitrary web script or HTML via the
email variable.
|
| CVE-2009-5099 |
Cross-site scripting (XSS) vulnerability in ViewAction in Pentaho BI
Server 1.7.0.1062 and earlier allows remote attackers to inject
arbitrary web script or HTML via the outputType parameter.
|
| CVE-2009-5096 |
Cross-site scripting (XSS) vulnerability in the Flag Content module
5.x-2.x before 5.x-2.10 for Drupal allows remote attackers to inject
arbitrary web script or HTML via the Reason parameter.
|
| CVE-2009-5092 |
Cross-site scripting (XSS) vulnerability in the management interface
in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-5086 |
Cross-site scripting (XSS) vulnerability in Appliance Configuration
Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.2 before 4.2r1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-5065 |
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal
Feed Parser (aka feedparser or python-feedparser) before 5.0 allows
remote attackers to inject arbitrary web script or HTML via vectors
involving nested CDATA stanzas.
|
| CVE-2009-5031 |
ModSecurity before 2.5.11 treats request parameter values containing
single quotes as files, which allows remote attackers to bypass
filtering rules and perform other attacks such as cross-site scripting
(XSS) attacks via a single quote in a request parameter in the
Content-Disposition field of a request with a multipart/form-data
Content-Type header.
|
| CVE-2009-5017 |
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong
UTF-8 encoding, which makes it easier for remote attackers to bypass
cross-site scripting (XSS) protection mechanisms via a crafted string,
a different vulnerability than CVE-2010-1210.
|
| CVE-2009-5016 |
Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in
PHP before 5.2.11 makes it easier for remote attackers to bypass
cross-site scripting (XSS) and SQL injection protection mechanisms via
a crafted string that uses overlong UTF-8 encoding, a different
vulnerability than CVE-2010-3870.
|
| CVE-2009-5000 |
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace
(aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x
before 4.0.2.3-P8AE-FP003 allow remote attackers to inject arbitrary
web script or HTML via unspecified parameters to .jsp pages.
|
| CVE-2009-4999 |
Cross-site scripting (XSS) vulnerability in the Workplace (aka WP)
component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before
3.5.1-016 allows remote attackers to inject arbitrary web script or
HTML via the Name field.
|
| CVE-2009-4995 |
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in
SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to
inject arbitrary web script or HTML via the email address field. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2009-4994 |
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in
SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to
inject arbitrary web script or HTML via the search parameter.
|
| CVE-2009-4991 |
Cross-site scripting (XSS) vulnerability in users/resume_register.php
in Omnistar Recruiting allows remote attackers to inject arbitrary web
script or HTML via the job2 parameter.
|
| CVE-2009-4990 |
Cross-site scripting (XSS) vulnerability in the Webform report module
5.x and 6.x for Drupal allows remote attackers to inject arbitrary web
script or HTML via a submission.
|
| CVE-2009-4989 |
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction
Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or
HTML via the txtkeyword parameter in a search action.
|
| CVE-2009-4984 |
Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me
PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary
web script or HTML via the (1) Keywords parameter to search.php and
(2) SearchIndex parameter to browse.php.
|
| CVE-2009-4983 |
Multiple cross-site scripting (XSS) vulnerabilities in Silurus
Classifieds 1.0 allow remote attackers to inject arbitrary web script
or HTML via the ID parameter to (1) category.php and (2)
wcategory.php, and the (3) keywords parameter to search.php.
|
| CVE-2009-4980 |
Multiple cross-site scripting (XSS) vulnerabilities in Photokorn
Gallery 1.81 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) where[] parameter to search.php and (2)
qc parameter to admin.php.
|
| CVE-2009-4976 |
Cross-site scripting (XSS) vulnerability in webkitpart.cpp in
kwebkitpart allows remote attackers to inject arbitrary web script or
HTML via a URL associated with a nonexistent domain name, related to a
"universal XSS" issue, a similar vulnerability to CVE-2010-2536.
|
| CVE-2009-4975 |
Cross-site scripting (XSS) vulnerability in webview.cpp in
QtDemoBrowser allows remote attackers to inject arbitrary web script
or HTML via a URL associated with a nonexistent domain name, related
to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536.
|
| CVE-2009-4972 |
Cross-site scripting (XSS) vulnerability in index.php (aka the log in
page) in SimpleID before 0.6.5 allows remote attackers to inject
arbitrary web script or HTML via the s parameter.
|
| CVE-2009-4963 |
Cross-site scripting (XSS) vulnerability in the Commerce extension
before 0.9.9 for TYPO3 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4956 |
Cross-site scripting (XSS) vulnerability in the Visitor Tracking
(ws_stats) extension before 0.1.2 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4953 |
Cross-site scripting (XSS) vulnerability in the Userdata Create/Edit
(sg_userdata) extension before 0.91.0 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4948 |
Cross-site scripting (XSS) vulnerability in the Store Locator
extension before 1.2.8 for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4945 |
AdPeeps 8.5d1 has a default password of admin for the admin account,
which makes it easier for remote attackers to obtain access via
requests to index.php.
|
| CVE-2009-4944 |
Multiple cross-site scripting (XSS) vulnerabilities in ATRC ACollab
1.2 allow remote attackers to inject arbitrary web script or HTML via
the (1) address parameter to profile.php or the (2) description
parameter to events/add_event.php. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-4943 |
index.php in AdPeeps 8.5d1 allows remote attackers to obtain sensitive
information via (1) a view_adrates action with an invalid uid
parameter, which reveals the installation path in an error message; or
(2) an adminlogin action with a crafted uid parameter, which reveals
the version number.
|
| CVE-2009-4941 |
Cross-site scripting (XSS) vulnerability in sign_in.php in ATRC
ACollab 1.2 allows remote attackers to inject arbitrary web script or
HTML via the f parameter.
|
| CVE-2009-4939 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
AdPeeps 8.5d1 allow remote attackers to inject arbitrary web script or
HTML via the (1) uid parameter, (2) uid parameter in a login_lookup
action, (3) uid parameter in an adminlogin action, (4) campaignid
parameter in a createcampaign action, (5) type parameter in a
view_account_stats action, (6) period parameter in a
view_account_stats action, (7) uid parameter in a view_adrates action,
(8) accname parameter in an account_confirmation action, (9) loginpass
parameter in an account_confirmation action, (10) e9 parameter in a
setup_account action, (11) from parameter in an email_advertisers
action, (12) message parameter in an email_advertisers action, (13)
idno parameter in an edit_ad_package action, (14) Advertiser Name
field, (15) First Name field, (16) Last Name field, (17) Address
field, (18) Phone Number field, (19) Password Hint field, or (20) URL
field; and (21) allow remote authenticated users to inject arbitrary
web script or HTML via an unspecified form associated with a
view_adrates action.
|
| CVE-2009-4937 |
Cross-site scripting (XSS) vulnerability in Small Pirate (SPirate) 2.1
allows remote attackers to inject arbitrary web script or HTML via an
onmouseover action in an img BBCode tag within a url BBCode tag.
|
| CVE-2009-4934 |
Cross-site scripting (XSS) vulnerability in index.php in Online Photo
Pro 2.0 allows remote attackers to inject arbitrary web script or HTML
via the section parameter.
|
| CVE-2009-4930 |
Cross-site scripting (XSS) vulnerability in the
twbkwbis.P_SecurityQuestion (aka Change Security Question) page in
SunGard Banner Student System 7.4 allows remote attackers to inject
arbitrary web script or HTML via the New Question field.
|
| CVE-2009-4926 |
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact
Manager (formerly EContact PRO) 3.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) showGroup parameter to (a)
index.php and the (2) id parameter to (b) view.php, (c) email.php, (d)
edit.php, and (e) delete.php.
|
| CVE-2009-4924 |
Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument
to cjson.encode, which makes it easier for remote attackers to conduct
certain cross-site scripting (XSS) attacks involving Firefox and the
end tag of a SCRIPT element.
|
| CVE-2009-4910 |
Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco
Adaptive Security Appliances (ASA) 5580 series devices with software
before 8.1(2) allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, aka Bug ID CSCsq78418.
|
| CVE-2009-4908 |
Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow
remote attackers to inject arbitrary web script or HTML via the (1)
commentName, (2) commentEmail, (3) commentWeb, or (4) commentText
parameter to article.php; and allow remote authenticated
administrators to inject arbitrary web script or HTML via the (5)
article_id or (6) title parameter to admin/write.php, the (7)
category_id or (8) category_name parameter to admin/groups.php, the
(9) blogroll_id or (10) title parameter to admin/blogroll.php, or the
(11) blog_name or (12) tag_line parameter to admin/settings.php.
|
| CVE-2009-4903 |
Cross-site scripting (XSS) vulnerability in index.php in oBlog allows
remote attackers to inject arbitrary web script or HTML via the search
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2009-4894 |
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in
PunBB before 1.3.4 allow remote attackers to inject arbitrary web
script or HTML via the (1) password or (2) e-mail.
|
| CVE-2009-4890 |
Multiple cross-site scripting (XSS) vulnerabilities in the login
application in vBook 4.2.17 allow remote attackers to inject arbitrary
web script or HTML via the (1) title and (2) message parameters.
|
| CVE-2009-4888 |
Cross-site scripting (XSS) vulnerability in poster.php in PHortail
1.2.1 allows remote attackers to inject arbitrary web script or HTML
via the (1) pseudo, (2) email, (3) ti, and (4) txt parameters.
|
| CVE-2009-4886 |
Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8
allow remote attackers to read arbitrary files via a .. (dot dot) in
the (1) file parameter to module/admin/files/show_file.php and the (2)
path parameter to module/admin/files/show_source.php.
|
| CVE-2009-4885 |
Cross-site scripting (XSS) vulnerability in templates/1/login.php in
phpCommunity 2 2.1.8 allows remote attackers to inject arbitrary web
script or HTML via the msg parameter.
|
| CVE-2009-4884 |
Multiple SQL injection vulnerabilities in phpCommunity 2 2.1.8, when
magic_quotes_gpc is disabled, allow remote attackers to execute
arbitrary SQL commands via (1) the forum_id parameter in a forum
action to index.php, (2) the topic_id parameter in a forum action to
index.php, (3) the wert parameter in an id search action to index.php,
(4) the wert parameter in a nick search action to index.php, or (5)
the wert parameter in a forum search action to index.php, related to
class_forum.php and class_search.php.
|
| CVE-2009-4882 |
Cross-site scripting (XSS) vulnerability in zc/publisher/html.rb in
ZoneCheck 2.0.4-13 and 2.1.0 allows remote attackers to inject
arbitrary web script or HTML via the ns parameter to zc.cgi.
|
| CVE-2009-4869 |
Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest
Book 1.2 allows remote attackers to inject arbitrary web script or
HTML via the page parameter.
|
| CVE-2009-4868 |
Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0
allows remote attackers to inject arbitrary web script or HTML via the
q_id parameter to the answers script (aka answers.php). NOTE: some of
these details are obtained from third party information.
|
| CVE-2009-4866 |
Cross-site scripting (XSS) vulnerability in search.cgi in Matt's
Script Archive (MSA) Simple Search 1.0 allows remote attackers to
inject arbitrary web script or HTML via the terms parameter. NOTE:
some of these details are obtained from third party information.
|
| CVE-2009-4864 |
Multiple cross-site scripting (XSS) vulnerabilities in
escorts_search.php in I-Escorts Directory Script and Agency Script
allow remote attackers to inject arbitrary web script or HTML via the
(1) search_name and (2) languages parameters. NOTE: some of these
details are obtained from third party information.
|
| CVE-2009-4861 |
Cross-site scripting (XSS) vulnerability in shownews.php in SupportPRO
SupportDesk 3.0 allows remote attackers to inject arbitrary web script
or HTML via the PATH_INFO.
|
| CVE-2009-4859 |
Multiple cross-site scripting (XSS) vulnerabilities in Online Work
Order Suite (OWOS) Lite Edition 3.10 allow remote attackers to inject
arbitrary web script or HTML via the show parameter to (1) default.asp
and (2) report.asp, and the (3) go parameter to login.asp.
|
| CVE-2009-4858 |
Cross-site scripting (XSS) vulnerability in questiondetail.php in
Yahoo Answers Clone allows remote attackers to inject arbitrary web
script or HTML via the questionid parameter.
|
| CVE-2009-4857 |
Cross-site scripting (XSS) vulnerability in login.php in PHP Photo
Vote 1.3F allows remote attackers to inject arbitrary web script or
HTML via the page parameter.
|
| CVE-2009-4856 |
Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy
Shopping Cart 3.1R allows remote attackers to inject arbitrary web
script or HTML via the name parameter.
|
| CVE-2009-4853 |
Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before
1.1.2 for Foswiki Wiki System allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4852 |
Multiple cross-site scripting (XSS) vulnerabilities in SemanticScuttle
before 0.94.1 allow remote attackers to inject arbitrary web script or
HTML via the sort parameter to index.php, and other unspecified
vectors, a different issue than CVE-2008-6113. NOTE: some of these
details are obtained from third party information.
|
| CVE-2009-4848 |
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual
VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers
to inject arbitrary web script or HTML via the (1) userId parameter to
tvserver/server/user/setPermissions.jsp, (2) deptName parameter to
tvserver/server/user/addDepartment.jsp, (3) ID parameter to
tvserver/server/inventory/inventoryTabs.jsp, (4) reportName parameter
to tvserver/reports/virtualIQAdminReports.do, or (5) middleName
parameter in a save action to tvserver/user/user.do.
|
| CVE-2009-4842 |
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual
VirtualIQ Pro 3.5 build 8691 allow remote attackers to inject
arbitrary web script or HTML via the (1) addNewDept, (2) deptId, or
(3) deptDesc parameter to tvserver/server/user/addDepartment.jsp; or
the (4) firstName, (5) lastName, or (6) email parameter in a save
action to tvserver/user/user.do. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-4839 |
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis
and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote
attackers to inject arbitrary web script or HTML via unspecified
parameters to (1) admin/base_roleadmin.php, (2)
admin/base_useradmin.php, (3) base_conf_contents.php, (4)
base_qry_sqlcalls.php, and (5) base_ag_main.php.
|
| CVE-2009-4837 |
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis
and Security Engine (BASE) before 1.4.3.1 allow remote attackers to
inject arbitrary web script or HTML via the (1) sig[1] parameter to
base/base_qry_main.php, or the time[0][1] parameter to (2)
base/base_stat_alerts.php or (3) base/base_stat_uaddr.php. NOTE: some
of these details are obtained from third party information.
|
| CVE-2009-4829 |
Cross-site scripting (XSS) vulnerability in the Automated Logout
module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2.3 for Drupal
allows remote authenticated users with administer autologout
privileges to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4823 |
Cross-site scripting (XSS) vulnerability in
frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows
remote attackers to inject arbitrary web script or HTML via the fileop
parameter.
|
| CVE-2009-4822 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web
script or HTML via the (1) do, (2) id, and (3) uname parameters.
|
| CVE-2009-4814 |
Cross-site scripting (XSS) vulnerability in Wolfram Research
webMathematica allows remote attackers to inject arbitrary web script
or HTML via the URI to the MSP script.
|
| CVE-2009-4813 |
Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka
MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary
web script or HTML via the username parameter in a donate action.
|
| CVE-2009-4812 |
Wolfram Research webMathematica allows remote attackers to obtain
sensitive information via a direct request to the MSP script, which
reveals the installation path in an error message.
|
| CVE-2009-4804 |
Cross-site scripting (XSS) vulnerability in the Calendar Base (cal)
extension before 1.1.1 for TYPO3, when Internet Explorer 6 is used,
allows remote attackers to inject arbitrary web script or HTML via
"search parameters."
|
| CVE-2009-4786 |
Multiple cross-site scripting (XSS) vulnerabilities in Pligg before
1.0.3 allow remote attackers to inject arbitrary web script or HTML
via the HTTP Referer header to (1) admin/admin_config.php, (2)
admin/admin_modules.php, (3) delete.php, (4) editlink.php, (5)
submit.php, (6) submit_groups.php, (7) user_add_remove_links.php, and
(8) user_settings.php.
|
| CVE-2009-4782 |
Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS,
possibly 0.01, allow remote attackers to inject arbitrary web script
or HTML via the (1) start, (2) forum, and (3) cat parameters to
community/thread.php; (4) start and (5) cat parameters to
community/forum.php; and (6) start parameter to blog/index.php.
|
| CVE-2009-4780 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web
script or HTML via (1) the lang parameter in a sitemap action, (2) the
search parameter in a search action, (3) the tagging_id parameter in a
search action, (4) the highlight parameter in an artikel action, (5)
the artlang parameter in an artikel action, (6) the letter parameter
in a sitemap action, (7) the lang parameter in a show action, (8) the
cat parameter in a show action, (9) the newslang parameter in a news
action, (10) the artlang parameter in a send2friend action, (11) the
cat parameter in a send2friend action, (12) the id parameter in a
send2friend action, (13) the srclang parameter in a translate action,
(14) the id parameter in a translate action, (15) the cat parameter in
a translate action, (16) the cat parameter in an add action, or (17)
the question parameter in an add action. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-4767 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) input_name and (2) input_text parameters.
NOTE: some of these details are obtained from third party information.
|
| CVE-2009-4746 |
Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels
DreamPoll 3.1 allows remote attackers to inject arbitrary web script
or HTML via the recordsPerPage parameter in a poll_default login
action.
|
| CVE-2009-4744 |
Cross-site scripting (XSS) vulnerability in the Contact module in
Exponent CMS 0.97-GA20090213 allows remote attackers to inject
arbitrary web script or HTML via the email parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2009-4743 |
Multiple cross-site scripting (XSS) vulnerabilities in
history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier
allow remote attackers to inject arbitrary web script or HTML via the
(1) HistoryStorageObjectName and (2) HistoryKey parameters.
|
| CVE-2009-4736 |
Cross-site scripting (XSS) vulnerability in search.php in CommonSense
CMS 5.0 allows remote attackers to inject arbitrary web script or HTML
via the q parameter.
|
| CVE-2009-4729 |
Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media
Script 1.7 allow remote attackers to inject arbitrary web script or
HTML via the (1) pic_id parameter to includes/video_ad.php, (2)
category parameter to linkvideos_listing.php, (3) id parameter to
templates/header1.php, and (4) key parameter to video_listing.php.
|
| CVE-2009-4717 |
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish
WebStatCaffe allow remote attackers to inject arbitrary web script or
HTML via the (1) host parameter to stat/host.php, nodayshow parameter
to (2) mostvisitpage.php and (3) visitorduration.php in stat/, (4)
nopagesmost parameter to stat/mostvisitpagechart.php, and date
parameter to (5) pageviewers.php, (6) pageviewerschart.php, and (7)
referer.php in stat/.
|
| CVE-2009-4716 |
Cross-site scripting (XSS) vulnerability in results.php in EDGEPHP
EZWebSearch allows remote attackers to inject arbitrary web script or
HTML via the language parameter.
|
| CVE-2009-4715 |
Cross-site scripting (XSS) vulnerability in rates.php in Real Time
Currency Exchange allows remote attackers to inject arbitrary web
script or HTML via the Amount parameter.
|
| CVE-2009-4714 |
Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS
Celepar allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to cadastro_usuario.php.
|
| CVE-2009-4713 |
Multiple cross-site scripting (XSS) vulnerabilities in the Qas (aka
Quas) module for XOOPS Celepar allow remote attackers to inject
arbitrary web script or HTML via (1) the cod_categoria parameter to
categoria.php, (2) the opcao parameter to index.php, and the PATH_INFO
to (3) categoria.php and (4) index.php.
|
| CVE-2009-4707 |
Cross-site scripting (XSS) vulnerability in the [Gobernalia] Front End
News Submitter (gb_fenewssubmit) extension 0.1.0 and earlier for TYPO3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4706 |
Cross-site scripting (XSS) vulnerability in the Mailform (mailform)
extension before 0.9.24 for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4705 |
Cross-site scripting (XSS) vulnerability in the Twitter Search
(twittersearch) extension before 0.1.1 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4699 |
Multiple cross-site scripting (XSS) vulnerabilities in SkaDate Dating
allow remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to (1) admin/auth.php and (2) file_uploader.php.
|
| CVE-2009-4697 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
RadNICS Gold 5 allow remote attackers to inject arbitrary web script
or HTML via the (1) order parameter in a ulist action and the (2) fid
parameter in a view_forum action.
|
| CVE-2009-4694 |
Cross-site scripting (XSS) vulnerability in index.php in RadScripts
RadLance Gold 7.5 allows remote attackers to inject arbitrary web
script or HTML via the fid parameter in a view_forum action. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2009-4692 |
Cross-site scripting (XSS) vulnerability in index.php in RadScripts
RadLance Gold 7.5 allows remote attackers to inject arbitrary web
script or HTML via the pr parameter in a ulist action.
|
| CVE-2009-4690 |
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld
Programs Rating Script allow remote attackers to inject arbitrary web
script or HTML via the id parameter to (1) rate.php and (2)
postcomments.php.
|
| CVE-2009-4688 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
PHP Shopping Cart Selling Website Script allow remote attackers to
inject arbitrary web script or HTML via the (1) txtkeywords and (2)
cid parameters.
|
| CVE-2009-4686 |
Cross-site scripting (XSS) vulnerability in account.php in phplemon
AdQuick 2.2.1 allows remote attackers to inject arbitrary web script
or HTML via the red_url parameter.
|
| CVE-2009-4685 |
Cross-site scripting (XSS) vulnerability in celebrities.php in PHP
Scripts Now Astrology allows remote attackers to inject arbitrary web
script or HTML via the day parameter.
|
| CVE-2009-4684 |
Cross-site scripting (XSS) vulnerability in index.php in EZodiak
allows remote attackers to inject arbitrary web script or HTML via the
sign parameter.
|
| CVE-2009-4682 |
Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote
allows remote attackers to inject arbitrary web script or HTML via the
id parameter in a vote action.
|
| CVE-2009-4681 |
Cross-site scripting (XSS) vulnerability in search.php in
phpDirectorySource 1.x allows remote attackers to inject arbitrary web
script or HTML via the st parameter.
|
| CVE-2009-4678 |
Cross-site scripting (XSS) vulnerability in index.php in Winn
Guestbook 2.4 allows remote attackers to inject arbitrary web script
or HTML via the PATH_INFO.
|
| CVE-2009-4677 |
Cross-site scripting (XSS) vulnerability in search.php in phpFK PHP
Forum ohne 7.0.4 allows remote attackers to inject arbitrary web
script or HTML via the search parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-4662 |
Cross-site scripting (XSS) vulnerability in the WebAccess component in
Novell GroupWise 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1 allows
remote attackers to inject arbitrary web script or HTML via the
User.Theme.index parameter.
|
| CVE-2009-4651 |
Multiple cross-site scripting (XSS) vulnerabilities in the Webee
Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla!
allow remote attackers to inject arbitrary web script or HTML via the
(1) color, (2) img, or (3) url BBCode tags in unspecified vectors.
|
| CVE-2009-4649 |
Multiple cross-site scripting (XSS) vulnerabilities in geccBBlite 0.1
allow remote attackers to inject arbitrary web script or HTML via the
postatoda parameter to (1) rispondi.php and (2) scrivi.php, which is
not properly handled in forum.php.
|
| CVE-2009-4647 |
Cross-site scripting (XSS) vulnerability in Accellion Secure File
Transfer Appliance before 7_0_296 allows remote attackers to inject
arbitrary web script or HTML via the username parameter, which is not
properly handled when the administrator views audit logs.
|
| CVE-2009-4616 |
Cross-site scripting (XSS) vulnerability in search.php in MYRE Holiday
Rental Manager allows remote attackers to inject arbitrary web script
or HTML via the cat_id1 parameter.
|
| CVE-2009-4612 |
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP
Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote
attackers to inject arbitrary web script or HTML via the PATH_INFO to
the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3)
jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
|
| CVE-2009-4610 |
Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty
6.x and 7.0.0 allow remote attackers to inject arbitrary web script or
HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature,
or the (2) Name or (3) Value parameter to the default URI for the
Session Dump Servlet under session/.
|
| CVE-2009-4608 |
Cross-site scripting (XSS) vulnerability in Canon IT Solutions Inc.
ACCESSGUARDIAN 3.0.14 and earlier, and 3.5.6 and earlier, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to authentication.
|
| CVE-2009-4602 |
Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x
through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4601 |
Cross-site scripting (XSS) vulnerability in basic_search_result.php in
Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web
script or HTML via the title parameter.
|
| CVE-2009-4596 |
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory
1.2 allows remote attackers to inject arbitrary web script or HTML via
the sup_id parameter in a suppliers details action.
|
| CVE-2009-4590 |
Cross-site scripting (XSS) vulnerability in base_local_rules.php in
Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4589 |
Cross-site scripting (XSS) vulnerability in the Special:Block
implementation in the getContribsLink function in SpecialBlockip.php
in MediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject
arbitrary web script or HTML via the ip parameter.
|
| CVE-2009-4586 |
Multiple cross-site scripting (XSS) vulnerabilities in index.html in
Wowd client before 1.3.1 allow remote attackers to inject arbitrary
web script or HTML via the (1) sortby, (2) tags, or (3) ctx parameter
in a search action.
|
| CVE-2009-4580 |
Multiple cross-site scripting (XSS) vulnerabilities in Hasta Blog 2.3
allow remote attackers to inject arbitrary web script or HTML via the
id parameter to (1) yorumyaz.php and (2) blog.php.
|
| CVE-2009-4579 |
Cross-site scripting (XSS) vulnerability in the Artist avenue
(com_artistavenue) component for Joomla! and Mambo allows remote
attackers to inject arbitrary web script or HTML via the Itemid
parameter to index.php.
|
| CVE-2009-4578 |
Cross-site scripting (XSS) vulnerability in the Facileforms
(com_facileforms) component for Joomla! and Mambo allows remote
attackers to inject arbitrary web script or HTML via the Itemid
parameter to index.php.
|
| CVE-2009-4575 |
Cross-site scripting (XSS) vulnerability in the Q-Personel
(com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via the personel_sira
parameter in a sirala action to index.php.
|
| CVE-2009-4573 |
Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus
(mod_joomulus) module 2.0 for Joomla! allow remote attackers to inject
arbitrary web script or HTML via the tagcloud parameter in a tags
action to (1) tagcloud_ell.swf, (2) tagcloud_eng.swf, (3)
tagcloud_por.swf, (4) tagcloud_rus.swf, and possibly (5)
tagcloud_jpn.swf. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2009-4570 |
Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows
remote attackers to inject arbitrary web script or HTML via the
order_id parameter in an order/order_print action to the default URI.
|
| CVE-2009-4568 |
Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and
Usermin before 1.430 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2009-4567 |
Multiple cross-site scripting (XSS) vulnerabilities in editprofile.php
in Viscacha 0.8 Gold allow remote authenticated users to inject
arbitrary web script or HTML via the (1) skype, (2) yahoo, (3) aol,
(4) msn, or (5) jabber parameter in a profile2 action. NOTE: some of
these details are obtained from third party information.
|
| CVE-2009-4562 |
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in
Zenphoto 1.2.5 allows remote attackers to inject arbitrary web script
or HTML via the from parameter.
|
| CVE-2009-4559 |
Cross-site scripting (XSS) vulnerability in the Submitted By module
6.x before 6.x-1.3 for Drupal allows remote authenticated users, with
"administer content types" privileges, to inject arbitrary web script
or HTML via an input string for "submitted by" text.
|
| CVE-2009-4557 |
Cross-site scripting (XSS) vulnerability in the Image Assist module
5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before
6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15,
a module for Drupal, allows remote authenticated users, with
image-node creation privileges, to inject arbitrary web script or HTML
via a node title.
|
| CVE-2009-4554 |
Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums
2000 3.4.07 allow remote attackers to inject arbitrary web script or
HTML via (1) the url parameter to pop_send_to_friend.asp, related to a
crafted onload attribute of an IMG element; or (2) an onload attribute
in a sound tag.
|
| CVE-2009-4552 |
Cross-site scripting (XSS) vulnerability in the Survey Pro module for
Miniweb 2.0 allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to index.php.
|
| CVE-2009-4548 |
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk
3.x allow remote attackers to inject arbitrary web script or HTML via
the category_id parameter to (1) products.php, (2) article.php, (3)
product_details.php, or (4) reviews.php; the (5) forum_id parameter to
forum.php; or the (6) search_category_id parameter to
products_search.php.
|
| CVE-2009-4547 |
Multiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x
allow remote attackers to inject arbitrary web script or HTML via the
(1) category_id parameter to forums.php, or the forum_id parameter to
(2) forum.php or (3) forum_topic_new.php.
|
| CVE-2009-4544 |
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in
Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers
to inject arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2009-4542 |
Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft
Support Center 2.5 allows remote attackers to inject arbitrary web
script or HTML via the lang parameter.
|
| CVE-2009-4539 |
Cross-site scripting (XSS) vulnerability in main.php in SQLiteManager
1.2.0 allows remote attackers to inject arbitrary web script or HTML
via the redirect parameter.
|
| CVE-2009-4532 |
Cross-site scripting (XSS) vulnerability in the Webform module 5.x
before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows
remote authenticated users, with webform creation privileges, to
inject arbitrary web script or HTML via a field label.
|
| CVE-2009-4525 |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer,
e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before
6.x-1.9, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via crafted data in a list of links.
|
| CVE-2009-4524 |
Cross-site scripting (XSS) vulnerability in the RealName module
6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via a realname (aka real name) element.
|
| CVE-2009-4523 |
Cross-site scripting (XSS) vulnerability in index.php in Zainu 1.0
allows remote attackers to inject arbitrary web script or HTML via the
searchSongKeyword parameter in a SearchSong action.
|
| CVE-2009-4522 |
Cross-site scripting (XSS) vulnerability in search.5.html in
BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web
script or HTML via the search parameter to index.php. NOTE: some of
these details are obtained from third party information.
|
| CVE-2009-4521 |
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse
Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used
in KonaKart and other products, allows remote attackers to inject
arbitrary web script or HTML via the __report parameter.
|
| CVE-2009-4518 |
Cross-site scripting (XSS) vulnerability in the Insert Node module 5.x
before 5.x-1.2 for Drupal allows remote attackers to inject arbitrary
web script or HTML via an inserted node.
|
| CVE-2009-4516 |
Cross-site scripting (XSS) vulnerability in the FAQ Ask module 5.x and
6.x before 6.x-2.0, a module for Drupal, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4514 |
Cross-site scripting (XSS) vulnerability in the OpenSocial
Shindig-Integrator module 5.x and 6.x before 6.x-2.1, a module for
Drupal, allows remote authenticated users, with "create application"
privileges, to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4513 |
Multiple cross-site scripting (XSS) vulnerabilities in the Workflow
module 5.x before 5.x-2.4 and 6.x before 6.x-1.2, a module for Drupal,
allow remote authenticated users, with "administer workflow"
privileges, to inject arbitrary web script or HTML via the name of a
(1) workflow or (2) workflow state.
|
| CVE-2009-4505 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP
Comments Module 1.0.1 allow remote attackers to inject arbitrary web
script or HTML via the name field in a comment, and other unspecified
vectors.
|
| CVE-2009-4497 |
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5
and 0.9.6 allows remote attackers to inject arbitrary web script or
HTML via the i parameter to the ident program.
|
| CVE-2009-4478 |
Multiple cross-site scripting (XSS) vulnerabilities in Xstate Real
Estate 1.0 allow remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to (1) home.html or (2) lands.html.
|
| CVE-2009-4473 |
Multiple cross-site scripting (XSS) vulnerabilities in
WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET
7.6.1.53 and 7.6.6.47, and possibly 7.52 through 7.66sp2, allow remote
attackers to inject arbitrary web script or HTML via the (1) css, (2)
eca, (3) id, and (4) skin parameters. NOTE: some of these details are
obtained from third party information.
|
| CVE-2009-4469 |
Multiple cross-site scripting (XSS) vulnerabilities in
pagenumber.inc.php in phpPowerCards 2.0 allow remote attackers to
inject arbitrary web script or HTML via the (1) PATH_INFO, the (2)
archiv parameter, and the (3) subcat parameter.
|
| CVE-2009-4468 |
Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3
allows remote attackers to inject arbitrary web script or HTML via the
page parameter.
|
| CVE-2009-4464 |
Cross-site scripting (XSS) vulnerability in searchadvance.asp in
Active Business Directory 2 allows remote attackers to inject
arbitrary web script or HTML via the search parameter.
|
| CVE-2009-4461 |
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909
allow remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to (1) contact.php, (2) login.php, and (3) search.php.
|
| CVE-2009-4460 |
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf
Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary
web script or HTML via the rid parameter to (1) index.php, (2)
faq.php, and (3) register.php.
|
| CVE-2009-4459 |
Redmine 0.8.7 and earlier uses the title tag before defining the
character encoding in a meta tag, which allows remote attackers to
conduct cross-site scripting (XSS) attacks and inject arbitrary script
via UTF-7 encoded values in the title parameter to a new issue page,
which may be interpreted as script by Internet Explorer 7 and 8.
|
| CVE-2009-4458 |
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2
and 2.6.0rc2, and possibly other versions, allow remote attackers to
inject arbitrary web script or HTML via the (1) tech parameter to
admin/admin/config.php during a trunks display action, the (2)
description parameter during an Add Zap Channel action, and (3)
unspecified vectors during an Add Recordings action.
|
| CVE-2009-4450 |
Multiple cross-site scripting (XSS) vulnerabilities in map.php in
LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web
script or HTML via the (1) lat, (2) lng, and (3) zom parameters, which
are not properly handled when processed with templates/map.tpl.
|
| CVE-2009-4446 |
Cross-site scripting (XSS) vulnerability in admin.php in
phpInstantGallery 1.1 allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO.
|
| CVE-2009-4433 |
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot
iSupport 1.8 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (a) 5 or (b) 9 field in a post action to
ticket_function.php, reachable through ticket_submit.php and
index.php; (c) the which parameter to function.php, or (d) the which
parameter to index.php, related to knowledgebase_list.php. NOTE: some
of these details are obtained from third party information.
|
| CVE-2009-4429 |
Cross-site scripting (XSS) vulnerability in the Sections module 5.x
before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote
authenticated users with "administer sections" privileges to inject
arbitrary web script or HTML via a section name (aka the Name field).
|
| CVE-2009-4425 |
Cross-site scripting (XSS) vulnerability in index.php in iDevCart 1.09
allows remote attackers to inject arbitrary web script or HTML via the
SEARCH parameter in a browse action.
|
| CVE-2009-4422 |
Multiple cross-site scripting (XSS) vulnerabilities in the
GetURLArguments function in jpgraph.php in Aditus Consulting JpGraph
3.0.6 allow remote attackers to inject arbitrary web script or HTML
via a key to csim_in_html_ex1.php, and other unspecified vectors.
|
| CVE-2009-4416 |
Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare
0.9.16.12, and possibly other versions before 0.9.16.014, allows
remote attackers to inject arbitrary web script or HTML via an
arbitrary parameter whose name begins with the "phpgw_" sequence.
|
| CVE-2009-4408 |
Multiple cross-site scripting (XSS) vulnerabilities in models.parser
in PyForum 1.0.3 and possibly earlier versions, and possibly zForum,
allow remote attackers to inject arbitrary web script or HTML via
crafted BBcode (1) img or (2) url tags, which are not properly handled
when a post is viewed.
|
| CVE-2009-4406 |
Cross-site scripting (XSS) vulnerability in Forms/login1 in American
Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3
or 3.7.0 on AOS 3.3.4, and possibly other versions, allows remote
attackers to inject arbitrary web script or HTML via the
login_username parameter.
|
| CVE-2009-4403 |
Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO. NOTE: some of these details are obtained from third party
information.
|
| CVE-2009-4400 |
Cross-site scripting (XSS) vulnerability in the Parish Administration
Database (ste_parish_admin) extension 0.1.3 and earlier for TYPO3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4398 |
Cross-site scripting (XSS) vulnerability in the Parish of the Holy
Spirit Religious Art Gallery (hs_religiousartgallery) extension 0.1.2
and earlier for TYPO3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2009-4397 |
Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth
Resources Database (pd_resources) extension 0.1.1 and earlier for
TYPO3 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2009-4395 |
Cross-site scripting (XSS) vulnerability in the Random Prayer 2
(ste_prayer2) extension 0.0.3 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4391 |
Cross-site scripting (XSS) vulnerability in the File list (dr_blob)
extension 2.1.1 for TYPO3 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2009-4388 |
Cross-site scripting (XSS) vulnerability in the ListMan (nl_listman)
extension 1.2.1 for TYPO3 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2009-4387 |
The cross-site scripting (XSS) protection mechanism in
ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP)
before 6.1 Build 6104 uses case-sensitive checks for malicious inputs,
which allows remote attackers to inject arbitrary web script or HTML
via the searchtext parameter and other unspecified inputs.
|
| CVE-2009-4384 |
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net
Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web
script or HTML via the (1) pid parameter in a code action to index.php
and the (2) uid parameter in a view action to profile.php.
|
| CVE-2009-4382 |
Cross-site scripting (XSS) vulnerability in module.php in PHPFABER
CMS, possibly 1.3.36, allows remote attackers to inject arbitrary web
script or HTML via the mod parameter.
|
| CVE-2009-4381 |
Cross-site scripting (XSS) vulnerability in index.php in texmedia
Million Pixel Script 3 allows remote attackers to inject arbitrary web
script or HTML via the pa parameter. NOTE: some of these details are
obtained from third party information.
|
| CVE-2009-4379 |
Multiple cross-site scripting (XSS) vulnerabilities in Valarsoft
Webmatic before 3.0.3 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors, a different issue than
CVE-2008-2924.
|
| CVE-2009-4371 |
Cross-site scripting (XSS) vulnerability in the Locale module
(modules/locale/locale.module) in Drupal Core 6.14, and possibly other
versions including 6.15, allows remote authenticated users with
"administer languages" permissions to inject arbitrary web script or
HTML via the (1) Language name in English or (2) Native language name
fields in the Custom language form.
|
| CVE-2009-4370 |
Cross-site scripting (XSS) vulnerability in the Menu module
(modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows
remote authenticated users with permissions to create new menus to
inject arbitrary web script or HTML via a menu description, which is
not properly handled in the menu administration overview.
|
| CVE-2009-4369 |
Cross-site scripting (XSS) vulnerability in the Contact module
(modules/contact/contact.admin.inc or modules/contact/contact.module)
in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote
authenticated users with "administer site-wide contact form"
permissions to inject arbitrary web script or HTML via the contact
category name.
|
| CVE-2009-4366 |
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez
Blog 1.0 allows remote attackers to inject arbitrary web script or
HTML via the yr parameter in a bmonth action.
|
| CVE-2009-4364 |
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez
Blog allows remote attackers to inject arbitrary web script or HTML
via the cname parameter, related to the act and id parameters. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2009-4363 |
Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application
Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde
Groupware Webmail Edition before 1.2.5 does not properly handle data:
URIs, which allows remote attackers to conduct cross-site scripting
(XSS) attacks via data:text/html values for the HREF attribute of an A
element in an HTML e-mail message. NOTE: the vendor states that the
issue is caused by "an XSS vulnerability in Firefox browsers."
|
| CVE-2009-4359 |
Cross-site scripting (XSS) vulnerability in folder.php in the
SmartMedia 0.85 Beta module for XOOPS allows remote attackers to
inject arbitrary web script or HTML via the categoryid parameter.
|
| CVE-2009-4352 |
Multiple cross-site scripting (XSS) vulnerabilities in TransWARE
Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other
versions before 2003.0139.0939, allow remote attackers to inject
arbitrary web script or HTML via the (1) From, (2) To, (3) Cc, and (4)
Bcc parameters.
|
| CVE-2009-4348 |
Cross-site scripting (XSS) vulnerability in index.php in Harold
Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to inject
arbitrary web script or HTML via the topic parameter in a topic
action, a different vector than CVE-2006-2146.
|
| CVE-2009-4347 |
Cross-site scripting (XSS) vulnerability in daloradius-users/login.php
in daloRADIUS 0.9-8 and earlier allows remote attackers to inject
arbitrary web script or HTML via the error parameter.
|
| CVE-2009-4346 |
Cross-site scripting (XSS) vulnerability in the Frontend news
submitter with RTE (fe_rtenews) extension 1.4.1 and earlier for TYPO3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4345 |
Cross-site scripting (XSS) vulnerability in the vShoutbox (vshoutbox)
extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2009-4344 |
Cross-site scripting (XSS) vulnerability in the ZID Linkliste
(zid_linklist) extension 1.0.0 for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4343 |
Cross-site scripting (XSS) vulnerability in the Training Company
Database (trainincdb) extension 0.4.7 for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4340 |
Cross-site scripting (XSS) vulnerability in the No indexed Search
(no_indexed_search) extension 0.2.0 for TYPO3 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4336 |
Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth
Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4320 |
Cross-site scripting (XSS) vulnerability in searchform.php in The Next
Generation of Genealogy Sitebuilding (TNG) 7.1.2 allows remote
attackers to inject arbitrary web script or HTML via the msg
parameter.
|
| CVE-2009-4318 |
Cross-site scripting (XSS) vulnerability in index.php in Real Estate
Manager 1.0.1 allows remote attackers to inject arbitrary web script
or HTML via the lang parameter. NOTE: some of these details are
obtained from third party information.
|
| CVE-2009-4317 |
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez
Cart allows remote attackers to inject arbitrary web script or HTML
via the sid parameter in a showcat action.
|
| CVE-2009-4316 |
Cross-site scripting (XSS) vulnerability in searchresults_main.php in
ZeeLyrics 3x allows remote attackers to inject arbitrary web script or
HTML via the keyword parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-4266 |
Cross-site scripting (XSS) vulnerability in search.php in YABSoft
Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows
remote attackers to inject arbitrary web script or HTML via the text
parameter.
|
| CVE-2009-4255 |
Cross-site scripting (XSS) vulnerability in the You!Hostit! template
1.0.1 for Joomla! allows remote attackers to inject arbitrary web
script or HTML via the created_by_alias parameter in index.php.
|
| CVE-2009-4253 |
Cross-site scripting (XSS) vulnerability in dspStats.php in
PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web
script or HTML via the edit parameter.
|
| CVE-2009-4252 |
Cross-site scripting (XSS) vulnerability in images.php in Image
Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject
arbitrary web script or HTML via the date parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2009-4250 |
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP
CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attackers to
inject arbitrary web script or HTML via (1) the result parameter to
register.php; (2) the user parameter to search.php; the (3) cat_msg,
(4) source_msg, (5) postponed_selected, (6) unapproved_selected, and
(7) news_per_page parameters in a list action to the editnews module
of index.php; and (8) the link tag in news comments. NOTE: some of the
vulnerabilities require register_globals to be enabled and/or
magic_quotes_gpc to be disabled.
|
| CVE-2009-4249 |
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP
CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc
is disabled, allow remote attackers to inject arbitrary web script or
HTML via the (1) lastusername and (2) mod parameters to index.php; and
(3) the title parameter to search.php.
|
| CVE-2009-4239 |
Cross-site scripting (XSS) vulnerability in the Web console in IBM
InfoSphere Information Server 8.1 before FP1 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4238 |
Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow
remote authenticated users to execute arbitrary SQL commands via (1)
the Test Case ID field to lib/general/navBar.php or (2) the logLevel
parameter to lib/events/eventviewer.php.
|
| CVE-2009-4237 |
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before
1.8.5 allow remote attackers to inject arbitrary web script or HTML
via (1) the req parameter to login.php, and allow remote authenticated
users to inject arbitrary web script or HTML via (2) the key parameter
to lib/general/staticPage.php, (3) the tableName parameter to
lib/attachments/attachmentupload.php, or the (4) startDate, (5)
endDate, or (6) logLevel parameter to lib/events/eventviewer.php; (7)
the search_notes_string parameter to
lib/results/resultsMoreBuilds_buildReport.php; or the (8)
expected_results, (9) name, (10) steps, or (11) summary parameter in a
find action to lib/testcases/searchData.php, related to
lib/functions/database.class.php.
|
| CVE-2009-4234 |
Cross-site scripting (XSS) vulnerability in
loginpages/error_user.shtml on the Micronet Network Access Controller
SP1910 allows remote attackers to inject arbitrary web script or HTML
via the msg parameter.
|
| CVE-2009-4233 |
Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php
in the YJ Whois component 1.0x and 1.5.x for Joomla! allows remote
attackers to inject arbitrary web script or HTML via the domain
parameter to index.php. NOTE: some of these details are obtained from
third party information.
|
| CVE-2009-4214 |
Cross-site scripting (XSS) vulnerability in the strip_tags function in
Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote
attackers to inject arbitrary web script or HTML via vectors involving
non-printing ASCII characters, related to HTML::Tokenizer and
actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
|
| CVE-2009-4209 |
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php
in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) cat and (2) file parameters in an editsite
action, different vectors than CVE-2008-6127 and CVE-2009-1367.
|
| CVE-2009-4207 |
Cross-site scripting (XSS) vulnerability in the Webform module 5.x
before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via a
submission.
|
| CVE-2009-4196 |
Multiple cross-site scripting (XSS) vulnerabilities in multiple
scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware
3.7.9.98 allow remote attackers to inject arbitrary web script or HTML
via the (1) BackButton parameter to error_1; (2) wzConnFlag parameter
to fresh_pppoe_1; (3) diag_pppindex_argen and (4) DiagStartFlag
parameters to rpDiag_argen_1; (5) wzdmz_active and (6) wzdmzHostIP
parameters to rpNATdmz_argen_1; (7) wzVIRTUALSVR_endPort, (8)
wzVIRTUALSVR_endPortLocal, (9) wzVIRTUALSVR_IndexFlag, (10)
wzVIRTUALSVR_localIP, (11) wzVIRTUALSVR_startPort, and (12)
wzVIRTUALSVR_startPortLocal parameters to rpNATvirsvr_argen_1; (13)
Connect_DialFlag, (14) Connect_DialHidden, and (15) Connect_Flag
parameters to rpStatus_argen_1; (16) Telephone_select, and (17)
wzFirstFlag parameters to rpwizard_1; and (18) wzConnectFlag parameter
to rpwizPppoe_1.
|
| CVE-2009-4187 |
Multiple cross-site scripting (XSS) vulnerabilities in the Gateway
component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4185 |
Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in
HP System Management Homepage (SMH) before 6.0 allows remote attackers
to inject arbitrary web script or HTML via the servercert parameter.
|
| CVE-2009-4172 |
Cross-site scripting (XSS) vulnerability in index.php in CutePHP
CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quotes_gpc is
disabled, allows remote attackers to inject arbitrary web script or
HTML via the body of a news article in an addnews action.
|
| CVE-2009-4169 |
Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the
WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4168 |
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as
used in the WP-Cumulus plugin before 1.23 for WordPress and the
Joomulus module 2.0 and earlier for Joomla!, allows remote attackers
to inject arbitrary web script or HTML via the tagcloud parameter in a
tags action.
Cross-site scripting (XSS) vulnerability in tagcloud.swf in the
WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers
to inject arbitrary web script or HTML via the tagcloud parameter.
|
| CVE-2009-4164 |
Cross-site scripting (XSS) vulnerability in the simple Glossar
(simple_glossar) extension 1.0.3 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4161 |
Cross-site scripting (XSS) vulnerability in the [AN] Search it!
(an_searchit) extension 2.4.1 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4159 |
Cross-site scripting (XSS) vulnerability in the newsletter
configuration feature in the backend module in the Direct Mail
(direct_mail) extension 2.6.4 and earlier for TYPO3 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4157 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
the ProofReader (com_proofreader) component 1.0 RC9 and earlier for
Joomla! allow remote attackers to inject arbitrary web script or HTML
via the URI, which is not properly handled in (1) 404 or (2) error
pages.
|
| CVE-2009-4152 |
Cross-site scripting (XSS) vulnerability in the Collaboration
component in IBM WebSphere Portal 6.1.x before 6.1.0.3 allows remote
attackers to inject arbitrary web script or HTML via the people picker
tag.
|
| CVE-2009-4149 |
Cross-site scripting (XSS) vulnerability in the web interface in CA
Service Desk 12.1 allows remote attackers to inject arbitrary web
script or HTML via an unspecified parameter.
|
| CVE-2009-4142 |
The htmlspecialchars function in PHP before 5.2.12 does not properly
handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences,
and (3) invalid EUC-JP sequences, which allows remote attackers to
conduct cross-site scripting (XSS) attacks by placing a crafted byte
sequence before a special character.
|
| CVE-2009-4119 |
Cross-site scripting (XSS) vulnerability in Feed Element Mapper module
5.x before 5.x-1.3, 6.x before 6.x-1.3, and 6.x-2.0-alpha before
6.x-2.0-alpha4 for Drupal allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2009-4110 |
Cross-site scripting (XSS) vulnerability in the search functionality
in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject
arbitrary web script or HTML via search terms that are not properly
filtered before display in a custom results page.
|
| CVE-2009-4093 |
Multiple cross-site scripting (XSS) vulnerabilities in comments.php in
Simplog 0.9.3.2, and possibly earlier, allow remote attackers to
inject arbitrary web script or HTML via the (1) cname (Name) or (2)
email parameters.
|
| CVE-2009-4087 |
Cross-site scripting (XSS) vulnerability in index.php in telepark.wiki
2.4.23 and earlier allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO.
|
| CVE-2009-4083 |
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.16 and
earlier allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors in (1) submitnews.php, (2) usersettings.php;
and (3) newpost.php, (4) banlist.php, (5) banner.php, (6) cpage.php,
(7) download.php, (8) users_extended.php, (9) frontpage.php, (10)
links.php, and (11) mailout.php in e107_admin/. NOTE: this may overlap
CVE-2004-2040 and CVE-2006-4794, but there are insufficient details to
be certain.
|
| CVE-2009-4078 |
Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5
and earlier allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2009-4074 |
The XSS Filter in Microsoft Internet Explorer 8 allows remote
attackers to leverage the "response-changing mechanism" to conduct
cross-site scripting (XSS) attacks against web sites that have no
inherent XSS vulnerabilities, related to the details of output
encoding and improper modification of an HTML attribute, aka "XSS
Filter Script Handling Vulnerability."
|
| CVE-2009-4071 |
Opera before 10.10, when exception stacktraces are enabled, places
scripting error messages from a web site into variables that can be
read by a different web site, which allows remote attackers to obtain
sensitive information or conduct cross-site scripting (XSS) attacks
via unspecified vectors.
|
| CVE-2009-4069 |
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14,
4.7.3, and possibly other versions allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4065 |
Cross-site scripting (XSS) vulnerability in the settings page in the
Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers
to inject arbitrary web script or HTML via the value field when
viewing overridden variables.
|
| CVE-2009-4064 |
Cross-site scripting (XSS) vulnerability in the Gallery Assist module
6.x before 6.x-1.7 for Drupal allows remote attackers to inject
arbitrary web script or HTML via node titles.
|
| CVE-2009-4063 |
Cross-site scripting (XSS) vulnerability in the Subgroups for Organic
Groups (OG) module 5.x before 5.x-4.0 and 5.x before 5.x-3.4 for
Drupal allows remote attackers to inject arbitrary web script or HTML
via unspecified node titles.
|
| CVE-2009-4062 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Printfriendly module 6.x before 6.x-1.6 for Drupal allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4061 |
Multiple cross-site scripting (XSS) vulnerabilities in the Agreement
module 6.x before 6.x-1.2 for Drupal allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4052 |
Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget
Library Runtime in IBM Rational Application Developer for WebSphere
Software before 7.0.0.10 and Rational Software Architect before
7.0.0.10 allow remote attackers to inject arbitrary web script or HTML
via vectors involving (1) the JSF Tree Control and (2) the JavaScript
Resource Servlet.
|
| CVE-2009-4047 |
Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk
1.43 allow remote attackers to inject arbitrary web script or HTML via
(1) the PATH_INFO to area.php; the (2) pagina, (3) sentido, (4)
q_registros, and (5) orden parameters to area.php; (6) the q_registros
parameter to solic_display.php; (7) the PATH_INFO to area_list.php;
(8) the q_registros parameter to area_list.php; (9) the PATH_INFO to
atributo.php; the (10) pagina, (11) q_registros, and (12) orden
parameters to atributo_list.php; (13) an arbitrary parameter name
beginning with "sentido" to atributo_list.php; and (14) the PATH_INFO
to caso_insert.php. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2009-4043 |
Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x
before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote
attackers to inject arbitrary web script or HTML via a node title.
|
| CVE-2009-4042 |
Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x
before 6.x-1.5 for Drupal allows remote attackers to inject arbitrary
web script or HTML via the URI.
|
| CVE-2009-4040 |
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and
2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows
remote attackers to inject arbitrary web script or HTML via
unspecified parameters to the search page.
|
| CVE-2009-4039 |
Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4038 |
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software
Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject
arbitrary web script or HTML via the (1) onok or (2) oncancel
parameter to the logon program. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-4032 |
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e
allow remote attackers to inject arbitrary web script or HTML via
vectors related to (1) graph.php, (2) include/top_graph_header.php,
(3) lib/html_form.php, and (4) lib/timespan_settings.php, as
demonstrated by the (a) graph_end or (b) graph_start parameters to
graph.php; (c) the date1 parameter in a tree action to graph_view.php;
and the (d) page_refresh and (e) default_dual_pane_width parameters to
graph_settings.php.
|
| CVE-2009-3988 |
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and
SeaMonkey before 2.0.3, does not properly restrict read access to
object properties in showModalDialog, which allows remote attackers to
bypass the Same Origin Policy and conduct cross-site scripting (XSS)
attacks via crafted dialogArguments values.
|
| CVE-2009-3956 |
The default configuration of Adobe Reader and Acrobat 9.x before 9.3,
and 8.x before 8.2 on Windows and Mac OS X, does not enable the
Enhanced Security feature, which has unspecified impact and attack
vectors, related to a "script injection vulnerability," as
demonstrated by Acrobat Forms Data Format (FDF) behavior that allows
cross-site scripting (XSS) by user-assisted remote attackers.
|
| CVE-2009-3950 |
Multiple cross-site scripting (XSS) vulnerabilities in Bractus
SunTrack allow remote attackers to inject arbitrary web script or HTML
via the (1) title parameter to newprofile.html; the (2) firstname, (3)
lastname, and (4) company parameters to signup/signup.html; and the
(5) firstname, (6) lastname, and (7) address[0].street1 parameters to
contact.html.
|
| CVE-2009-3919 |
Cross-site scripting (XSS) vulnerability in the NGP COO/CWP
Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows
remote attackers to inject arbitrary web script or HTML via
unspecified "user-supplied information."
|
| CVE-2009-3918 |
Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x
before 5.x-2.2 and 6.x before 6.x-1.4, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via the node
title.
|
| CVE-2009-3917 |
Cross-site scripting (XSS) vulnerability in the S5 Presentation Player
module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to
inject arbitrary web script or HTML via an unspecified field that is
copied to the HTML HEAD element.
|
| CVE-2009-3916 |
Cross-site scripting (XSS) vulnerability in the Node Hierarchy module
5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via a child
node title.
|
| CVE-2009-3915 |
Cross-site scripting (XSS) vulnerability in the "Separate title and
URL" formatter in the Link module 5.x before 5.x-2.6 and 6.x before
6.x-2.7, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via the link title field.
|
| CVE-2009-3914 |
Cross-site scripting (XSS) vulnerability in the Temporary Invitation
module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via the Name field in an invitation.
|
| CVE-2009-3911 |
Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery
0.13 allows remote attackers to inject arbitrary web script or HTML
via the sample parameter.
|
| CVE-2009-3905 |
Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS
allow remote attackers to inject arbitrary web script or HTML via the
UserGUID parameter to (1) Wizard_tracking.asp, (2) wizard_oe2.asp, (3)
your-register.asp, (4) main-whyregister.asp, and (5) your.asp in
home/, and other unspecified vectors. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-3903 |
Multiple cross-site scripting (XSS) vulnerabilities in jspui/index.jsp
in ManageEngine Netflow Analyzer 7.5 build 7500 allow remote attackers
to inject arbitrary web script or HTML via the (1) view and (2)
section parameters. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2009-3901 |
Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS
allow remote attackers to inject arbitrary web script or HTML via the
UserGUID parameter to home/index.asp and other unspecified vectors.
|
| CVE-2009-3892 |
Cross-site scripting (XSS) vulnerability in Best Practical Solutions
RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and other 3.4.6 through
3.8.4 versions allows remote attackers to inject arbitrary web script
or HTML via certain Custom Fields.
|
| CVE-2009-3891 |
Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in
WordPress before 2.8.6 allows remote authenticated users to inject
arbitrary web script or HTML via the s parameter (aka the selection
variable).
|
| CVE-2009-3858 |
Cross-site scripting (XSS) vulnerability in GejoSoft allows remote
attackers to inject arbitrary web script or HTML via the PATH_INFO to
the default URI in photos/tags.
|
| CVE-2009-3856 |
Cross-site scripting (XSS) vulnerability in the default URI in news/
in Twilight CMS before 4.1 allows remote attackers to inject arbitrary
web script or HTML via the calendar parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2009-3833 |
Cross-site scripting (XSS) vulnerability in index.php in TFTgallery
0.13 allows remote attackers to inject arbitrary web script or HTML
via the album parameter.
|
| CVE-2009-3821 |
Cross-site scripting (XSS) vulnerability in the Apache Solr Search
(solr) extension 1.0.0 for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-3816 |
Multiple cross-site scripting (XSS) vulnerabilities in Activities
pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-3803 |
Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS
5.4.0.0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the status_message parameter to (1) /news, (2)
/comment, (3) /forum, (4) /blog, and (5) /tags; the status_message
parameter to (6) forum.php, (7) discussion.php, (8) guestbook.php, (9)
blog.php, (10) news.php, (11) srv_updates.php, (12) srv_backups.php,
(13) srv_twist_prevention.php, (14) srv_tags.php, (15)
srv_tags_reindex.php, (16) google_sitemap.php, (17)
sitemap_history.php, (18) srv_options.php, (19) locales.php and (20)
plugins_wizard.php in _admin/; a crafted IMG BBcode tag in the message
body of a (21) forum, (22) guestbook, or (23) comment; (24) the
content of an avatar file, which is not properly handled by Internet
Explorer; and (25) the loginname parameter (aka username) in
_admin/index.php.
|
| CVE-2009-3789 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan
1.2.5 allow remote attackers to inject arbitrary web script or HTML
via the last_message parameter to (1) add.php, (2) toBePublished.php,
(3) index.php, and (4) admin.php; the PATH_INFO to the default URI to
(5) category.php, (6) department.php, (7) profile.php, (8)
rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php,
and (12) view_file.php; and (13) the caller parameter in a Modify User
action to user.php.
|
| CVE-2009-3786 |
Cross-site scripting (XSS) vulnerability in Organic Groups (OG)
Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for
Drupal, allows remote attackers to inject arbitrary web script or HTML
via the group title.
|
| CVE-2009-3783 |
Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x
before 6.x-2.0, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via unspecified vector.
|
| CVE-2009-3780 |
Cross-site scripting (XSS) vulnerability in Abuse 5.x before 5.x-2.1
and 6.x before 6.x-1.1-alpha1, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-3779 |
Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4
and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors,
related to the addition of the theme_vcard function to a theme and the
use of default content.
|
| CVE-2009-3757 |
Multiple cross-site scripting (XSS) vulnerabilities in sample code in
the XenServer Resource Kit in Citrix XenCenterWeb allow remote
attackers to inject arbitrary web script or HTML via the (1) username
parameter to config/edituser.php; (2) location, (3) sessionid, and (4)
vmname parameters to console.php; (5) vmrefid and (6) vmname
parameters to forcerestart.php; and (7) vmname and (8) vmrefid
parameters to forcesd.php. NOTE: some of these details are obtained
from third party information.
|
| CVE-2009-3755 |
Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96
allow remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to (1) index.php and (2) modules\base\myaccount.php; and the
PATH_INFO to (3) modules_view.php, (4) tabledefs_options.php, and (5)
adminsettings.php in phpbms\modules\base\.
|
| CVE-2009-3751 |
Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0
allows remote attackers to inject arbitrary web script or HTML via the
genres_parent parameter.
|
| CVE-2009-3748 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web
Administrator in Websense Personal Email Manager 7.1 before Hotfix 4
and Email Security 7.1 before Hotfix 4 allow remote attackers to
inject arbitrary web script or HTML via the (1) FileName, (2)
IsolatedMessageID, (3) ServerName, (4) Dictionary, (5) Scoring, and
(6) MessagePart parameters to
web/msgList/viewmsg/actions/msgAnalyse.asp; the (7) Queue, (8)
FileName, (9) IsolatedMessageID, and (10) ServerName parameters to
actions/msgForwardToRiskFilter.asp and viewHeaders.asp in
web/msgList/viewmsg/; and (11) the subject in an e-mail message that
is held in a Queue.
|
| CVE-2009-3747 |
Cross-site scripting (XSS) vulnerability in index.php in TBmnetCMS 1.0
allows remote attackers to inject arbitrary web script or HTML via the
content parameter. NOTE: this was originally reported for tbmnet.php,
but that program does not exist in the TBmnetCMS 1.0 distribution.
|
| CVE-2009-3745 |
Cross-site scripting (XSS) vulnerability in the help pages in IBM
Rational AppScan Enterprise Edition 5.5.0.2 allows remote attackers to
inject arbitrary web script or HTML via the query string.
|
| CVE-2009-3742 |
Cross-site scripting (XSS) vulnerability in Liferay Portal before
5.3.0 allows remote attackers to inject arbitrary web script or HTML
via the p_p_id parameter.
|
| CVE-2009-3731 |
Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help
2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156;
VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware
vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x
before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher
2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through
2008.4, and 2009.x before 2009.3 allow remote attackers to inject
arbitrary web script or HTML via (1) wwhelp_entry.html, reachable
through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3)
wwhelp/wwhimpl/common/html/frameset.htm, (4)
wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener
component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a)
unspecified parameters and (b) messages used in topic links for the
bookmarking functionality.
|
| CVE-2009-3730 |
Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help
feature (aka the Web Client Help system) in IBM Rational RequisitePro
7.1.0 allow remote attackers to inject arbitrary web script or HTML
via (1) the operation parameter to ReqWebHelp/advanced/workingSet.jsp,
or the (2) searchWord, (3) maxHits, (4) scopedSearch, or (5) scope
parameter to ReqWebHelp/basic/searchView.jsp.
|
| CVE-2009-3719 |
Cross-site scripting (XSS) vulnerability in comment.asp in Battle Blog
1.25 and 1.30 build 2 allows remote attackers to inject arbitrary web
script or HTML via a comment.
|
| CVE-2009-3714 |
Cross-site scripting (XSS) vulnerability in admin_login.php in
MCshoutbox 1.1 allows remote attackers to inject arbitrary web script
or HTML via the loginerror parameter.
|
| CVE-2009-3701 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administration interface in Horde Application Framework before 3.3.6,
Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition
before 1.2.5 allow remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3)
sqlshell.php in admin/, related to the PHP_SELF variable.
|
| CVE-2009-3696 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before
2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject
arbitrary web script or HTML via a crafted name for a MySQL table.
|
| CVE-2009-3668 |
Cross-site scripting (XSS) vulnerability in ardguest.php in Ardguest
1.8 allows remote attackers to inject arbitrary web script or HTML via
the page parameter.
|
| CVE-2009-3666 |
Cross-site scripting (XSS) vulnerability in index.php in Nullam Blog
0.1.2 allows remote attackers to inject arbitrary web script or HTML
via the e parameter in an error action.
|
| CVE-2009-3653 |
Cross-site scripting (XSS) vulnerability in the additional links
interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote
authenticated users, with "administer site configuration" permission,
to inject arbitrary web script or HTML via unspecified vectors,
related to link path output.
|
| CVE-2009-3652 |
Cross-site scripting (XSS) vulnerability in Organic Groups (OG)
5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before
6.x-1.4, a module for Drupal, allows remote authenticated users, with
create or edit group nodes permissions, to inject arbitrary web script
or HTML via the User-Agent HTTP header, a different issue than
CVE-2008-3095.
|
| CVE-2009-3651 |
Cross-site scripting (XSS) vulnerability in the "Monitor browsers'
feature in Browscap before 5.x-1.1 and 6.x-1.1, a module for Drupal,
allows remote attackers to inject arbitrary web script or HTML via the
User-Agent HTTP header.
|
| CVE-2009-3650 |
Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier
and 6.x-1.0-rc1 and earlier, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-3649 |
Cross-site scripting (XSS) vulnerability in forums/index.php in Power
Bulletin Board (PBBoard) 2.0.2 and possibly earlier allows remote
attackers to inject arbitrary web script or HTML via the id parameter
in a new_topic action.
|
| CVE-2009-3648 |
Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a
module for Drupal, allows remote authenticated users, with 'administer
content types' permissions, to inject arbitrary web script or HTML via
unspecified vectors when displaying content type names.
|
| CVE-2009-3647 |
Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft
Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers
to inject arbitrary web script or HTML via the moudi parameter. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2009-3636 |
Cross-site scripting (XSS) vulnerability in the Install Tool
subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x
before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to
inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2009-3634 |
Cross-site scripting (XSS) vulnerability in the Frontend Login Box
(aka felogin) subcomponent in TYPO3 4.2.0 through 4.2.6 allows remote
attackers to inject arbitrary web script or HTML via unspecified
parameters.
|
| CVE-2009-3633 |
Cross-site scripting (XSS) vulnerability in the
t3lib_div::quoteJSvalue API function in TYPO3 4.0.13 and earlier,
4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to the sanitizing algorithm.
|
| CVE-2009-3629 |
Multiple cross-site scripting (XSS) vulnerabilities in the Backend
subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x
before 4.2.10, and 4.3.x before 4.3beta2 allow remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-3619 |
Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before
1.1.2 has unknown impact and remote attack vectors related to
"printing illegal parameter names and values."
|
| CVE-2009-3618 |
Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0
before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject
arbitrary web script or HTML via the view parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2009-3601 |
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez
Ultimate Poll allows remote attackers to inject arbitrary web script
or HTML via the clr parameter in a vote action.
|
| CVE-2009-3599 |
Cross-site scripting (XSS) vulnerability in single_winner1.php in
HUBScript 1.0 allows remote attackers to inject arbitrary web script
or HTML via the bid_id parameter.
|
| CVE-2009-3598 |
Cross-site scripting (XSS) vulnerability in survey_result.php in
eCardMAX FormXP 2007 allows remote attackers to inject arbitrary web
script or HTML via the sid parameter.
|
| CVE-2009-3594 |
Cross-site scripting (XSS) vulnerability in bpost.php in BLOB Blog
System before 1.2 allows remote attackers to inject arbitrary web
script or HTML via the postid parameter.
|
| CVE-2009-3593 |
Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) id parameter to placebid.php and (2) jobid parameter to
post_resume.php.
|
| CVE-2009-3592 |
Cross-site scripting (XSS) vulnerability in customer/home.php in
Qualiteam X-Cart allows remote attackers to inject arbitrary web
script or HTML via the email parameter in a subscribed action, a
different vector than CVE-2005-1823.
|
| CVE-2009-3581 |
Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger
2.8.24 allow remote authenticated users to inject arbitrary web script
or HTML via (1) the DCN Description field in the Accounts Receivables
menu item for Add Transaction, (2) the Description field in the
Accounts Payable menu item for Add Transaction, or the name field in
(3) the Customers menu item for Add Customer or (4) the Vendor menu
item for Add Vendor.
|
| CVE-2009-3579 |
Cross-site scripting (XSS) vulnerability in the CookieDump.java sample
application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote
attackers to inject arbitrary web script or HTML via the Value
parameter in a GET request to cookie/.
|
| CVE-2009-3567 |
Cross-site scripting (XSS) vulnerability in
modules/tickets/functions_ticketsui.php in Kayako SupportSuite and
eSupport 3.60.04 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors in the staff
control panel, a different vector than CVE-2007-1145.
|
| CVE-2009-3566 |
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1
does not include the HTTPOnly flag in the Set-Cookie header for the
session identifier, which allows remote attackers to hijack a session
by leveraging a cross-site scripting (XSS) vulnerability.
|
| CVE-2009-3565 |
Multiple cross-site scripting (XSS) vulnerabilities in
intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security
Manager (NSM) before 5.1.11.6 allow remote attackers to inject
arbitrary web script or HTML via the (1) iaction or (2) node
parameter.
|
| CVE-2009-3562 |
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32
allows remote attackers to inject arbitrary web script or HTML via the
currentPath parameter in a chooseDirectory action.
|
| CVE-2009-3540 |
Cross-site scripting (XSS) vulnerability in listads.php in
YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject
arbitrary web script or HTML via the cn parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2009-3539 |
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld
Ultra Classifieds Pro allow remote attackers to inject arbitrary web
script or HTML via the (1) cname parameter to subclass.php and the (2)
sn parameter to listads.php.
|
| CVE-2009-3530 |
Cross-site scripting (XSS) vulnerability in storefront.php in
RadScripts RadBids Gold 4 allows remote attackers to inject arbitrary
web script or HTML via the mode parameter.
|
| CVE-2009-3521 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Visualization Engine (VE) in IBM Tivoli Composite Application Manager
for WebSphere (ITCAM) 6.1.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2009-3513 |
Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group
(PG) eTraining allow remote attackers to inject arbitrary web script
or HTML via (1) the cat_id parameter to courses_login.php, the id
parameter to (2) news_read.php or (3) lessons_login.php, or (4) the
cur parameter in a start action to lessons_login.php.
|
| CVE-2009-3512 |
Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) date parameter to user_addfood.php, info parameter to (2)
user_forgot_pwd_form.php and (3) user_login.php, and (4) return
parameter to user_login.php.
|
| CVE-2009-3509 |
Cross-site scripting (XSS) vulnerability in admin/admin_index.php in
CJ Dynamic Poll PRO 2.0 allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO.
|
| CVE-2009-3506 |
Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21
allow remote attackers to inject arbitrary web script or HTML via the
(1) cook_user parameter to index.php and the (2) name parameter to
modules.php.
|
| CVE-2009-3496 |
Cross-site scripting (XSS) vulnerability in view_mag.php in Vastal
I-Tech DVD Zone allows remote attackers to inject arbitrary web script
or HTML via the mag_id parameter.
|
| CVE-2009-3493 |
Multiple cross-site scripting (XSS) vulnerabilities in Zenas
PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary
web script or HTML via the PATH_INFO to (1) scrivi.php and (2)
index.php.
|
| CVE-2009-3488 |
Cross-site scripting (XSS) vulnerability in the Bibliography (aka
Biblio) module 6.x-1.6 for Drupal allows remote authenticated users,
with certain content-creation privileges, to inject arbitrary web
script or HTML via the Title field, probably a different vulnerability
than CVE-2009-3479.
|
| CVE-2009-3487 |
Multiple cross-site scripting (XSS) vulnerabilities in the J-Web
interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users
to inject arbitrary web script or HTML via (1) the JEXEC_OUTID
parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec program;
the (2) act, (3) refresh-time, or (4) ifid parameter to scripter.php;
(5) the revision parameter in a rollback action to the configuration
program; the m[] parameter to the (6) monitor, (7) manage, (8) events,
(9) configuration, or (10) alarms program; (11) the m[] parameter to
the default URI; (12) the m[] parameter in a browse action to the
default URI; (13) the wizard-next parameter in an https action to the
configuration program; or the (14) Contact Information, (15) System
Description, (16) Local Engine ID, (17) System Location, or (18)
System Name Override SNMP parameter, related to the configuration
program.
|
| CVE-2009-3486 |
Multiple cross-site scripting (XSS) vulnerabilities in the J-Web
interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users
to inject arbitrary web script or HTML via the host parameter to (1)
the pinghost program, reachable through the diagnose program; or (2)
the traceroute program, reachable through the diagnose program; or (3)
the probe-limit parameter to the configuration program; the (4)
wizard-ids or (5) pager-new-identifier parameter in a firewall-filters
action to the configuration program; (6) the
cos-physical-interface-name parameter in a
cos-physical-interfaces-edit action to the configuration program; the
(7) wizard-args or (8) wizard-ids parameter in an snmp action to the
configuration program; the (9) username or (10) fullname parameter in
a users action to the configuration program; or the (11) certname or
(12) certbody parameter in a local-cert (aka https) action to the
configuration program.
|
| CVE-2009-3485 |
Cross-site scripting (XSS) vulnerability in the J-Web interface in
Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO to the default URI.
|
| CVE-2009-3479 |
Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x
before 5.x-1.17 and 6.x before 6.x-1.6, a module for Drupal, allows
remote attackers, with "create content displayed by the Bibliography
module" permissions, to inject arbitrary web script or HTML via a
title.
|
| CVE-2009-3469 |
Cross-site scripting (XSS) vulnerability in
profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows
remote attackers to inject arbitrary web script or HTML via the name
parameter.
|
| CVE-2009-3467 |
Cross-site scripting (XSS) vulnerability in an unspecified method in
Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject
arbitrary web script or HTML via unknown vectors.
|
| CVE-2009-3453 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus
Quickr 8.1.0 services for WebSphere Portal allow remote attackers to
inject arbitrary web script or HTML via the filename of a .odt file in
a Lotus Quickr place, related to the Library template.
|
| CVE-2009-3450 |
Multiple cross-site scripting (XSS) vulnerabilities in
WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote
attackers to inject arbitrary web script or HTML via parameters with
names beginning with __ (underscore underscore) sequences, which are
incompatible with an XSS protection mechanism provided by Microsoft
ASP.NET.
|
| CVE-2009-3444 |
Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16
and earlier allows remote attackers to inject arbitrary web script or
HTML via the HTTP Referer header in a news.1 (aka news to email)
action.
|
| CVE-2009-3440 |
Cross-site scripting (XSS) vulnerability in Open Source Security
Information Management (OSSIM) before 2.1.2 allows remote attackers to
inject arbitrary web script or HTML via the option parameter to the
default URI (aka the main menu).
|
| CVE-2009-3437 |
Cross-site scripting (XSS) vulnerability in the live preview feature
in the Markdown Preview module 6.x for Drupal allows remote attackers
to inject arbitrary web script or HTML via "Markdown input."
|
| CVE-2009-3435 |
Cross-site scripting (XSS) vulnerability in the variable editor in the
Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for
Drupal, allows remote attackers to inject arbitrary web script or HTML
via a variable name.
|
| CVE-2009-3427 |
Cross-site scripting (XSS) vulnerability in Kayako SupportSuite
3.50.06 allows remote attackers to inject arbitrary web script or HTML
via the subject field in a ticket.
|
| CVE-2009-3420 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
the Publisher module 2.0 for Miniweb allow remote attackers to inject
arbitrary web script or HTML via the (1) begin parameter and the (2)
PATH_INFO.
|
| CVE-2009-3368 |
Cross-site scripting (XSS) vulnerability in the Hotel Booking
Reservation System (aka HBS or com_hbssearch) component for Joomla!
allows remote attackers to inject arbitrary web script or HTML via the
adult parameter in a showhoteldetails action to index.php.
|
| CVE-2009-3367 |
Multiple cross-site scripting (XSS) vulnerabilities in An image
gallery 1.0 allow remote attackers to inject arbitrary web script or
HTML via the path parameter to (1) index.php and (2) main.php, and the
(3) show parameter to main.php. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-3363 |
Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x
before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via input to
the "plain textarea editor."
|
| CVE-2009-3360 |
Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) return parameter to photo_view.php, and st parameter to (2)
photo_search.php and (3) search.php.
|
| CVE-2009-3359 |
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency
BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) important parameter to edit_profile.php and (2) pid
parameter to report.php.
|
| CVE-2009-3357 |
Multiple SQL injection vulnerabilities in the Hotel Booking
Reservation System (aka HBS or com_hbssearch) component for Joomla!
allow remote attackers to execute arbitrary SQL commands via the (1)
h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id
parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7)
detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11)
detail7.php, and (12) detail8.php, different vectors than
CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.
|
| CVE-2009-3355 |
Cross-site scripting (XSS) vulnerability in profile.php in Datetopia
Buy Dating Site 1.0 allows remote attackers to inject arbitrary web
script or HTML via the s_r parameter.
|
| CVE-2009-3348 |
Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows
remote attackers to inject arbitrary web script or HTML via the cid
parameter in a cat action to the home component.
|
| CVE-2009-3328 |
Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook
1.1.208 allows remote attackers to inject arbitrary web script or HTML
via the sName parameter (aka the name field). NOTE: some of these
details are obtained from third party information.
|
| CVE-2009-3320 |
Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas
PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO.
|
| CVE-2009-3311 |
Cross-site scripting (XSS) vulnerability in index.php in
RSSMediaScript allows remote attackers to inject arbitrary web script
or HTML via the page parameter.
|
| CVE-2009-3303 |
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in
GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject
arbitrary web script or HTML via the helpname parameter.
|
| CVE-2009-3300 |
Multiple cross-site scripting (XSS) vulnerabilities in the Identity
Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the
Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2
Middleware Initiative Shibboleth allow remote attackers to inject
arbitrary web script or HTML via URLs that are encountered in
redirections, and appear in automatically generated forms.
|
| CVE-2009-3299 |
Cross-site scripting (XSS) vulnerability in the resume blocktype in
Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-3283 |
Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image
Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot,
dated before 20090914, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors related to cookies.
|
| CVE-2009-3266 |
Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2)
Atom feed, which allows remote attackers to conduct cross-site
scripting (XSS) attacks, and conduct cross-zone scripting attacks
involving the Feed Subscription Page to read feeds or create feed
subscriptions, via a crafted feed, related to the rendering of the
application/rss+xml content type as "scripted content."
|
| CVE-2009-3265 |
Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows
remote attackers to inject arbitrary web script or HTML via a (1) RSS
or (2) Atom feed, related to the rendering of the application/rss+xml
content type as "scripted content." NOTE: the vendor reportedly
considers this behavior a "design feature," not a vulnerability.
|
| CVE-2009-3263 |
Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x
before 3.0.195.21 allows remote attackers to inject arbitrary web
script or HTML via a (1) RSS or (2) Atom feed, related to the
rendering of the application/rss+xml content type as XML "active
content."
|
| CVE-2009-3262 |
Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI)
in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote
authenticated users to inject arbitrary web script or HTML via the
last name field in a profile.
|
| CVE-2009-3260 |
Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows
remote attackers to inject arbitrary web script or HTML via the header
of the topic in a comment.
|
| CVE-2009-3256 |
Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php
in LiveStreet 0.2 allows remote attackers to inject arbitrary web
script or HTML via the URI, as demonstrated by a SCRIPT element in an
arbitrary parameter such as the asd parameter.
|
| CVE-2009-3247 |
Cross-site scripting (XSS) vulnerability in the Activities module in
vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web
script or HTML via the action parameter to phprint.php. NOTE: the
query_string vector is already covered by CVE-2008-3101.3.
|
| CVE-2009-3240 |
Cross-site scripting (XSS) vulnerability in the Happy Linux XF-Section
module 1.12a for XOOPS allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2009-3237 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde
Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware
1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition
1.1 before 1.1.6 and 1.2 before 1.2.4; allow remote attackers to
inject arbitrary web script or HTML via the (1) crafted number
preferences that are not properly handled in the preference system
(services/prefs.php), as demonstrated by the sidebar_width parameter;
or (2) crafted unknown MIME "text parts" that are not properly handled
in the MIME viewer library (config/mime_drivers.php).
|
| CVE-2009-3227 |
Cross-site scripting (XSS) vulnerability in index.php in AlmondSoft
Almond Classifieds Ads Enterprise and Almond Affiliate Network
Classifieds allows remote attackers to inject arbitrary web script or
HTML via the city parameter in a search action. NOTE: some of these
details are obtained from third party information.
|
| CVE-2009-3225 |
Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft
Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network
Classifieds, allow remote attackers to inject arbitrary web script or
HTML via (1) the page parameter in a browse action to index.php or (2)
the addr parameter to gmap.php. NOTE: some of these details are
obtained from third party information.
|
| CVE-2009-3222 |
Cross-site scripting (XSS) vulnerability in index.php in
FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to
inject arbitrary web script or HTML via the msg parameter.
|
| CVE-2009-3210 |
Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka
Printer, e-mail and PDF versions) module 5.x before 5.x-4.8 and 6.x
before 6.x-1.8, a module for Drupal, allow remote authenticated users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-3206 |
Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache
module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for
Drupal, allow remote authenticated users, with "administer imagecache"
permissions, to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-3204 |
Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0
allow remote attackers to inject arbitrary web script or HTML via the
id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to
(3) include_forum.php.
|
| CVE-2009-3202 |
Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP
Forum 2.1 allows remote attackers to inject arbitrary web script or
HTML via the term parameter.
|
| CVE-2009-3198 |
Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech
Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to
inject arbitrary web script or HTML via the search parameter.
|
| CVE-2009-3197 |
Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech PHP
Calendars Script allows remote attackers to inject arbitrary web
script or HTML via the search parameter.
|
| CVE-2009-3196 |
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP
Video Script allows remote attackers to inject arbitrary web script or
HTML via the key parameter.
|
| CVE-2009-3195 |
Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech
Auction RSS Content Script 3.0 allow remote attackers to inject
arbitrary web script or HTML via the id parameter to (1) rss.php and
(2) search.php.
|
| CVE-2009-3194 |
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech
SearchFeed Script allows remote attackers to inject arbitrary web
script or HTML via the search parameter.
|
| CVE-2009-3192 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
LinkorCMS 1.2 and earlier allow remote attackers to inject arbitrary
web script or HTML via (1) the searchstr parameter in a search action;
or the (2) nikname, (3) realname, (4) homepage, or (5) city parameter
in a registration action.
|
| CVE-2009-3191 |
Multiple cross-site scripting (XSS) vulnerabilities in PAD Site
Scripts 3.6 allow remote attackers to inject arbitrary web script or
HTML via the cat parameter to (1) rss.php and (2) opml.php.
|
| CVE-2009-3189 |
Cross-site scripting (XSS) vulnerability in search.php in DigiOz
Guestbook 1.7.2 allows remote attackers to inject arbitrary web script
or HTML via the search_term parameter.
|
| CVE-2009-3187 |
Cross-site scripting (XSS) vulnerability in gamelist.php in Stand
Alone Arcade 1.1 allows remote attackers to inject arbitrary web
script or HTML via the cat parameter.
|
| CVE-2009-3186 |
Multiple cross-site scripting (XSS) vulnerabilities in VideoGirls BiZ
allow remote attackers to inject arbitrary web script or HTML via the
(1) t parameter to forum.php, (2) profile_name parameter to
profile.php, and (3) p parameter to view.php.
|
| CVE-2009-3171 |
Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft
Gazelle CMS 1.0 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) user parameter to user.php or (2)
lookup parameter to search.php.
|
| CVE-2009-3162 |
Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows
remote attackers to inject arbitrary web script or HTML via the search
parameter in a search action to the default URI.
|
| CVE-2009-3157 |
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x
before 6.x-2.2 for Drupal allows remote authenticated users, with
"create new content types" privileges, to inject arbitrary web script
or HTML via the title of a content type.
|
| CVE-2009-3156 |
Cross-site scripting (XSS) vulnerability in the Date Tools sub-module
in the Date module 6.x before 6.x-2.3 for Drupal allows remote
authenticated users, with "use date tools" or "administer content
types" privileges, to inject arbitrary web script or HTML via a
"Content type label" field.
|
| CVE-2009-3155 |
Cross-site scripting (XSS) vulnerability in gmap.php in the Almond
Classifieds (com_aclassf) component 7.5 for Joomla! allows remote
attackers to inject arbitrary web script or HTML via the addr
parameter.
|
| CVE-2009-3153 |
Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search
engine 1.6.5 allow remote attackers to inject arbitrary web script or
HTML via the (1) pic_id parameter to includes/video_ad.php, (2)
category parameter to linkvideos_listing.php, id parameter to (3)
templates/header1.php and (4) mp3/lyrics.php, key parameter to (5)
video_listing.php and (6) adult/video_listing.php, and name parameter
to (7) mp3/embed.php and (8) mp3/info.php.
|
| CVE-2009-3152 |
Multiple cross-site scripting (XSS) vulnerabilities in
becommunity/community/index.php in NTSOFT BBS E-Market Professional
allow remote attackers to inject arbitrary web script or HTML via the
(1) page, (2) bt_code, and (3) b_no parameters in a board view action.
|
| CVE-2009-3147 |
Cross-site scripting (XSS) vulnerability in showproduct.php in
ReviewPost Pro vB3 allows remote attackers to inject arbitrary web
script or HTML via the date parameter.
|
| CVE-2009-3146 |
Cross-site scripting (XSS) vulnerability in search_advance.php in
ArticleFriend Script allows remote attackers to inject arbitrary web
script or HTML via the SearchWd parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2009-3121 |
Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x
for Drupal allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2009-3120 |
Cross-site scripting (XSS) vulnerability in public/index.php in BIGACE
Web CMS 2.6 allows remote attackers to inject arbitrary web script or
HTML via the id parameter. NOTE: some of these details are obtained
from third party information.
|
| CVE-2009-3105 |
Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka
Domino Web Access or DWA) before 211.241 for Domino 8.0.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, aka SPR EZEL7UURYC.
|
| CVE-2009-3067 |
Cross-site scripting (XSS) vulnerability in index.php in Reservation
Manager allows remote attackers to inject arbitrary web script or HTML
via the resman_startdate parameter.
|
| CVE-2009-3066 |
Multiple cross-site scripting (XSS) vulnerabilities in
PropertyWatchScript.com Property Watch 2.0 allow remote attackers to
inject arbitrary web script or HTML via the (1) videoid parameter to
tools/email.php and (2) redirect parameter to tools/login.php.
|
| CVE-2009-3060 |
Multiple cross-site scripting (XSS) vulnerabilities in Joker Board
(aka JBoard) 2.0 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) the notice parameter to
editform.php, (2) the edit_user_message parameter to
core/edit_user_message.php, or (3) the user_title parameter to
inc/head.inc.php, reachable through any PHP script.
|
| CVE-2009-3057 |
Multiple cross-site scripting (XSS) vulnerabilities in AOM Software
Beex 3 allow remote attackers to inject arbitrary web script or HTML
via the navaction parameter to (1) news.php and (2) partneralle.php.
|
| CVE-2009-3036 |
Cross-site scripting (XSS) vulnerability in the console in Symantec IM
Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-3030 |
Cross-site scripting (XSS) vulnerability in Symantec
SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and
earlier allows remote attackers to inject arbitrary web script or HTML
via vectors that trigger an error message in a response, related to an
"HTML Injection issue."
|
| CVE-2009-3029 |
Cross-site scripting (XSS) vulnerability in the console in Symantec
SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and
earlier allows remote authenticated users to inject arbitrary web
script or HTML via "external client input" that triggers crafted error
messages.
|
| CVE-2009-3021 |
Cross-site scripting (XSS) vulnerability in Site Calendar 'mycaljp'
plugin 2.0.0 through 2.0.6, as used in the Japanese extended package
of Geeklog 1.5.0 through 1.5.2 and when distributed 20090629 or
earlier, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2009-3018 |
Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block
javascript: and data: URIs in Refresh headers in HTTP responses, which
allows remote attackers to conduct cross-site scripting (XSS) attacks
via vectors related to (1) injecting a Refresh header that contains a
javascript: URI, (2) entering a javascript: URI when specifying the
content of a Refresh header, (3) injecting a Refresh header that
contains JavaScript sequences in a data:text/html URI, or (4) entering
a data:text/html URI with JavaScript sequences when specifying the
content of a Refresh header; does not properly block data: URIs in
Location headers in HTTP responses, which allows user-assisted remote
attackers to conduct cross-site scripting (XSS) attacks via vectors
related to (5) injecting a Location header that contains JavaScript
sequences in a data:text/html URI or (6) entering a data:text/html URI
with JavaScript sequences when specifying the content of a Location
header; and does not properly handle javascript: URIs in HTML links
within (a) 301 and (b) 302 error documents sent from web servers,
which allows user-assisted remote attackers to conduct cross-site
scripting (XSS) attacks via vectors related to (7) injecting a
Location HTTP response header or (8) specifying the content of a
Location HTTP response header.
|
| CVE-2009-3017 |
Orca Browser 1.2 build 5 does not properly block data: URIs in Refresh
and Location headers in HTTP responses, which allows remote attackers
to conduct cross-site scripting (XSS) attacks via vectors related to
(1) injecting a Refresh header that contains JavaScript sequences in a
data:text/html URI, (2) entering a data:text/html URI with JavaScript
sequences when specifying the content of a Refresh header, (3)
injecting a Location header that contains JavaScript sequences in a
data:text/html URI, or (4) entering a data:text/html URI with
JavaScript sequences when specifying the content of a Location header;
and does not properly handle javascript: URIs in HTML links within 302
error documents sent from web servers, which allows user-assisted
remote attackers to conduct cross-site scripting (XSS) attacks via
vectors related to (5) injecting a Location HTTP response header or
(6) specifying the content of a Location HTTP response header.
|
| CVE-2009-3016 |
Apple Safari 4.0.3 does not properly block javascript: and data: URIs
in Refresh headers in HTTP responses, which allows remote attackers to
conduct cross-site scripting (XSS) attacks via vectors related to (1)
injecting a Refresh header that contains a javascript: URI, (2)
entering a javascript: URI when specifying the content of a Refresh
header, (3) injecting a Refresh header that contains JavaScript
sequences in a data:text/html URI, or (4) entering a data:text/html
URI with JavaScript sequences when specifying the content of a Refresh
header.
|
| CVE-2009-3015 |
QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and
data: URIs in Refresh and Location headers in HTTP responses, which
allows remote attackers to conduct cross-site scripting (XSS) attacks
via vectors related to (1) injecting a Refresh header that contains a
javascript: URI, (2) entering a javascript: URI when specifying the
content of a Refresh header, (3) injecting a Refresh header that
contains JavaScript sequences in a data:text/html URI, (4) entering a
data:text/html URI with JavaScript sequences when specifying the
content of a Refresh header, (5) injecting a Location header that
contains JavaScript sequences in a data:text/html URI, or (6) entering
a data:text/html URI with JavaScript sequences when specifying the
content of a Location header.
|
| CVE-2009-3014 |
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre;
SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle
javascript: URIs in HTML links within 302 error documents sent from
web servers, which allows user-assisted remote attackers to conduct
cross-site scripting (XSS) attacks via vectors related to (1)
injecting a Location HTTP response header or (2) specifying the
content of a Location HTTP response header.
|
| CVE-2009-3013 |
Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly
block data: URIs in Location headers in HTTP responses, which allows
remote attackers to conduct cross-site scripting (XSS) attacks via
vectors related to (1) injecting a Location header that contains
JavaScript sequences in a data:text/html URI or (2) entering a
data:text/html URI with JavaScript sequences when specifying the
content of a Location header. NOTE: the JavaScript executes outside of
the context of the HTTP site.
|
| CVE-2009-3012 |
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre
does not properly block data: URIs in Location headers in HTTP
responses, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via vectors related to (1) injecting a
Location header that contains JavaScript sequences in a data:text/html
URI or (2) entering a data:text/html URI with JavaScript sequences
when specifying the content of a Location header. NOTE: the JavaScript
executes outside of the context of the HTTP site.
|
| CVE-2009-3011 |
Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and
3.0.193.2 Beta does not properly block data: URIs in Refresh headers
in HTTP responses, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via vectors related to (1) injecting a Refresh
header that contains JavaScript sequences in a data:text/html URI or
(2) entering a data:text/html URI with JavaScript sequences when
specifying the content of a Refresh header. NOTE: the JavaScript
executes outside of the context of the HTTP site.
|
| CVE-2009-3010 |
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre;
SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block
data: URIs in Refresh headers in HTTP responses, which allows remote
attackers to conduct cross-site scripting (XSS) attacks via vectors
related to (1) injecting a Refresh header that contains JavaScript
sequences in a data:text/html URI or (2) entering a data:text/html URI
with JavaScript sequences when specifying the content of a Refresh
header. NOTE: in some product versions, the JavaScript executes
outside of the context of the HTTP site.
|
| CVE-2009-3009 |
Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before
2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject
arbitrary web script or HTML by placing malformed Unicode strings into
a form helper.
|
| CVE-2009-2967 |
Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6
through 0.7.11p2 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors, different vulnerabilities than
CVE-2009-2959.
|
| CVE-2009-2965 |
Cross-site scripting (XSS) vulnerability in entry/index.jsp in
Radvision Scopia 5.7, and possibly other versions before SD 7.0.100,
allows remote attackers to inject arbitrary web script or HTML via the
page parameter.
|
| CVE-2009-2959 |
Cross-site scripting (XSS) vulnerability in the waterfall web status
view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-2947 |
Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16
allows remote attackers to inject arbitrary web script or HTML via
unspecified CGI parameter values, which are sometimes included in
exception messages.
|
| CVE-2009-2937 |
Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet
Venus allows remote attackers to inject arbitrary web script or HTML
via the SRC attribute of an IMG element in a feed.
|
| CVE-2009-2932 |
Cross-site scripting (XSS) vulnerability in uddiclient/process in the
UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows
remote attackers to inject arbitrary web script or HTML via the TModel
Key field.
|
| CVE-2009-2930 |
Cross-site scripting (XSS) vulnerability in the Search feature in elka
CMS (aka Elkapax) allows remote attackers to inject arbitrary web
script or HTML via the q parameter to the default URI.
|
| CVE-2009-2928 |
Cross-site scripting (XSS) vulnerability in login.php in TGS Content
Management 0.x allows remote attackers to inject arbitrary web script
or HTML via the previous_page parameter, a different vector than
CVE-2008-6839.
|
| CVE-2009-2920 |
Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) component and (2) priority parameters to buglist.php; and the (3)
Username (4) E-mail, (5) Pass, and (6) Confirm pass fields to
createaccount.php.
|
| CVE-2009-2919 |
Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2
allows remote authenticated users to inject arbitrary web script or
HTML via the topic title field.
|
| CVE-2009-2914 |
Cross-site scripting (XSS) vulnerability in index.php in XZero
Community Classifieds 4.97.8 and earlier allows remote attackers to
inject arbitrary web script or HTML via the name of an uploaded file.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2009-2913 |
Cross-site scripting (XSS) vulnerability in index.php in XZero
Community Classifieds 4.97.8 allows remote attackers to inject
arbitrary web script or HTML via the URI. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-2907 |
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc
Server 6.0.20.B and earlier, Application Management Suite (AMS) before
2.0.0.SR4, Hyperic HQ Open Source before 4.2.x, Hyperic HQ 4.0
Enterprise before 4.0.3.2, and Hyperic HQ 4.1 Enterprise before
4.1.2.1 allow remote attackers to inject arbitrary web script or HTML
via the description field and unspecified "input fields."
|
| CVE-2009-2898 |
Cross-site scripting (XSS) vulnerability in the Alerts list feature in
the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1,
4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application
Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allows remote
authenticated users to inject arbitrary web script or HTML via the
Description field. NOTE: some of these details are obtained from third
party information.
|
| CVE-2009-2897 |
Multiple cross-site scripting (XSS) vulnerabilities in
hq/web/common/GenericError.jsp in the generic exception handler in the
web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x
before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application
Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allow remote
attackers to inject arbitrary web script or HTML via invalid values
for numerical parameters, as demonstrated by an uncaught
java.lang.NumberFormatException exception resulting from (1) the
typeId parameter to mastheadAttach.do, (2) the eid parameter to
Resource.do, and (3) the u parameter in a view action to
admin/user/UserAdmin.do. NOTE: some of these details are obtained from
third party information.
|
| CVE-2009-2893 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
XZero Community Classifieds 4.97.8 allow remote attackers to inject
arbitrary web script or HTML via (1) the postevent parameter in a post
action or (2) the _xzcal_y parameter.
|
| CVE-2009-2890 |
Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts
Now Riddles allows remote attackers to inject arbitrary web script or
HTML via the searchquery parameter.
|
| CVE-2009-2889 |
Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts
Now Hangman allows remote attackers to inject arbitrary web script or
HTML via the letters parameter.
|
| CVE-2009-2887 |
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts
Now President Bios allows remote attackers to inject arbitrary web
script or HTML via the rank parameter.
|
| CVE-2009-2884 |
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts
Now World's Tallest Buildings allows remote attackers to inject
arbitrary web script or HTML via the rank parameter.
|
| CVE-2009-2882 |
Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking
allow remote attackers to inject arbitrary web script or HTML via the
show parameter to (1) browse_ladies.php and (2) browse_men.php, the
(3) gender parameter to search.php, and the (4) id parameter to
services.php.
|
| CVE-2009-2851 |
Cross-site scripting (XSS) vulnerability in the administrator
interface in WordPress before 2.8.2 allows remote attackers to inject
arbitrary web script or HTML via a comment author URL.
|
| CVE-2009-2823 |
The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the
HTTP TRACE method, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via unspecified web client software.
|
| CVE-2009-2820 |
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X
before 10.6.2 and other platforms, does not properly handle (1) HTTP
headers and (2) HTML templates, which allows remote attackers to
conduct cross-site scripting (XSS) attacks and HTTP response splitting
attacks via vectors related to (a) the product's web interface, (b)
the configuration of the print system, and (c) the titles of printed
jobs, as demonstrated by an XSS attack that uses the kerberos
parameter to the admin program, and leverages attribute injection and
HTTP Parameter Pollution (HPP) issues.
|
| CVE-2009-2814 |
Cross-site scripting (XSS) vulnerability in the Wiki Server in Apple
Mac OS X 10.5.8 allows remote attackers to inject arbitrary web script
or HTML via a search request containing data that does not use UTF-8
encoding.
|
| CVE-2009-2785 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP Open
Classifieds Script allow remote attackers to inject arbitrary web
script or HTML via the (1) page parameter to buy.php and the id
parameter to (2) contact.php and (3) tellafriend.php.
|
| CVE-2009-2783 |
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3
allow remote attackers to inject arbitrary web script or HTML via the
(1) op parameter to modules/pm/viewpmsg.php and (2) query string to
modules/profile/user.php.
|
| CVE-2009-2780 |
Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds
4.1 allow remote attackers to inject arbitrary web script or HTML via
the (1) cat parameter to category.php, view parameter to (2) login.php
and (3) viewlisting.php, page parameter to (4) searchresults.php and
(5) toplistings.php, and (6) member parameter to viewmember.php.
|
| CVE-2009-2778 |
Cross-site scripting (XSS) vulnerability in visitor/view.php in
GarageSales Script allows remote attackers to inject arbitrary web
script or HTML via the key parameter. NOTE: some of these details are
obtained from third party information.
|
| CVE-2009-2772 |
Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate
Finder Solution allow remote attackers to inject arbitrary web script
or HTML via the part parameter to (1) quick_search.php and (2)
viewprofile.php.
|
| CVE-2009-2771 |
Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3
allows remote attackers to inject arbitrary web script or HTML via the
keyword parameter to the default URI under search/.
|
| CVE-2009-2748 |
Cross-site scripting (XSS) vulnerability in the Administration Console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1
before 7.0.0.7 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2009-2742 |
Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM
WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote
attackers to inject arbitrary web script or HTML via unspecified
input.
|
| CVE-2009-2739 |
Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2009-2733 |
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before
1.4.0 allow remote attackers to inject arbitrary web script or HTML
via (1) the scheduler title in the scheduler module, and the (2)
atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4)
atksearchmode[contracttype], and possibly (5) atksearch[contractname]
parameters to the Organization Contracts administration page,
reachable through dispatch.php.
|
| CVE-2009-2705 |
CA SiteMinder allows remote attackers to bypass cross-site scripting
(XSS) protections for J2EE applications via a request containing
non-canonical, "overlong Unicode" in place of blacklisted characters.
|
| CVE-2009-2704 |
CA SiteMinder allows remote attackers to bypass cross-site scripting
(XSS) protections for J2EE applications via a request containing a %00
(encoded null byte).
|
| CVE-2009-2696 |
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the
calendar application in the examples web application in Apache Tomcat
on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux
Desktop 5 allows remote attackers to inject arbitrary web script or
HTML via the time parameter, related to "invalid HTML." NOTE: this is
due to a missing fix for CVE-2009-0781.
|
| CVE-2009-2684 |
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and
the Embedded Web Server (EWS) on certain HP LaserJet and Color
LaserJet printers, and HP Digital Senders, allow remote attackers to
inject arbitrary web script or HTML via the (1) Product_URL or (2)
Tech_URL parameter in an Apply action to the support_param.html/config
script.
|
| CVE-2009-2636 |
Cross-site scripting (XSS) vulnerability in the Integration page in
the WebMail component in Kerio MailServer 6.6.0, 6.6.1, 6.6.2, and
6.7.0 allows remote attackers to inject arbitrary web script or HTML
via an e-mail message.
|
| CVE-2009-2615 |
Multiple cross-site scripting (XSS) vulnerabilities in DataCheck
Solutions SitePal 1.x allow remote attackers to inject arbitrary web
script or HTML via the page parameter to (1) z_admin_login.asp, (2)
z_forgot.asp, and possibly unspecified other components. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2009-2613 |
Multiple cross-site scripting (XSS) vulnerabilities in DataCheck
Solutions LinkPal 1.x allow remote attackers to inject arbitrary web
script or HTML via the page parameter to (1) z_loginfailed.asp, (2)
z_admin_login.asp, (3) z_forgot.asp, and possibly unspecified other
components. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2009-2610 |
Cross-site scripting (XSS) vulnerability in the Links Related module
in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a
module for Drupal, allows remote authenticated users to inject
arbitrary web script or HTML via the title field.
|
| CVE-2009-2595 |
Cross-site scripting (XSS) vulnerability in productSearch.html in
Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary
web script or HTML via the q parameter in a ProductSearch action.
|
| CVE-2009-2594 |
Cross-site scripting (XSS) vulnerability in censura.php in Censura
1.16.04 allows remote attackers to inject arbitrary web script or HTML
via the itemid parameter in a details action.
|
| CVE-2009-2589 |
Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP
Website Script allow remote attackers to inject arbitrary web script
or HTML via the msg parameter to (1) feedback.php, (2) index.php, and
(3) lostpassword.php.
|
| CVE-2009-2588 |
Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type
PHP Clone Script allow remote attackers to inject arbitrary web script
or HTML via the msg parameter to (1) feedback.php, (2) index.php, and
(3) lostpassword.php.
|
| CVE-2009-2587 |
Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart
allow remote attackers to inject arbitrary web script or HTML via the
(1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to
includes/ajax/getstate.php, the search parameter to (3) index.php and
(4) search.php, the (5) redirect parameter to login.php, and the (6)
product parameter to productdetail.php.
|
| CVE-2009-2586 |
Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP
EZArticles allows remote attackers to inject arbitrary web script or
HTML via the title parameter.
|
| CVE-2009-2581 |
Cross-site scripting (XSS) vulnerability in modifier.php in
EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary
web script or HTML via the msg parameter.
|
| CVE-2009-2571 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to inject arbitrary
web script or HTML via (1) the URI, (2) the q parameter, (3) the nick
parameter, or (4) the nick parameter in a bantest action.
|
| CVE-2009-2569 |
Multiple cross-site scripting (XSS) vulnerabilities in Verlihub
Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary
web script or HTML via (1) the nick parameter in a login action to
index.php or (2) the URI in a news request to index.html.
|
| CVE-2009-2565 |
Cross-site scripting (XSS) vulnerability in Perl CGI's By Mrs.
Shiromuku shiromuku(fs6)DIARY 2.40 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-2551 |
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy
Image Downloader allow remote attackers to inject arbitrary web script
or HTML via the id parameter in a detail action to (1) main.php and
possibly (2) demo_page.php.
|
| CVE-2009-2492 |
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart
Movable Type before 4.261 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, a different vulnerability
than CVE-2009-2480.
|
| CVE-2009-2480 |
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart
Movable Type 4.24, and 4.25 when global templates are not initialized,
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-2472 |
Mozilla Firefox before 3.0.12 does not always use
XPCCrossOriginWrapper when required during object construction, which
allows remote attackers to bypass the Same Origin Policy and conduct
cross-site scripting (XSS) attacks via a crafted document, related to
a "cross origin wrapper bypass."
|
| CVE-2009-2455 |
Multiple cross-site scripting (XSS) vulnerabilities in
webadmin/admin.php in @mail 5.6.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) type and (2) func parameters.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2009-2454 |
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6,
5.0, and 5.0.1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2009-2448 |
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online
Guestbook Pro 5.1 allows remote attackers to inject arbitrary web
script or HTML via the search_choice parameter. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2009-2447 |
Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in
Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary
web script or HTML via the (1) search or (2) display parameter.
|
| CVE-2009-2442 |
Cross-site scripting (XSS) vulnerability in public/index.php in
Linea21 1.2.1 allows remote attackers to inject arbitrary web script
or HTML via the search parameter in a resultats-recherche action.
|
| CVE-2009-2441 |
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online
Guestbook Pro 5.1 allows remote attackers to inject arbitrary web
script or HTML via the entry parameter.
|
| CVE-2009-2440 |
Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook
3.0 allows remote attackers to inject arbitrary web script or HTML via
the page parameter.
|
| CVE-2009-2438 |
Cross-site scripting (XSS) vulnerability in index.php in the search
module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to
inject arbitrary web script or HTML via the text parameter in a list
action. NOTE: this might overlap CVE-2008-1399.
|
| CVE-2009-2437 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Rentventory 1.0.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) username (aka Login) and (2) password
parameters in a login action.
|
| CVE-2009-2424 |
Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone
2009 allows remote attackers to inject arbitrary web script or HTML
via the mode parameter.
|
| CVE-2009-2405 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web Console
in the Application Server in Red Hat JBoss Enterprise Application
Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA,
4.3 before 4.3.0.CP07, and 5.1.0GA allow remote attackers to inject
arbitrary web script or HTML via the (1) monitorName, (2) objectName,
(3) attribute, or (4) period parameter to createSnapshot.jsp, or the
(5) monitorName, (6) objectName, (7) attribute, (8) threshold, (9)
period, or (10) enabled parameter to createThresholdMonitor.jsp. NOTE:
some of these details are obtained from third party information.
|
| CVE-2009-2401 |
Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows
remote attackers to inject arbitrary web script or HTML via a forum
post.
|
| CVE-2009-2391 |
Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz
Virtue Online Test Generator allows remote attackers to inject
arbitrary web script or HTML via the tid parameter.
|
| CVE-2009-2380 |
Cross-site scripting (XSS) vulnerability in includes/functions.php in
4images 1.7 through 1.7.7 allows remote attackers to inject arbitrary
web script or HTML via vectors related to the url variable.
|
| CVE-2009-2376 |
Cross-site scripting (XSS) vulnerability in the Html::textarea
function in application/libraries/Html.php in TangoCMS 2.x before
2.3.0 allows remote attackers to inject arbitrary web script or HTML
via the value parameter, related to the Contact module.
|
| CVE-2009-2373 |
Cross-site scripting (XSS) vulnerability in the Forum module in Drupal
6.x before 6.13 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2009-2370 |
Cross-site scripting (XSS) vulnerability in Advanced Forum 5.x before
5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-2360 |
Cross-site scripting (XSS) vulnerability in passwd/main.php in the
Passwd module before 3.1.1 for Horde allows remote attackers to inject
arbitrary web script or HTML via the backend parameter.
|
| CVE-2009-2352 |
Google Chrome 1.0.154.48 and earlier does not block javascript: URIs
in Refresh headers in HTTP responses, which allows remote attackers to
conduct cross-site scripting (XSS) attacks via vectors related to (1)
injecting a Refresh header or (2) specifying the content of a Refresh
header, a related issue to CVE-2009-1312. NOTE: it was later reported
that 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta are also affected.
|
| CVE-2009-2351 |
Opera 9.52 and earlier does not block javascript: URIs in Refresh
headers in HTTP responses, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via vectors related to (1)
injecting a Refresh header or (2) specifying the content of a Refresh
header, a related issue to CVE-2009-1312. NOTE: it was later reported
that 10.00 Beta 3 Build 1699 is also affected.
|
| CVE-2009-2350 |
Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block
javascript: URIs in Refresh headers in HTTP responses, which allows
remote attackers to conduct cross-site scripting (XSS) attacks via
vectors related to (1) injecting a Refresh header or (2) specifying
the content of a Refresh header, a related issue to CVE-2009-1312.
|
| CVE-2009-2343 |
Cross-site scripting (XSS) vulnerability in people.php in Zoph before
0.7.0.6 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors. NOTE: some of these details are obtained from
third party information.
|
| CVE-2009-2342 |
Cross-site scripting (XSS) vulnerability in admin.php (aka the login
page) in Content Management Made Easy (CMME) before 1.22 allows remote
attackers to inject arbitrary web script or HTML via the username
field.
|
| CVE-2009-2334 |
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not
require administrative authentication to access the configuration of a
plugin, which allows remote attackers to specify a configuration file
in the page parameter to obtain sensitive information or modify this
file, as demonstrated by the (1) collapsing-archives/options.txt, (2)
akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4)
wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files.
NOTE: this can be leveraged for cross-site scripting (XSS) and denial
of service.
|
| CVE-2009-2330 |
Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in
CMS Chainuk 1.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the menu parameter.
|
| CVE-2009-2327 |
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet
Forum 1.1 and earlier allows remote authenticated users to inject
arbitrary web script or HTML via the v_variant1 parameter.
|
| CVE-2009-2326 |
Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and
earlier allow remote attackers to execute arbitrary SQL commands via
(1) an enter_parol cookie to index.php in an auto action or (2) the
topic parameter to message.php. NOTE: vector 2 can be leveraged for a
cross-site scripting (XSS) attack.
|
| CVE-2009-2324 |
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor
before 2.6.4.1 allow remote attackers to inject arbitrary web script
or HTML via components in the samples (aka _samples) directory.
|
| CVE-2009-2322 |
Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the
Axesstel MV 410R allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2009-2316 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli
Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary
web script or HTML by entering an unspecified URL in (1) the
self-service UI interface or (2) the console interface. NOTE: it was
later reported that 4.6.0 is also affected by the first vector.
|
| CVE-2009-2302 |
Cross-site scripting (XSS) vulnerability in index.php in Aardvark
Topsites PHP 5.2.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the q parameter in a search action.
NOTE: it was later reported that 5.2.1 is also affected.
|
| CVE-2009-2292 |
Cross-site scripting (XSS) vulnerability in Appleple a-News 2.32
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-2289 |
Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade
Script 1.0 beta allows remote attackers to inject arbitrary web script
or HTML via the q parameter in a gamelist action.
|
| CVE-2009-2284 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1
allows remote attackers to inject arbitrary web script or HTML via a
crafted SQL bookmark.
|
| CVE-2009-2283 |
Multiple cross-site scripting (XSS) vulnerabilities in the help jsp
scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web
Console in Solaris 10, allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2009-2277 |
Cross-site scripting (XSS) vulnerability in WebAccess in VMware
VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote
attackers to inject arbitrary web script or HTML via vectors related
to "context data."
|
| CVE-2009-2268 |
Cross-site scripting (XSS) vulnerability in the Cross-Domain
Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7
2005Q4, and 7.1 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2009-2241 |
Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline
Corporate Calendar allows remote attackers to inject arbitrary web
script or HTML via the keyword parameter.
|
| CVE-2009-2240 |
Cross-site scripting (XSS) vulnerability in AD2000 free-sw leger (aka
Web Conference Room Free) 1.6.4 and earlier allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-2228 |
Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS
allows remote attackers to inject arbitrary web script or HTML via the
url parameter in a redirect action.
|
| CVE-2009-2226 |
Cross-site scripting (XSS) vulnerability in Let's PHP! Tree BBS
2004/11/23 and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2009-2221 |
Cross-site scripting (XSS) vulnerability in PHP-I-BOARD 1.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2009-2219 |
Multiple cross-site scripting (XSS) vulnerabilities in
phpCollegeExchange 0.1.5c allow remote attackers to inject arbitrary
web script or HTML via the (1) _SESSION[handle] parameter to (a)
home.php, (b) books/allbooks.php, or (c) books/home.php; or the (2)
home parameter to (d) i_head.php or (e) i_nav.php, or (f)
allbooks.php, (g) home.php, or (h) i_nav.php in books/.
|
| CVE-2009-2217 |
Cross-site scripting (XSS) vulnerability in NBBC before 1.4.2 allows
remote attackers to inject arbitrary web script or HTML via an invalid
URL in a BBCode img tag.
|
| CVE-2009-2216 |
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in
DirectAdmin 1.33.6 and earlier allows remote attackers to inject
arbitrary web script or HTML via the URI in a view=advanced request.
|
| CVE-2009-2215 |
Multiple cross-site scripting (XSS) vulnerabilities in URD before
0.6.2 allow remote attackers to inject arbitrary web script or HTML
via vectors related to the fatal_error page and unspecified other
components.
|
| CVE-2009-2211 |
Cross-site scripting (XSS) vulnerability in the CQWeb server in IBM
Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-2181 |
Cross-site scripting (XSS) vulnerability in
admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote
attackers to inject arbitrary web script or HTML via the listbasedir
parameter.
|
| CVE-2009-2178 |
Cross-site scripting (XSS) vulnerability in website.php in
phpDatingClub 3.7 allows remote attackers to inject arbitrary web
script or HTML via the page parameter.
|
| CVE-2009-2172 |
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in
the Radio and TV Player addon for vBulletin allows remote registered
users to inject arbitrary web script or HTML via the station
parameter.
|
| CVE-2009-2170 |
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0
before 1.0.12 and 1.1 before 1.1.5 allow remote attackers to inject
arbitrary web script or HTML via unknown vectors.
|
| CVE-2009-2163 |
Cross-site scripting (XSS) vulnerability in login/default.aspx in
Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to
inject arbitrary web script or HTML via the sc_error parameter.
|
| CVE-2009-2162 |
Cross-site scripting (XSS) vulnerability in the XOOPS MANIAC
PukiWikiMod module 1.6.6.2 and earlier for XOOPS allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-2156 |
Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader
Classic 1.09 allow remote authenticated users to inject arbitrary web
script or HTML via (1) the Title field to requests.php, related to
viewrequests.php; and (2) the Torrent Name field to
torrents-upload.php, related to the logging of torrent uploads; and
allow remote attackers to inject arbitrary web script or HTML via (3)
the ttversion parameter to themes/default/footer.php, the (4) SITENAME
and (5) CURUSER[username] parameters to themes/default/header.php, (6)
the todayactive parameter to visitorstoday.php, (7) the activepeople
parameter to visitorsnow.php, (8) the faq_categ[999][title] parameter
to faq.php, and (9) the keepget parameter to torrents-details.php.
|
| CVE-2009-2155 |
Cross-site scripting (XSS) vulnerability in report/ReportViewAction.do
in WebNMS Free Edition 5 allows remote attackers to inject arbitrary
web script or HTML via the type parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2009-2153 |
Cross-site scripting (XSS) vulnerability in index.php in Impleo Music
Collection 2.0 allows remote attackers to inject arbitrary web script
or HTML via the sort parameter.
|
| CVE-2009-2149 |
Multiple cross-site scripting (XSS) vulnerabilities in Campus
Virtual-LMS allow remote attackers to inject arbitrary web script or
HTML via the (1) courseid parameter to enrolments/step1.php, or the
(2) search or (3) siteid parameter to files/shared_list.php.
|
| CVE-2009-2145 |
Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75
allow remote attackers to inject arbitrary web script or HTML via the
(a) NodeID and (b) action parameters to the default URI, and the (c)
NodeID parameter to the default URI for the admin section; and allow
remote authenticated users to inject arbitrary web script or HTML via
the (d) Title (aka page name) and (e) Url fields in a (1) new or (2)
modified page.
|
| CVE-2009-2141 |
Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET
01-01-08 allow remote attackers to inject arbitrary web script or HTML
via (1) the returnto parameter to makepoll.php, (2) the returnto
parameter in a delete action to polls.php, or the (3) Info or (4)
Avatar field to my.php.
|
| CVE-2009-2138 |
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow
remote attackers to redirect users to arbitrary web sites and conduct
phishing attacks via (1) the returnto parameter to login.php or (2)
the returnto parameter in a delete action to news.php. NOTE: this can
be leveraged for cross-site scripting (XSS) by redirecting to a data:
URI.
|
| CVE-2009-2133 |
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4
and 1.40.7 allow remote attackers to inject arbitrary web script or
HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3)
the value of a check array parameter in a delete action to
pivot/index.php, (4) the element name in a check array parameter in a
delete action to pivot/index.php, (5) the edituser parameter in an
edituser action to pivot/index.php, (6) the edit parameter in a
templates action to pivot/index.php, (7) the blog parameter in a
blog_edit1 action to pivot/index.php, (8) the cat parameter in a
cat_edit action to pivot/index.php, (9) a certain form field in a
doaction=1 request to pivot/index.php, (10) the url field in a
my_weblog edit_prefs action to pivot/user.php, or (11) the username
(aka name) field in a my_weblog reg_user action to pivot/user.php.
|
| CVE-2009-2131 |
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier
allows remote authenticated users to inject arbitrary web script or
HTML by providing a crafted user_homepage parameter to member.php, and
then posting a comment associated with a picture.
|
| CVE-2009-2127 |
Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin
1.2.0 allows remote attackers to inject arbitrary web script or HTML
via the id parameter.
|
| CVE-2009-2126 |
Cross-site scripting (XSS) vulnerability in close_bug.php in Elvin
before 1.2.1 allows remote attackers to inject arbitrary web script or
HTML via the title (aka subject) field.
|
| CVE-2009-2119 |
Cross-site scripting (XSS) vulnerability in the login interface
(my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0
through 6.0.3 allows remote attackers to inject arbitrary web script
or HTML via a base64-encoded xcho parameter.
|
| CVE-2009-2114 |
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in
SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web
script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and
(5) dir parameters.
|
| CVE-2009-2107 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to
inject arbitrary web script or HTML via event handlers such as
onmouseover in the (1) search or (2) tag parameters; (3) arbitrary
invalid parameter names that are not properly handled when triggered
on a column; (4) bookmark parameter in an edit action; or (5) email
parameter in a remember action.
|
| CVE-2009-2104 |
Cross-site scripting (XSS) vulnerability in the Modern Guestbook /
Commenting System (ve_guestbook) extension 2.7.1 and earlier for TYPO3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-2083 |
Cross-site scripting (XSS) vulnerability in the term data detail page
in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows
remote authenticated users, with administer taxonomy privileges or the
ability to use free tagging to add taxonomy terms, to inject arbitrary
web script or HTML via "Parent and related terms."
|
| CVE-2009-2079 |
Cross-site scripting (XSS) vulnerability in the administrative page
interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before
6.x-1.1, a module for Drupal, allows remote authenticated users, with
administer taxonomy privileges or the ability to use free tagging to
add taxonomy terms, to inject arbitrary web script or HTML via (1)
vocabulary names, (2) synonyms, and (3) term names.
|
| CVE-2009-2078 |
Multiple cross-site scripting (XSS) vulnerabilities in Booktree 5.x
before 5.x-7.3 and 6.x before 6.x-1.1, a module for Drupal, allow
remote attackers to inject arbitrary web script or HTML via the (1)
node title and (2) node body in a tree root page.
|
| CVE-2009-2076 |
Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6,
a module for Drupal, allows remote authenticated users to inject
arbitrary web script or HTML via (1) exposed filters in the Views UI
administrative interface and in the (2) view name parameter in the
define custom views feature. NOTE: vector 2 is only exploitable by
users with administer views permissions.
|
| CVE-2009-2074 |
Cross-site scripting (XSS) vulnerability in Nodequeue 5.x before
5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, allows remote
authenticated users with administer taxonomy permissions to inject
arbitrary web script or HTML via vocabulary names.
|
| CVE-2009-2048 |
Cross-site scripting (XSS) vulnerability in the Administration
interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2
in Cisco Unified Contact Center Express (aka CCX) server allows remote
authenticated users to inject arbitrary web script or HTML into the
CCX database via unspecified vectors.
|
| CVE-2009-2041 |
Cross-site scripting (XSS) vulnerability in A51 D.O.O. activeCollab
0.7.1 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, a different vulnerability than CVE-2009-1772.
|
| CVE-2009-2033 |
Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3
allows remote attackers to inject arbitrary web script or HTML via the
msg parameter.
|
| CVE-2009-2032 |
Cross-site scripting (XSS) vulnerability in search.asp in PDshopPro,
when downloaded before 20070308, allows remote attackers to inject
arbitrary web script or HTML via the search parameter.
|
| CVE-2009-2020 |
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue
News Manager allows remote attackers to inject arbitrary web script or
HTML via the nid parameter.
|
| CVE-2009-2009 |
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5,
and possibly earlier, allow remote attackers to inject arbitrary web
script or HTML via the (1) curdirpath parameter to
main/document/slideshow.php and the (2) file parameter to
main/exercice/testheaderpage.php.
|
| CVE-2009-2006 |
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5,
and possibly earlier, allow remote attackers to inject arbitrary web
script or HTML via the (1) search_term parameter to
main/auth/courses.php; the (2) frm_title and (3) frm_content
parameters in a new personal agenda item action; the (4) title and (5)
tutor_name parameters in a new course action; and the (6) student and
(7) course parameters to main/mySpace/myStudents.php. NOTE: vectors 2
and 3 might only be exploitable via a separate CSRF vulnerability.
|
| CVE-2009-1968 |
Unspecified vulnerability in the Secure Enterprise Search component in
Oracle Database 10.1.8.3 allows remote attackers to affect integrity
via unknown vectors. NOTE: the previous information was obtained from
the July 2009 CPU. Oracle has not commented on claims from an
established researcher that this is cross-site scripting (XSS) via the
search_p_groups parameter in search/query/search.
|
| CVE-2009-1951 |
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax
Pro FREE 0.3 allows remote attackers to inject arbitrary web script or
HTML via the pl parameter in a mi action.
|
| CVE-2009-1942 |
Cross-site scripting (XSS) vulnerability in the Quiz module 5.x,
6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for
Drupal, allows remote authenticated users, with create quizzes or quiz
questions access, to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-1940 |
Cross-site scripting (XSS) vulnerability in the administrator panel in
the com_users core component for Joomla! 1.5.x through 1.5.10 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-1939 |
Cross-site scripting (XSS) vulnerability in the JA_Purity template for
Joomla! 1.5.x through 1.5.10 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-1938 |
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through
1.5.10 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to database output and the frontend
administrative panel.
|
| CVE-2009-1937 |
Cross-site scripting (XSS) vulnerability in the comment posting
feature in LightNEasy 2.2.1 "no database" (aka flat) and 2.2.2 SQLite
allows remote attackers to inject arbitrary web script or HTML via the
(1) commentname (aka Author), (2) commentemail (aka Email), and (3)
commentmessage (aka Comment) parameters. NOTE: some of these details
are obtained from third party information.
|
| CVE-2009-1934 |
Cross-site scripting (XSS) vulnerability in the Reverse Proxy Plug-in
in Sun Java System Web Server 6.1 before SP11 allows remote attackers
to inject arbitrary web script or HTML via the query string in
situations that result in a 502 Gateway error.
|
| CVE-2009-1908 |
Cross-site scripting (XSS) vulnerability in Skip 1.0.2 and earlier,
and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-1907 |
Cross-site scripting (XSS) vulnerability in
claroline/linker/notfound.php in Claroline 1.8.11 allows remote
attackers to inject arbitrary web script or HTML via the Referer HTTP
header.
|
| CVE-2009-1903 |
The PDF XSS protection feature in ModSecurity before 2.5.8 allows
remote attackers to cause a denial of service (Apache httpd crash) via
a request for a PDF file that does not use the GET method.
|
| CVE-2009-1881 |
Cross-site scripting (XSS) vulnerability in MT312 IMG-BBS allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to model.php with a timestamp before
20090521.
|
| CVE-2009-1880 |
Cross-site scripting (XSS) vulnerability in MT312 REP-BBS allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to (1) model.php and (2) config.php with
timestamps before 20090521.
|
| CVE-2009-1879 |
Cross-site scripting (XSS) vulnerability in index.template.html in the
express-install templates in the SDK in Adobe Flex before 3.4, when
the installed Flash version is older than a specified
requiredMajorVersion value, allows remote attackers to inject
arbitrary web script or HTML via the query string.
|
| CVE-2009-1877 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, a different vulnerability than CVE-2009-1875.
|
| CVE-2009-1875 |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe
ColdFusion 8.0.1 and earlier allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors, a different
vulnerability than CVE-2009-1877.
|
| CVE-2009-1874 |
Multiple cross-site scripting (XSS) vulnerabilities in the Management
Console in Adobe JRun 4.0 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2009-1872 |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe
ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to
inject arbitrary web script or HTML via (1) the startRow parameter to
administrator/logviewer/searchlog.cfm, or the query string to (2)
wizards/common/_logintowizard.cfm, (3)
wizards/common/_authenticatewizarduser.cfm, or (4)
administrator/enter.cfm.
|
| CVE-2009-1849 |
Cross-site scripting (XSS) vulnerability in the Monitor_Bandwidth
function in PRTG Traffic Grapher 6.2.2.977 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-1845 |
Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in
Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject
arbitrary web script or HTML via the RequestName parameter.
|
| CVE-2009-1844 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x
before 5.18 and 6.x before 6.12 allow (1) remote authenticated users
to inject arbitrary web script or HTML via crafted UTF-8 byte
sequences that are treated as UTF-7 by Internet Explorer 6 and 7,
which are not properly handled in the "HTML exports of books" feature;
and (2) allow remote authenticated users with administer taxonomy
permissions to inject arbitrary web script or HTML via the help text
of an arbitrary vocabulary. NOTE: vector 1 exists because of an
incomplete fix for CVE-2009-1575.
|
| CVE-2009-1823 |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer,
e-mail and PDF versions) module 5.x before 5.x-4.7 and 6.x before
6.x-1.7, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML by modifying a document head, before the
Content-Type META element, to contain crafted UTF-8 byte sequences
that are treated as UTF-7 by Internet Explorer 6 and 7, a related
issue to CVE-2009-1575.
|
| CVE-2009-1820 |
Cross-site scripting (XSS) vulnerability in product.php in 2daybiz
Custom T-shirt Design Script allows remote attackers to inject
arbitrary web script or HTML via the id parameter.
|
| CVE-2009-1811 |
Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14
(aka 0.9) allow remote attackers to inject arbitrary web script or
HTML via (1) the Page parameter in a List action to
modules/ereignis.php, (2) the Kontext parameter in a Search action to
modules/kategorie.php, (3) the image parameter to modules/image.php,
or (4) the ID parameter in a Detail action to modules/sitzung.php.
|
| CVE-2009-1809 |
Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2
allow remote attackers to inject arbitrary web script or HTML via (1)
the year parameter to modules/kalender.php, (2) the Page parameter in
a List action to modules/ereignis.php, (3) the Kontext parameter in a
Search action to modules/kategorie.php, or (4) the image parameter to
modules/image.php.
|
| CVE-2009-1801 |
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1,
and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote
attackers to inject arbitrary web script or HTML via the (1) display
parameter to reports.php, the (2) order and (3) extdisplay parameters
to config.php, and the (4) sort parameter to recordings/index.php.
NOTE: some of these details are obtained from third party information.
|
| CVE-2009-1798 |
Multiple cross-site scripting (XSS) vulnerabilities on the Network
Management Card (NMC) on American Power Conversion (APC) Switched Rack
PDU (aka Rack Mount Power Distribution) devices and other devices
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: the login_username vector for Forms/login1
is already covered by CVE-2009-4406.
|
| CVE-2009-1796 |
Cross-site scripting (XSS) vulnerability in Sun Java System Portal
Server 6.3.1, 7.1, and 7.2 allows remote attackers to inject arbitrary
web script or HTML via vectors related to an error page.
|
| CVE-2009-1790 |
Cross-site scripting (XSS) vulnerability in CGI RESCUE Trees before
2.11 allows remote attackers to inject arbitrary web script or HTML
via unspecified parameters.
|
| CVE-2009-1785 |
Cross-site scripting (XSS) vulnerability in Ulteo Open Virtual Desktop
1.0 allows remote attackers to inject arbitrary web script or HTML via
the error parameter to header.php. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-1776 |
Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in
Matt Wright FormMail 1.92, and possibly earlier, allow remote
attackers to inject arbitrary web script or HTML via javascript: URIs
in the (1) request and (2) return_link_url parameters.
|
| CVE-2009-1775 |
Multiple cross-site scripting (XSS) vulnerabilities in Ulteo Open
Virtual Desktop 1.0 allow remote attackers to inject arbitrary web
script or HTML via the id parameter to (1) admin/applications.php, (2)
admin/appsgroup.php, (3) admin/users.php, (4) admin/usersgroup.php,
and (5) admin/tasks.php; (6) show parameter to admin/logs.php; and (7)
mode parameter to admin/configuration-partial.php. NOTE: some of these
details are obtained from third party information.
|
| CVE-2009-1772 |
Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate
allows remote attackers to inject arbitrary web script or HTML via the
re_route parameter to the login script.
|
| CVE-2009-1762 |
Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess
login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2
allow remote attackers to inject arbitrary web script or HTML via the
(1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter.
|
| CVE-2009-1749 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web
script or HTML via the (1) userman_form and (2) webpages_form
parameters.
|
| CVE-2009-1738 |
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before
6.x-1.1, a module for Drupal, allows remote authenticated users with
administrator feed permissions to inject arbitrary web script or HTML
via unspecified vectors in "aggregator items."
|
| CVE-2009-1735 |
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro
allows remote attackers to inject arbitrary web script or HTML via the
searchtxt parameter. NOTE: some of these details are obtained from
third party information.
|
| CVE-2009-1732 |
Cross-site scripting (XSS) vulnerability in admin/usermanager in
IPplan 4.91a allows remote attackers to inject arbitrary web script or
HTML via the grp parameter.
|
| CVE-2009-1729 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System
Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote
attackers to inject arbitrary web script or HTML via (1) the
abperson_displayName parameter to uwc/abs/search.xml in the Add
Contact implementation in the Personal Address Book component or (2)
the temporaryCalendars parameter to uwc/base/UWCMain.
|
| CVE-2009-1724 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1
for iPod touch, and other platforms, allows remote attackers to inject
arbitrary web script or HTML via vectors related to parent and top
objects.
|
| CVE-2009-1715 |
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in
Apple Safari before 4.0 allows user-assisted remote attackers to
inject arbitrary web script or HTML, and read local files, via vectors
related to script execution with incorrect privileges.
|
| CVE-2009-1714 |
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in
Apple Safari before 4.0 allows user-assisted remote attackers to
inject arbitrary web script or HTML, and read local files, via vectors
related to the improper escaping of HTML attributes.
|
| CVE-2009-1702 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
1.1 through 2.2.1 allows remote attackers to inject arbitrary web
script or HTML via vectors related to improper handling of Location
and History objects.
|
| CVE-2009-1697 |
CRLF injection vulnerability in WebKit in Apple Safari before 4.0,
iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through
2.2.1 allows remote attackers to inject HTTP headers and bypass the
Same Origin Policy via a crafted HTML document, related to cross-site
scripting (XSS) attacks that depend on communication with arbitrary
web sites on the same server through use of XMLHttpRequest without a
Host header.
|
| CVE-2009-1695 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
1.1 through 2.2.1 allows remote attackers to inject arbitrary web
script or HTML via vectors involving access to frame contents after
completion of a page transition.
|
| CVE-2009-1691 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
1.1 through 2.2.1 allows remote attackers to inject arbitrary web
script or HTML via vectors related to insufficient access control for
standard JavaScript prototypes in other domains.
|
| CVE-2009-1689 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
1.1 through 2.2.1 allows remote attackers to inject arbitrary web
script or HTML via vectors involving submission of a form to the
about:blank URL, leading to security-context replacement.
|
| CVE-2009-1688 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
1.1 through 2.2.1 allows remote attackers to inject arbitrary web
script or HTML via vectors related to determining a security context
through an approach that is not the "HTML 5 standard method."
|
| CVE-2009-1685 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
1.1 through 2.2.1 allows remote attackers to inject arbitrary web
script or HTML by overwriting the document.implementation property of
(1) an embedded document or (2) a parent document.
|
| CVE-2009-1684 |
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
1.1 through 2.2.1 allows remote attackers to inject arbitrary web
script or HTML via an event handler that triggers script execution in
the context of the next loaded document.
|
| CVE-2009-1654 |
Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy
Scripts Answer and Question Script allows remote attackers to inject
arbitrary web script or HTML via the questionid parameter.
|
| CVE-2009-1635 |
Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess
component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0
HP2 allow remote attackers to inject arbitrary web script or HTML via
(1) the User.lang parameter to the login page (aka gw/webacc), (2)
style expressions in a message that contains an HTML file, or (3)
vectors associated with incorrect protection mechanisms against
scripting, as demonstrated using whitespace between JavaScript event
names and values.
|
| CVE-2009-1623 |
Cross-site scripting (XSS) vulnerability in index.php in
Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web
script or HTML via the PID parameter.
|
| CVE-2009-1620 |
Multiple cross-site scripting (XSS) vulnerabilities in input.php in
MataChat allow remote attackers to inject arbitrary web script or HTML
via the (1) nickname and (2) color parameters.
|
| CVE-2009-1616 |
Cross-site scripting (XSS) vulnerability in docs/showdoc.php in
Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers
to inject arbitrary web script or HTML via the css parameter, a
different vector than CVE-2008-0505.
|
| CVE-2009-1614 |
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4
allow remote attackers to inject arbitrary web script or HTML via (1)
the msg parameter (aka the message in an article comment) or (2) the
searchterm parameter (aka the search post form). NOTE: some of these
details are obtained from third party information.
|
| CVE-2009-1607 |
Cross-site scripting (XSS) vulnerability in the administrator panel in
phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary
web script or HTML via the username in a registration, which is not
properly handled when the administrator accesses the Users menu.
|
| CVE-2009-1594 |
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x
before 2.4.4, does not properly implement the "positive model," which
allows remote attackers to bypass certain protection mechanisms via a
%0A (encoded newline), as demonstrated by a %0A in a cross-site
scripting (XSS) attack URL.
|
| CVE-2009-1593 |
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x
before 2.4.4, does not properly implement the "negative model," which
allows remote attackers to conduct cross-site scripting (XSS) attacks
via a modified end tag of a SCRIPT element.
|
| CVE-2009-1591 |
CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04
allows remote attackers to inject arbitrary HTTP headers, and conduct
cross-site scripting (XSS) or HTTP response splitting attacks, via
CRLF sequences in an unspecified web form.
|
| CVE-2009-1588 |
Cross-site scripting (XSS) vulnerability in CGI RESCUE MiniBBS 8t
before 8.95t, 8 before 8.95, 9 before 9.08, and 10 before 10.32 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-1583 |
Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3
and 1.031 allow remote attackers to inject arbitrary web script or
HTML via the (1) search form; (2) _expresion_de_busqueda, (3) letra,
(4) estado_id, and (5) tema parameters to index.php; the (6) PATH_INFO
to index.php; (7) unspecified parameters when editing a term as
specified by the edit_id and tema parameters to index.php; and the (7)
y, (8) ord, and (9) m parameters to sobre.php.
|
| CVE-2009-1581 |
functions/mime.php in SquirrelMail before 1.4.18 does not protect the
application's content from Cascading Style Sheets (CSS) positioning in
HTML e-mail messages, which allows remote attackers to spoof the user
interface, and conduct cross-site scripting (XSS) and phishing
attacks, via a crafted message.
|
| CVE-2009-1578 |
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail
before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject
arbitrary web script or HTML via vectors involving (1) certain
encrypted strings in e-mail headers, related to
contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string
(aka QUERY_STRING).
|
| CVE-2009-1575 |
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and
6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote
attackers to inject arbitrary web script or HTML via crafted UTF-8
byte sequences before the Content-Type meta tag, which are treated as
UTF-7 by Internet Explorer 6 and 7.
|
| CVE-2009-1557 |
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco
Linksys WVC54GCA wireless video camera with firmware 1.00R22 and
1.00R24 allow remote attackers to inject arbitrary web script or HTML
via the next_file parameter to (1) main.cgi, (2) img/main.cgi, or (3)
adm/file.cgi; or (4) the this_file parameter to adm/file.cgi.
|
| CVE-2009-1554 |
Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun
Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other
products, allows remote attackers to inject arbitrary web script or
HTML via a UTF-7 string in the PATH_INFO, which is displayed on the
404 error page, as demonstrated by the PATH_INFO to theme/META-INF.
|
| CVE-2009-1553 |
Multiple cross-site scripting (XSS) vulnerabilities in the Admin
Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers
to inject arbitrary web script or HTML via the query string to (1)
applications/applications.jsf, (2) configuration/configuration.jsf,
(3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5)
sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or
the name parameter to (7) configuration/auditModuleEdit.jsf, (8)
configuration/httpListenerEdit.jsf, or (9)
resourceNode/jdbcResourceEdit.jsf.
|
| CVE-2009-1524 |
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before
6.1.17 allows remote attackers to inject arbitrary web script or HTML
via a directory listing request containing a ; (semicolon) character.
|
| CVE-2009-1501 |
Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x
before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for
Drupal, allows remote attackers to inject arbitrary web script or HTML
via EXIF tags in an image.
|
| CVE-2009-1484 |
Cross-site scripting (XSS) vulnerability in the web mail interface
feature in AXIGEN Mail Server 6.2.2 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors involving e-mail
messages. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2009-1482 |
Multiple cross-site scripting (XSS) vulnerabilities in
action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote
attackers to inject arbitrary web script or HTML via (1) an AttachFile
sub-action in the error_msg function or (2) multiple vectors related
to package file errors in the upload_form function, different vectors
than CVE-2009-0260.
|
| CVE-2009-1467 |
Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail
Server and WebMail Server before 9.4.2 allow remote attackers to
inject arbitrary web script or HTML via (1) the body of a message,
related to the email view and incorrect HTML filtering in the
cleanHTML function in server/inc/tools.php; or the (2) title, (3)
link, or (4) description element in an RSS feed, related to the
getHTML function in server/inc/rss/item.php.
|
| CVE-2009-1461 |
Cross-site scripting (XSS) vulnerability in the Create New Page form
in razorCMS 0.3 RC2 and earlier allows remote authenticated users to
inject arbitrary web script or HTML via the Page Title field.
|
| CVE-2009-1458 |
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php
in razorCMS before 0.4 allow remote attackers to inject arbitrary web
script or HTML via (1) the slab parameter in an edit action, (2) the
catname parameter in a showcats action, and (3) the cat parameter in a
reordercat action.
|
| CVE-2009-1457 |
Cross-site scripting (XSS) vulnerability in player.php in Nuke
Evolution Xtreme 2.x allows remote attackers to inject arbitrary web
script or HTML via the defaultVisualExt parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2009-1454 |
Cross-site scripting (XSS) vulnerability in tasks.php in WebCollab
before 2.50 (aka Billy Goat) allows remote attackers to inject
arbitrary web script or HTML via the selection parameter in a todo
action.
|
| CVE-2009-1451 |
Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB
0.3.12 allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO.
|
| CVE-2009-1448 |
Cross-site scripting (XSS) vulnerability in apricot.php in LovPop.net
APRICOT, probably 1.20, allows remote attackers to inject arbitrary
web script or HTML via unspecified parameters.
|
| CVE-2009-1428 |
Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in
the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before
10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1,
Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow
remote attackers to inject arbitrary web script or HTML via a crafted
e-mail message, related to "two parsing errors."
|
| CVE-2009-1418 |
Cross-site scripting (XSS) vulnerability in HP System Management
Homepage (SMH) before 3.0.1.73 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-1414 |
Google Chrome 2.0.x lets modifications to the global object persist
across a page transition, which makes it easier for attackers to
conduct Universal XSS attacks via unspecified vectors.
|
| CVE-2009-1413 |
Google Chrome 1.0.x does not cancel timeouts upon a page transition,
which makes it easier for attackers to conduct Universal XSS attacks
by calling setTimeout to trigger future execution of JavaScript code,
and then modifying document.location to arrange for JavaScript
execution in the context of an arbitrary web site. NOTE: this can be
leveraged for a remote attack by exploiting a chromehtml:
argument-injection vulnerability.
|
| CVE-2009-1412 |
Argument injection vulnerability in the chromehtml: protocol handler
in Google Chrome before 1.0.154.59, when invoked by Internet Explorer,
allows remote attackers to determine the existence of files, and open
tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via
a web page that sets document.location to a chromehtml: value, as
demonstrated by use of a (1) javascript: or (2) data: URL. NOTE: this
can be leveraged for Universal XSS by exploiting certain behavior
involving persistence across page transitions.
|
| CVE-2009-1408 |
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows
remote attackers to inject arbitrary web script or HTML allows remote
attackers to inject arbitrary web script or HTML via Javascript events
such as onmouseover in nested BBcode tags, as demonstrated using (1)
email, (2) img, and (3) url tags.
|
| CVE-2009-1380 |
Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP)
4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote
attackers to inject arbitrary web script or HTML via the filter
parameter, related to the key property and the position of quote and
colon characters.
|
| CVE-2009-1367 |
Cross-site scripting (XSS) vulnerability in index.php in moziloCMS
1.11 allows remote attackers to inject arbitrary web script or HTML
via the query parameter in search action, a different issue than
CVE-2008-6127.2a.
|
| CVE-2009-1366 |
Cross-site scripting (XSS) vulnerability in
Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to "name/value pairs" and "paypal IPN
functionality."
|
| CVE-2009-1349 |
Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2.3
allows remote attackers to inject arbitrary web script or HTML via the
URI.
|
| CVE-2009-1344 |
Cross-site scripting (XSS) vulnerability in the Localization client
module 5.x before 5.x-1.2 and 6.x before 6.x-1.7, a module for Drupal,
allows remote attackers to inject arbitrary web script or HTML via
input to the translation functionality.
|
| CVE-2009-1343 |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer,
e-mail and PDF versions) module 5.x before 5.x-4.5 and 6.x before
6.x-1.5, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via content titles.
|
| CVE-2009-1342 |
Cross-site scripting (XSS) vulnerability in the CCK comment reference
module 6.x before 6.x-1.2, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via certain comment
titles associated with a node edit form.
|
| CVE-2009-1334 |
Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html
in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0
allows remote attackers to inject arbitrary web script or HTML via the
reason parameter.
|
| CVE-2009-1333 |
Cross-site scripting (XSS) vulnerability in refresh_rate.htm in the
web interface on the HP Deskjet 6840 printer with firmware XF1M131A
allows remote attackers to inject arbitrary web script or HTML via the
POST request body.
|
| CVE-2009-1321 |
Cross-site scripting (XSS) vulnerability in search.asp in ASP Product
Catalog 1.0 allows remote attackers to inject arbitrary web script or
HTML via the keywords parameter.
|
| CVE-2009-1320 |
Multiple cross-site scripting (XSS) vulnerabilities in
include/zstore.php in Zazzle Store Builder 1.0.2 allow remote
attackers to inject arbitrary web script or HTML via the (1) gridPage
and (2) gridSort parameters. NOTE: some of these details are obtained
from third party information.
|
| CVE-2009-1315 |
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) gid parameter to groups_profile.php, (2) cat_id and (3) razd_id
parameters to adv_cat.php, and the (4) URL to blogs_full.php.
|
| CVE-2009-1312 |
Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block
javascript: URIs in Refresh headers in HTTP responses, which allows
remote attackers to conduct cross-site scripting (XSS) attacks via
vectors related to (1) injecting a Refresh header or (2) specifying
the content of a Refresh header. NOTE: it was later reported that
Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.
|
| CVE-2009-1310 |
Cross-site scripting (XSS) vulnerability in the MozSearch plugin
implementation in Mozilla Firefox before 3.0.9 allows user-assisted
remote attackers to inject arbitrary web script or HTML via a
javascript: URI in the SearchForm element.
|
| CVE-2009-1309 |
Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not
properly implement the Same Origin Policy for (1) XMLHttpRequest,
involving a mismatch for a document's principal, and (2)
XPCNativeWrapper.toString, involving an incorrect __proto__ scope,
which allows remote attackers to conduct cross-site scripting (XSS)
attacks and possibly other attacks via a crafted document.
|
| CVE-2009-1308 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before
3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject
arbitrary web script or HTML via vectors involving XBL JavaScript
bindings and remote stylesheets, as exploited in the wild by a March
2009 eBay listing.
|
| CVE-2009-1306 |
The jar: URI implementation in Mozilla Firefox before 3.0.9,
Thunderbird, and SeaMonkey does not follow the Content-Disposition
header of the inner URI, which allows remote attackers to conduct
cross-site scripting (XSS) attacks and possibly other attacks via an
uploaded .jar file with a "Content-Disposition: attachment"
designation.
|
| CVE-2009-1294 |
Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home
in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3)
allow remote attackers to inject arbitrary web script or HTML via the
(1) p_p_state or (2) p_p_mode parameters.
|
| CVE-2009-1288 |
Multiple cross-site scripting (XSS) vulnerabilities in the Advanced
Management Module (AMM) on the IBM BladeCenter, including the
BladeCenter H with BPET36H 54, allow remote attackers to inject
arbitrary web script or HTML via (1) the username in a login action or
(2) the PATH parameter to private/file_management.ssi in the File
manager.
|
| CVE-2009-1287 |
Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge
Services Manager (SESM) allows remote attackers to inject arbitrary
web script or HTML via the URI. NOTE: some of these details are
obtained from third party information.
|
| CVE-2009-1281 |
Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-1279 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5
through 1.5.9 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors to the (1) com_admin component, (2)
com_search component when "Gather Search Statistics" is enabled, and
(3) the category view in the com_content component.
|
| CVE-2009-1275 |
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other
products, evaluates Expression Language (EL) expressions twice in
certain circumstances, which allows remote attackers to conduct
cross-site scripting (XSS) attacks or obtain sensitive information via
unspecified vectors, related to the (1) tiles:putAttribute and (2)
tiles:insertTemplate JSP tags.
|
| CVE-2009-1261 |
Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk
9.1.22 (evaluation version) allow remote attackers to inject arbitrary
web script or HTML via the (1) Report Name, (2) Asset No., and (3)
Full Name fields in a Models action. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-1249 |
Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x
before 5.x-1.1, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via the content title in
admin/content/node-type/nodetype/map.
|
| CVE-2009-1228 |
Cross-site scripting (XSS) vulnerability in register.php in Arcadwy
Arcade Script CMS allows remote attackers to inject arbitrary web
script or HTML via the username field (user_name parameter).
|
| CVE-2009-1225 |
Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook
Store 1.1 allows remote attackers to inject arbitrary web script or
HTML via the keywords parameter in a search action.
|
| CVE-2009-1220 |
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in
WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with
software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and
8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled,
allows remote attackers to inject arbitrary web script or HTML via the
Host HTTP header.
|
| CVE-2009-1218 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar
Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System
Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to
inject arbitrary web script or HTML via (1) the fmt-out parameter to
login.wcap or (2) the date parameter to command.shtml.
|
| CVE-2009-1204 |
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki)
CMS/Groupware 2.2 allows remote attackers to inject arbitrary web
script or HTML via the PHP_SELF portion of a URI to (1)
tiki-galleries.php, (2) tiki-list_file_gallery.php, (3)
tiki-listpages.php, and (4) tiki-orphan_pages.php.
|
| CVE-2009-1202 |
WebVPN on the Cisco Adaptive Security Appliances (ASA) device with
software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass
certain protection mechanisms involving URL rewriting and HTML
rewriting, and conduct cross-site scripting (XSS) attacks, by
modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID
CSCsy80705.
|
| CVE-2009-1201 |
Eval injection vulnerability in the csco_wrap_js function in
/+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances
(ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote
attackers to bypass a DOM wrapper and conduct cross-site scripting
(XSS) attacks by setting CSCO_WebVPN['process'] to the name of a
crafted function, aka Bug ID CSCsy80694.
|
| CVE-2009-1198 |
Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0
allows remote attackers to inject arbitrary web script or HTML via the
dsname parameter to happyjuddi.jsp.
|
| CVE-2009-1175 |
Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in
the DAAP extension in Banshee 1.4.2 allows remote attackers to inject
arbitrary web script or HTML via the server parameter, which is not
properly handled in an error message.
|
| CVE-2009-1162 |
Cross-site scripting (XSS) vulnerability in the Spam Quarantine login
page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X
appliances allows remote attackers to inject arbitrary web script or
HTML via the referrer parameter.
|
| CVE-2009-1150 |
Multiple cross-site scripting (XSS) vulnerabilities in the export page
(display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x
before 3.1.3.1 allow remote attackers to inject arbitrary web script
or HTML via the pma_db_filename_template cookie.
|
| CVE-2009-1104 |
The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime
Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier;
and 1.4.2_19 and earlier does not prevent Javascript that is loaded
from the localhost from connecting to other ports on the system, which
allows user-assisted attackers to bypass intended access restrictions
via LiveConnect, aka CR 6724331. NOTE: this vulnerability can be
leveraged with separate cross-site scripting (XSS) vulnerabilities for
remote attack vectors.
|
| CVE-2009-1091 |
Cross-site scripting (XSS) vulnerability in upload.php in Rapidleech
rev.36 and earlier allows remote attackers to inject arbitrary web
script or HTML via the uploaded parameter.
|
| CVE-2009-1081 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System
Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka Bug
IDs 19595 and 19661.
|
| CVE-2009-1080 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System
Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka Bug
ID 19033.
|
| CVE-2009-1079 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System
Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka Bug
IDs 19659, 19660, and 19683.
|
| CVE-2009-1070 |
Cross-site scripting (XSS) vulnerability in system/index.php in
ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions,
allows remote attackers to inject arbitrary web script or HTML via the
avatar parameter.
|
| CVE-2009-1069 |
Multiple cross-site scripting (XSS) vulnerabilities in the node edit
form feature in Drupal Content Construction Kit (CCK) 6.x before
6.x-2.2, a module for Drupal, allow remote attackers to inject
arbitrary web script or HTML via the (1) titles of candidate
referenced nodes in the Node reference sub-module and the (2) names of
candidate referenced users in the User reference sub-module.
|
| CVE-2009-1067 |
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS
1.01a allows remote attackers to inject arbitrary web script or HTML
via the x parameter.
|
| CVE-2009-1047 |
Cross-site scripting (XSS) vulnerability in the Send by e-mail module
in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4
and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers
to inject arbitrary web script or HTML via vectors involving outbound
HTML e-mail.
|
| CVE-2009-1035 |
Cross-site scripting (XSS) vulnerability in the Tasklist module
5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for
Drupal, allows remote authenticated users to inject arbitrary web
script or HTML via Cascading Style Sheets (CSS).
|
| CVE-2009-1030 |
Cross-site scripting (XSS) vulnerability in the choose_primary_blog
function in wp-includes/wpmu-functions.php in WordPress MU (WPMU)
before 2.7 allows remote attackers to inject arbitrary web script or
HTML via the HTTP Host header.
|
| CVE-2009-0971 |
Cross-site scripting (XSS) vulnerability in futomi's CGI Cafe Access
Analyzer CGI Standard Version 3.8.1 and earlier allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2009-0934 |
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors related to links and MUC logs.
|
| CVE-2009-0933 |
Cross-site scripting (XSS) vulnerability in the administrative
interface in Dotclear before 2.1.5 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-0931 |
Cross-site scripting (XSS) vulnerability in the tag cloud search
script (horde/services/portal/cloud_search.php) in Horde before 3.2.4
and 3.3.3, and Horde Groupware before 1.1.5, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-0930 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP
before 4.2.2 and 4.3.3 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors to (1) smime.php, (2) pgp.php,
and (3) message.php.
|
| CVE-2009-0917 |
Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through
1.0.4 allows remote attackers to inject arbitrary web script or HTML
by providing a forensic image containing HTML documents, which are
rendered in web browsers during inspection by PTK. NOTE: the vendor
states that the product is intended for use in a laboratory with "no
contact from / to internet."
|
| CVE-2009-0877 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System
Communications Express allow remote attackers to inject arbitrary web
script or HTML via the (1) Full Name or (2) Subject field.
|
| CVE-2009-0862 |
Cross-site scripting (XSS) vulnerability in the
hook_cntrlr_error_output function in modules/page/hooks/listeners.php
in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: some of these details are obtained from
third party information.
|
| CVE-2009-0861 |
Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3
allows remote attackers to inject arbitrary web script or HTML via an
IRC channel name. NOTE: some of these details are obtained from third
party information.
|
| CVE-2009-0860 |
Cross-site scripting (XSS) vulnerability in the web user interface in
the login application in NetMRI 3.0.1 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, related to error pages.
|
| CVE-2009-0857 |
Cross-site scripting (XSS) vulnerability in /prm/reports in the
Performance Reporting Module (PRM) for Sun Management Center (SunMC)
3.6.1 and 4.0 allows remote attackers to inject arbitrary web script
or HTML via the msg parameter. NOTE: this can be leveraged for access
to the SunMC Web Console.
|
| CVE-2009-0856 |
Multiple cross-site scripting (XSS) vulnerabilities in sample
applications in IBM WebSphere Application Server (WAS) 6.0.2 before
6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-0855 |
Cross-site scripting (XSS) vulnerability in the administrative console
in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-0850 |
Cross-site scripting (XSS) vulnerability in BitDefender Internet
Security 2009 allows user-assisted remote attackers to inject
arbitrary web script or HTML via the filename of a virus-infected
file, as demonstrated by a filename inside a (1) rar or (2) zip
archive file.
|
| CVE-2009-0830 |
Cross-site scripting (XSS) vulnerability in QuoteBook allows remote
attackers to inject arbitrary web script or HTML via the (1) QuoteName
and (2) QuoteText parameters to quotesadd.php. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2009-0818 |
Cross-site scripting (XSS) vulnerability in the
taxonomy_theme_admin_table_builder function (taxonomy_theme_admin.inc)
in Taxonomy Theme module before 5.x-1.2, a module for Drupal, allows
remote authenticated users with the "administer taxonomy" permission,
or the ability to create pages when tagging is enabled, to inject
arbitrary web script or HTML via the Vocabulary name (name parameter)
to index.php. NOTE: some of these details are obtained from third
party information.
|
| CVE-2009-0817 |
Cross-site scripting (XSS) vulnerability in the Protected Node module
5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows
remote authenticated users with "administer site configuration"
permissions to inject arbitrary web script or HTML via the Password
page info field, which is not properly handled by the
protected_node_enterpassword function in protected_node.module.
|
| CVE-2009-0816 |
Multiple cross-site scripting (XSS) vulnerabilities in the backend
user interface in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1
before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 allow remote attackers
to inject arbitrary web script or HTML via unspecified fields.
|
| CVE-2009-0815 |
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through
3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and
4.3alpha1 leaks a hash secret (juHash) in an error message, which
allows remote attackers to read arbitrary files by including the hash
in a request.
|
| CVE-2009-0814 |
Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0
Beta 3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the searchText parameter.
|
| CVE-2009-0805 |
Cross-site scripting (XSS) vulnerability in piCal 0.91h and earlier, a
module for XOOPS, allows remote attackers to inject arbitrary web
script or HTML via the event_id parameter in index.php.
|
| CVE-2009-0796 |
Cross-site scripting (XSS) vulnerability in Status.pm in
Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the
Apache HTTP Server, when /perl-status is accessible, allows remote
attackers to inject arbitrary web script or HTML via the URI.
|
| CVE-2009-0781 |
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the
calendar application in the examples web application in Apache Tomcat
4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18
allows remote attackers to inject arbitrary web script or HTML via the
time parameter, related to "invalid HTML."
|
| CVE-2009-0764 |
Multiple cross-site scripting (XSS) vulnerabilities in Kipper 2.01
allow remote attackers to inject arbitrary web script or HTML via the
charm parameter to (1) index.php and (2) kipper.php. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2009-0763 |
Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01
allows remote attackers to inject arbitrary web script or HTML via the
charm parameter.
|
| CVE-2009-0762 |
Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment
allows remote attackers to inject arbitrary web script or HTML via the
name parameter. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2009-0761 |
Cross-site scripting (XSS) vulnerability in online.asp in Team Board
1.x allows remote attackers to inject arbitrary web script or HTML via
the lookname parameter.
|
| CVE-2009-0743 |
Cross-site scripting (XSS) vulnerability in the edit account page in
the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0
before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1)
allows remote authenticated users to inject arbitrary web script or
HTML via the E-mail Address field.
|
| CVE-2009-0737 |
Multiple cross-site scripting (XSS) vulnerabilities in the web-based
installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12
before 1.12.4, and 1.13 before 1.13.4, when the installer is in active
use, allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-0736 |
Cross-site scripting (XSS) vulnerability in Pebble before 2.3.2 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-0710 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6
allow remote attackers to inject arbitrary web script or HTML via (1)
the user parameter to login.php or (2) the dbfield parameter to
filter.php. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2009-0699 |
Cross-site scripting (XSS) vulnerability in
pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1
and earlier allows remote authenticated users to inject arbitrary web
script or HTML via the (1) QUB and (2) Bez74 parameters.
|
| CVE-2009-0679 |
Cross-site scripting (XSS) vulnerability in the Your Account module in
RavenNuke 2.30 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2009-0664 |
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x
before 1.0.11 and 1.1.x before 1.1.3 allow remote attackers to inject
arbitrary web script or HTML via (1) the introduction field in a user
profile or (2) an arbitrary text block in a user view.
|
| CVE-2009-0660 |
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0
before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject
arbitrary web script or HTML via a (1) profile and (2) blog, a
different vulnerability than CVE-2009-0487.
|
| CVE-2009-0611 |
Multiple cross-site scripting (XSS) vulnerabilities in
qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise
Server 1.x allow remote attackers to inject arbitrary web script or
HTML via (1) the siteloc parameter in a displayaddsite action, the
site parameter in a (2) generalproperties or (3)
clusterserviceproperties action, (4) the adminurl parameter in a
global action, or (5) the print-list parameter.
|
| CVE-2009-0603 |
Cross-site scripting (XSS) vulnerability in index.php in the Link
module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with
"administer content types" privileges, to inject arbitrary web script
or HTML via the description parameter (aka the Help field). NOTE: some
of these details are obtained from third party information.
|
| CVE-2009-0594 |
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite
1.4 allows remote attackers to inject arbitrary web script or HTML via
the PATH_INFO.
|
| CVE-2009-0575 |
Cross-site scripting (XSS) vulnerability in the
theme_views_bulk_operations_confirmation function in
views_bulk_operations.module in Views Bulk Operations 5.x before
5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors related to node titles. NOTE: some of these details are
obtained from third party information.
|
| CVE-2009-0573 |
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0
(Build 273) allow remote attackers to inject arbitrary web script or
HTML via the (1) s parameter to cmdrequest/Login.fwx and the (2)
search parameter to Grid.fwx.
|
| CVE-2009-0548 |
Cross-site scripting (XSS) vulnerability in the Additional Report
Settings interface in ESET Remote Administrator before 3.0.105 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: some of these details are obtained from
third party information.
|
| CVE-2009-0541 |
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0
and 1.2.1.1 allow remote attackers to inject arbitrary web script or
HTML via (1) the username field in an admin/ request to index.php,
possibly related to the login[username] parameter and the
app/code/core/Mage/Admin/Model/Session.php login function; (2) the
email address field in an admin/index/forgotpassword/ request to
index.php, possibly related to the email parameter and the
app/code/core/Mage/Adminhtml/controllers/IndexController.php
forgotpasswordAction function; or (3) the return parameter to the
default URI under downloader/.
|
| CVE-2009-0540 |
Cross-site scripting (XSS) vulnerability in Libero 5.3 SP5, and
possibly other versions before 5.5 SP1, allows remote attackers to
inject arbitrary web script or HTML via the search term field.
|
| CVE-2009-0533 |
Cross-site scripting (XSS) vulnerability in password.php in Scripts
for Sites EZ Reminder allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, possibly involving the u2
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2009-0532 |
Cross-site scripting (XSS) vulnerability in password.php in Scripts
For Sites (SFS) EZ Baby allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, possibly involving the u2
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2009-0529 |
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster
Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web
script or HTML via the language parameter.
|
| CVE-2009-0526 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web
script or HTML via the (1) url and (2) acuparam parameters, and (3)
the URI.
|
| CVE-2009-0525 |
Cross-site scripting (XSS) vulnerability in the sajax_get_common_js
function in php/Sajax.php in Sajax 0.12 allows remote attackers to
inject arbitrary web script or HTML via the URL parameter, which is
not properly handled when using browsers that do not URL-encode
requests, such as Internet Explorer 6. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2009-0524 |
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7,
and RoboHelp Server 6 and 7, allows remote attackers to inject
arbitrary web script or HTML via vectors involving files produced by
RoboHelp.
|
| CVE-2009-0523 |
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6
and 7 allows remote attackers to inject arbitrary web script or HTML
via a crafted URL, which is not properly handled when displaying the
Help Errors log.
|
| CVE-2009-0502 |
Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php
in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7,
1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to
inject arbitrary web script or HTML via an HTML block, which is not
properly handled when the "Login as" feature is used to visit a
MyMoodle or Blog page.
|
| CVE-2009-0500 |
Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle
1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before
1.9.4 allows remote attackers to inject arbitrary web script or HTML
via crafted log table information that is not properly handled when it
is displayed in a log report.
|
| CVE-2009-0496 |
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime
Openfire 3.6.2 allow remote attackers to inject arbitrary web script
or HTML via the (1) log parameter to (a) logviewer.jsp and (b)
log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username
parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize,
(6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e)
audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp;
and the (10) roomconfig_roomname and (11) roomconfig_roomdesc
parameters to (g) muc-room-edit-form.jsp. NOTE: this can be leveraged
for arbitrary code execution by using XSS to upload a malicious
plugin.
|
| CVE-2009-0488 |
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.10
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-0487 |
Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows
remote attackers to inject arbitrary web script or HTML via a crafted
forum post.
|
| CVE-2009-0481 |
Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and
3.3 before 3.3.2 allows remote authenticated users to conduct
cross-site scripting (XSS) and related attacks by uploading HTML and
JavaScript attachments that are rendered by web browsers.
|
| CVE-2009-0472 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface in the Rockwell Automation ControlLogix 1756-ENBT/A
EtherNet/IP Bridge Module allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2009-0471 |
Cross-site request forgery (CSRF) vulnerability in the HTTP server in
Cisco IOS 12.4(23) allows remote attackers to execute arbitrary
commands, as demonstrated by executing the hostname command with a
level/15/configure/-/hostname request.
|
| CVE-2009-0470 |
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server
in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web
script or HTML via the PATH_INFO to the default URI under (1)
level/15/exec/-/ or (2) exec/, a different vulnerability than
CVE-2008-3821.
|
| CVE-2009-0467 |
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web
Application Firewall 2.6.2 and 2.6.3 allows remote attackers to inject
arbitrary web script or HTML via the proxy parameter in a deny_log
manage action.
|
| CVE-2009-0466 |
Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1
allows remote attackers to inject arbitrary web script or HTML via a
URI that triggers a 404 Page Not Found response.
|
| CVE-2009-0455 |
Cross-site scripting (XSS) vulnerability in the anonymous comments
feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and earlier
versions allows remote attackers to inject arbitrary web script or
HTML via the username parameter to comment.php.
|
| CVE-2009-0430 |
Multiple cross-site scripting (XSS) vulnerabilities in Active Bids
allow remote attackers to inject arbitrary web script or HTML via the
(1) search parameter to search.asp and the (2) URL parameter to
tellafriend.asp.
|
| CVE-2009-0424 |
Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook
(ANG) before 0.7.7 allows remote attackers to inject arbitrary web
script or HTML via the country parameter, which is not properly
handled in (1) administrator/manage.php or (2)
administrator/trash.php. NOTE: some of these details are obtained from
third party information.
|
| CVE-2009-0417 |
Cross-site scripting (XSS) vulnerability in the
AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0
before 1.0.0 beta 8 allows remote attackers to inject arbitrary web
script or HTML via a crafted URL with certain characters that are not
properly handled by web browsers that do not strictly follow RFC 3986,
such as Internet Explorer 6 and 7.
|
| CVE-2009-0413 |
Cross-site scripting (XSS) vulnerability in RoundCube Webmail
(roundcubemail) 0.2 stable allows remote attackers to inject arbitrary
web script or HTML via the background attribute embedded in an HTML
e-mail message.
|
| CVE-2009-0404 |
Multiple cross-site scripting (XSS) vulnerabilities in Bioinformatics
htmLawed 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary
web script or HTML via invalid Cascading Style Sheets (CSS)
expressions in the style attribute, which is processed by Internet
Explorer 7.
|
| CVE-2009-0393 |
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola
Wimax modem CPEi300 allows remote authenticated users to inject
arbitrary web script or HTML via the page parameter.
|
| CVE-2009-0378 |
Cross-site scripting (XSS) vulnerability in index.php in the
beamospetition (com_beamospetition) 1.0.12 component for Joomla!
allows remote attackers to inject arbitrary web script or HTML via the
pet parameter in a sign action.
|
| CVE-2009-0359 |
Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before
0.6.2 allow remote authenticated users to inject arbitrary web script
or HTML via the (1) message title or (2) user full name.
|
| CVE-2009-0354 |
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x
before 3.0.6 allows remote attackers to bypass the Same Origin Policy,
and access the properties of an arbitrary window and conduct
cross-site scripting (XSS) attacks, via vectors involving a chrome XBL
method and the window.eval function.
|
| CVE-2009-0339 |
SQL injection vulnerability in inc_webblogmanager.asp in DMXReady Blog
Manager allows remote attackers to execute arbitrary SQL commands via
the itemID parameter in a view action.
|
| CVE-2009-0338 |
Cross-site scripting (XSS) vulnerability in inc_webblogmanager.asp in
DMXReady Blog Manager allows remote attackers to inject arbitrary web
script or HTML via the CategoryID parameter in a refer action.
|
| CVE-2009-0335 |
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton
BlogIt! allows remote attackers to inject arbitrary web script or HTML
via the view parameter.
|
| CVE-2009-0312 |
Cross-site scripting (XSS) vulnerability in the antispam feature
(security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote
attackers to inject arbitrary web script or HTML via crafted,
disallowed content.
|
| CVE-2009-0307 |
Cross-site scripting (XSS) vulnerability in the "Customize Statistics
Page" (admin/statistics/ConfigureStatistics) in the MDS Connection
Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES)
before 4.1.6 MR5 allows remote attackers to inject arbitrary web
script or HTML via the (1) customDate, (2) interval, (3)
lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval,
(6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9)
addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.
|
| CVE-2009-0303 |
Cross-site scripting (XSS) vulnerability in Web Help Desk before
9.1.18 allows remote attackers to inject arbitrary web script or HTML
via vectors related to "encoded JavaScript" and Helpdesk.woa.
|
| CVE-2009-0285 |
Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13
and earlier allows remote attackers to inject arbitrary web script or
HTML via the message parameter.
|
| CVE-2009-0283 |
Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows
remote attackers to inject arbitrary web script or HTML via the
message parameter.
|
| CVE-2009-0273 |
Multiple cross-site scripting (XSS) vulnerabilities in Novell
GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) User.id and (2) Library.queryText parameters to gw/webacc, and
other vectors involving (3) HTML e-mail and (4) HTML attachments.
|
| CVE-2009-0260 |
Multiple cross-site scripting (XSS) vulnerabilities in
action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers
to inject arbitrary web script or HTML via an AttachFile action to the
WikiSandBox component with (1) the rename parameter or (2) the drawing
parameter (aka the basename variable).
|
| CVE-2009-0257 |
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0
through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow
remote attackers to inject arbitrary web script or HTML via the (1)
name and (2) content of indexed files to the (a) Indexed Search Engine
(indexed_search) system extension; (b) unspecified test scripts in the
ADOdb system extension; and (c) unspecified vectors in the Workspace
module.
|
| CVE-2009-0248 |
Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton
RankEm allows remote attackers to inject arbitrary web script or HTML
via the siteID parameter.
|
| CVE-2009-0247 |
The server for 53KF Web IM 2009 Home, Professional, and Enterprise
editions relies on client-side protection mechanisms against
cross-site scripting (XSS), which allows remote attackers to conduct
XSS attacks by using a modified client to send a crafted IM message,
related to the msg variable.
|
| CVE-2009-0245 |
Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS
1.2.0.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, a different issue than
CVE-2008-4629.
|
| CVE-2009-0239 |
Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows
user-assisted remote attackers to inject arbitrary web script or HTML
via a crafted file that appears in a preview in a search result, aka
"Script Execution in Windows Search Vulnerability."
|
| CVE-2009-0237 |
Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML
forms authentication component in Microsoft Forefront Threat
Management Gateway, Medium Business Edition (TMG MBE); and Internet
Security and Acceleration (ISA) Server 2006, 2006 Supportability
Update, and 2006 SP1; allows remote attackers to inject arbitrary web
script or HTML via "authentication input" to this component, aka
"Cross-Site Scripting Vulnerability."
|
| CVE-2009-0204 |
Cross-site scripting (XSS) vulnerability in HP Select Access 6.1 and
6.2 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-0162 |
Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4
Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows
remote attackers to inject arbitrary web script or HTML via a crafted
feed: URL.
|
| CVE-2009-0153 |
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x
versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0
through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9
and 10, and possibly other operating systems, does not properly handle
invalid byte sequences during Unicode conversion, which might allow
remote attackers to conduct cross-site scripting (XSS) attacks.
|
| CVE-2009-0107 |
Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions
(aka PHPAuctionSystem) allows remote attackers to inject arbitrary web
script or HTML via the user_id parameter.
|
| CVE-2009-0105 |
Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2
allows remote attackers to inject arbitrary web script or HTML via the
mdfd parameter in a prog action.
|
| CVE-2009-0063 |
Cross-site scripting (XSS) vulnerability in the Control Center in
Symantec Brightmail Gateway Appliance before 8.0.1 allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-0038 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
administration console in Apache Geronimo Application Server 2.1
through 2.1.3 allow remote attackers to inject arbitrary web script or
HTML via the (1) name, (2) ip, (3) username, or (4) description
parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to
the default URI under console/portal/.
|
| CVE-2009-0026 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache
Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web
script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
|
| CVE-2008-7275 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket
Request System (OTRS) before 2.3.3 allow remote attackers to inject
arbitrary web script or HTML via vectors related to (1)
AgentTicketMailbox or (2) CustomerTicketOverView.
|
| CVE-2008-7271 |
Multiple cross-site scripting (XSS) vulnerabilities in the Help
Contents web application (aka the Help Server) in Eclipse IDE,
possibly 3.3.2, allow remote attackers to inject arbitrary web script
or HTML via (1) the searchWord parameter to
help/advanced/searchView.jsp or (2) the workingSet parameter in an add
action to help/advanced/workingSetManager.jsp, a different issue than
CVE-2010-4647.
|
| CVE-2008-7266 |
Cross-site scripting (XSS) vulnerability in an unspecified Shockwave
Flash file in RSA Adaptive Authentication 2.x and 5.7.x allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-7250 |
Cross-site scripting (XSS) vulnerability in Squid Analysis Report
Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web
script or HTML via a JavaScript onload event in the User-Agent header,
which is not properly handled when displaying the Squid proxy log.
NOTE: this issue exists because of an incomplete fix for
CVE-2008-1168.
|
| CVE-2008-7242 |
Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS
0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web
script or HTML via the (1) search, (2) "a," (3) messagesubject, and
(4) messagebody parameters to certain pages as reachable from
manager/index.php; (5) highlight, (6) id, (7) email, (8) name, and (9)
parent parameters to index.php; and the (10) docgrp and (11)
moreResultsPage parameters to index-ajax.php.
|
| CVE-2008-7231 |
Cross-site scripting (XSS) vulnerability in Meridio Document and
Records Management before 4.3 SR1 allows remote authenticated users to
inject arbitrary web script or HTML via the Title field in a (1)
document (subGeneralProps:dmpvDocTitle:PROP_W_title) or (2) container
(subGeneralProps:dmpvContainerTitle:PROP_W_title).
|
| CVE-2008-7223 |
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before
1.3.3 allow remote attackers to inject arbitrary web script or HTML
via (1) ftp/index.php, (2) viewer.php, (3) functions/other.php, (4)
include/left_menu.class.php, or (5) plugins/stats/stats_view.php.
|
| CVE-2008-7222 |
Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS
1.6.1 allows remote attackers to inject arbitrary web script or HTML
via the rank_title parameter in a RankForumAdd action.
|
| CVE-2008-7221 |
Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows
remote attackers to hijack the authentication of administrators for
requests that (1) add new administrators or (2) modify user profiles
via a crafted request to system/admin.php.
|
| CVE-2008-7215 |
The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and
earlier, allows remote attackers to rename arbitrary files and cause a
denial of service via modified file[NewFile][name],
file[NewFile][tmp_name], and file[NewFile][size] parameters in a
FileUpload command, which are used to modify equivalent variables in
$_FILES that are accessed when the is_uploaded_file check fails.
|
| CVE-2008-7214 |
Cross-site request forgery (CSRF) vulnerability in
administrator/index2.php in MOStlyCE before 2.4, as used in Mambo
4.6.3 and earlier, allows remote attackers to hijack the
authentication of administrators for requests that add new
administrator accounts via the save task in a com_users action, as
demonstrated using a separate XSS vulnerability in
mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php.
|
| CVE-2008-7213 |
Cross-site scripting (XSS) vulnerability in
mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php
in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows
remote attackers to inject arbitrary web script or HTML via the
Command parameter.
|
| CVE-2008-7212 |
MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote
attackers to obtain sensitive information via certain requests to
mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php,
which reveals the installation path in an error message.
|
| CVE-2008-7206 |
Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2
has unknown impact and attack vectors when the "logbook contains HTML
code," probably cross-site scripting (XSS).
|
| CVE-2008-7202 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenWebMail
before 2.53 (Stable) allow remote attackers to inject arbitrary web
script or HTML via unknown vectors.
|
| CVE-2008-7190 |
Unspecified vulnerability in Adium before 1.2 has unknown impact and
attack vectors related to javascript: URLs, possibly cross-site
scripting (XSS).
|
| CVE-2008-7184 |
Cross-site scripting (XSS) vulnerability in Diigo Toolbar and Diigolet
allows remote attackers to inject arbitrary web script or HTML via a
public comment.
|
| CVE-2008-7175 |
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in
NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote
attackers to inject arbitrary web script or HTML via the picture
description field in a page edit action.
|
| CVE-2008-7171 |
Multiple cross-site scripting (XSS) vulnerabilities in Lightweight
news portal (LNP) 1.0b allow remote attackers to inject arbitrary web
script or HTML via the (1) photo parameter to show_photo.php, (2) potd
parameter to show_potd.php, or (3) the Current question field in a
vote action to admin.php.
|
| CVE-2008-7150 |
Cross-site scripting (XSS) vulnerability in Refine by Taxonomy 5.x
before 5.x-0.1, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via a taxonomy term, which is not
properly handled by refine_by_taxo when displaying tags.
|
| CVE-2008-7147 |
Multiple cross-site scripting (XSS) vulnerabilities in IntraLearn
Software IntraLearn 2.1, and possibly other versions before 4.2.3,
allow remote attackers to inject arbitrary web script or HTML via the
(1) outline and (2) course parameters to library/description_link.cfm,
or the (3) records_to_display and (4) the_start parameters to
library/courses_catalog.cfm.
|
| CVE-2008-7141 |
Cross-site scripting (XSS) vulnerability in setup.php in @lex Poll 2.1
allows remote attackers to inject arbitrary web script or HTML via the
language_setup parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-7140 |
Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook
4.0.5 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) language_setup parameter to setup.php or
(2) test parameter to index.php. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information. NOTE: a third party has been reported that the test
parameter is not used in @lex Guestbook.
|
| CVE-2008-7134 |
Multiple cross-site scripting (XSS) vulnerabilities in the default URI
in Chris LaPointe RedGalaxy Download Center 1.2 allow remote attackers
to inject arbitrary web script or HTML via the (1) file parameter, (2)
message parameter in a login action, (3) category parameter in a
browse action, (4) now parameter, or (5) search parameter in a
search_results action. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-7133 |
Multiple cross-site scripting (XSS) vulnerabilities in onlinetools.org
EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary
web script or HTML via the (1) search and (2) d index.php parameters
to index.php, (3) dir parameter to thumber.php, and the d parameter to
(4) describe.php and (5) addcomment.php. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-7132 |
Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan
1.3 beta allows remote attackers to inject arbitrary web script or
HTML via the nuked_nude parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-7121 |
Cross-site scripting (XSS) vulnerability in Mr. CGI Guy Hot Links
SQL-PHP 3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the search bar.
|
| CVE-2008-7117 |
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to
modify arbitrary cascading style sheets (CSS) files via a certain
request with the file parameter set to style.css. NOTE: this can
probably be leveraged for cross-site scripting (XSS) attacks.
|
| CVE-2008-7108 |
Multiple cross-site scripting (XSS) vulnerabilities in Carmosa phpCart
3.4 through 4.6.4 allow remote attackers to inject arbitrary web
script or HTML via the (1) quantity or (2) Add Engraving fields to the
default URI; (3) Quantity field to phpcart.php; (4) Name, (5) Company,
(6) Address, (7) City, and (8) Province/State fields in a checkout
action to phpcart.php; and other unspecified vectors.
|
| CVE-2008-7098 |
Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate
Premium allow remote attackers to inject arbitrary web script or HTML
via the blog, possibly the (1) Title and (2) Text fields; (3) the
gallery, possibly the Description field in Your Pictures; (4) the
forum, possibly the Your Message field when posting a new thread; or
(5) the vote parameter in a view action to index.php. NOTE: some of
these details are obtained from third party information.
|
| CVE-2008-7092 |
Multiple cross-site scripting (XSS) vulnerabilities in Unica Affinium
Campaign 7.2.1.0.55 allow remote attackers to inject arbitrary web
script or HTML via a Javascript event in the (1) url, (2) PageName,
and (3) title parameters in a CustomBookMarkLink action to
Campaign/Campaign; (4) a Javascript event in the displayIcon parameter
to Campaign/updateOfferTemplateSubmit.do (aka the templates web page);
(5) crafted input to Campaign/CampaignListener (aka the listener
server), which is not properly handled when displaying the status log;
and (6) id parameter to Campaign/campaignDetails.do, (7) id parameter
to Campaign/offerDetails.do, (8) function parameter to
Campaign/Campaign, (9) sessionID parameter to
Campaign/runAllFlowchart.do, (10) id parameter in an edit action to
Campaign/updateOfferTemplatePage.do, (11) Frame parameter in a
LoadFrame action to Campaign/Campaign, (12) affiniumUserName parameter
to manager/jsp/test.jsp, (13) affiniumUserName parameter to
Campaign/main.do, and possibly other vectors.
|
| CVE-2008-7089 |
Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
keyword parameter in a search action to user.php and other unspecified
vectors.
|
| CVE-2008-7072 |
Cross-site scripting (XSS) vulnerability in index.php in Chipmunk
Topsites allows remote attackers to inject arbitrary web script or
HTML via the start parameter.
|
| CVE-2008-7060 |
Multiple cross-site scripting (XSS) vulnerabilities in One-News Beta 2
allow remote attackers to inject arbitrary HTML and web script via the
(1) title or (2) content parameters in a news item to add.php, and the
(3) itemnum, (4) author, or (5) comment parameters in a comment to
index.php. NOTE: vectors 1 and 2 require user authentication.
|
| CVE-2008-7057 |
Cross-site scripting (XSS) vulnerability in merchandise.php in
BandSite CMS 1.1.4 allows remote attackers to inject arbitrary HTML or
web script via the type parameter.
|
| CVE-2008-7048 |
Multiple cross-site scripting (XSS) vulnerabilities in NatterChat 1.12
allow remote attackers to inject arbitrary web script or HTML via the
(1) txtUsername parameter to registerDo.asp, as invoked from
register.asp, or (2) txtRoomName parameter to room_new.asp. NOTE:
these issues might be resultant from XSS in SQL error messages.
|
| CVE-2008-7043 |
Cross-site scripting (XSS) vulnerability in register.php in
FreshScripts Fresh Email Script 1.0 through 1.11 allows remote
attackers to inject arbitrary web script or HTML via the Email
parameter. NOTE: this can be leveraged to modify cookies and conduct
session fixation attacks.
|
| CVE-2008-7039 |
Cross-site scripting (XSS) vulnerability in admin/comments.php in
Gelato CMS 0.95 allows remote attackers to inject arbitrary web script
or HTML via the content parameter in a comment. NOTE: some of these
details are obtained from third party information.
|
| CVE-2008-7036 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker
module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to
inject arbitrary web script or HTML via the (1) direction and (2)
order_by parameters.
|
| CVE-2008-7035 |
Cross-site scripting (XSS) vulnerability in an unspecified component
in Simple Machines phpRaider 1.0.7 allows remote attackers to inject
arbitrary web script or HTML via the resistance field. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-7018 |
Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar
6.3.25 allows remote attackers to inject arbitrary web script or HTML
via the Details field (descr parameter) in an Add New Event action in
an unspecified request as generated by an add action in index.php.
|
| CVE-2008-7017 |
Cross-site scripting (XSS) vulnerability in analyse.php in CAcert
20080921, and possibly other versions before 20080928, allows remote
attackers to inject arbitrary web script or HTML via the CN
(CommonName) field in the subject of an X.509 certificate.
|
| CVE-2008-6989 |
SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka
Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL
commands via the username parameter.
|
| CVE-2008-6988 |
Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo
Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) galleryid parameter to
gallery.php, and the (2) size or (3) imageid parameters to show.php.
|
| CVE-2008-6982 |
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a
allows remote attackers to inject arbitrary web script or HTML via the
currentpath parameter.
|
| CVE-2008-6979 |
Cross-site scripting (XSS) vulnerability in as_archives.php in
phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject
arbitrary web script or HTML via the results_per_page parameter to
index.php. NOTE: some of these details are obtained from third party
information. NOTE: this issue might be resultant from a separate SQL
injection vulnerability.
|
| CVE-2008-6977 |
Cross-site scripting (XSS) vulnerability in album.asp in Full
Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary
web script or HTML via the message parameter in a summary action.
|
| CVE-2008-6972 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content
Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated
users with "administer content" permissions to inject arbitrary web
script or HTML via the (1) "field label," (2) "help text," or (3)
"allowed values" settings.
|
| CVE-2008-6969 |
Multiple cross-site scripting (XSS) vulnerabilities in checkout.php in
Avactis Shopping Cart 1.8.0 and 1.8.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) step_id and (2)
CHECKOUT_CZ_BLOWFISH_KEY parameters.
|
| CVE-2008-6967 |
Multiple unspecified vulnerabilities in WorldClient in Alt-N MDaemon
before 10.02 have unknown impact and attack vectors, probably related
to cross-site scripting (XSS) and WorldClient DLL 10.0.1, a different
vulnerability than CVE-2008-6893.
|
| CVE-2008-6946 |
Cross-site scripting (XSS) vulnerability in manageproject.php in
Collabtive 0.4.8 allows user-assisted remote attackers to inject
arbitrary web script or HTML via the project Name, which is not
properly handled when the administrator performs an editform action,
related to admin.php.
|
| CVE-2008-6945 |
Multiple cross-site scripting (XSS) vulnerabilities in Interchange 5.7
before 5.7.1, 5.6 before 5.6.1, and 5.4 before 5.4.3 allow remote
attackers to inject arbitrary web script or HTML via (1) the
mv_order_item CGI variable parameter in Core, (2) the country-select
widget, or (3) possibly the value specifier when used in the UserTag
feature.
|
| CVE-2008-6927 |
Multiple cross-site scripting (XSS) vulnerabilities in
autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module
for cPanel allow remote attackers to inject arbitrary web script or
HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4)
domain_show, (5) thispage, (6) thisapp, and (7) currentversion
parameters in an Upgrade action.
|
| CVE-2008-6925 |
Cross-site scripting (XSS) vulnerability in function.php in Zenphoto
1.1.7 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors in the "request logging" feature. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-6924 |
Multiple cross-site scripting (XSS) vulnerabilities in register.php in
eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) username, (2) email, (3) password, (4)
password2, (5) security_code, and (6) register parameters.
|
| CVE-2008-6915 |
Cross-site scripting (XSS) vulnerability in view_prop_details.php in
Zeeways ZEEPROPERTY 1.0 allows remote attackers to inject arbitrary
web script or HTML via the propid parameter.
|
| CVE-2008-6906 |
Cross-site scripting (XSS) vulnerability in index.php in BabbleBoard
1.1.6 allows remote attackers to inject arbitrary web script or HTML
via the username.
|
| CVE-2008-6894 |
Multiple cross-site scripting (XSS) vulnerabilities in login.php in
3CX Phone System Free Edition 6.1793 and 6.0.806.0 allow remote
attackers to inject arbitrary web script or HTML via the (1) fName and
(2) fPassword parameters.
|
| CVE-2008-6893 |
Cross-site scripting (XSS) vulnerability in Alt-N MDaemon WorldClient
10.0.2, when Internet Explorer 7 is used, allows remote attackers to
inject arbitrary web script or HTML via a crafted img tag.
|
| CVE-2008-6891 |
Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum
Script allow remote attackers to inject arbitrary web script or HTML
via the (1) forum_id parameter to (a) new_message.asp and (b)
messages.asp, and the (2) query string to default.asp.
|
| CVE-2008-6888 |
Cross-site scripting (XSS) vulnerability in signup.asp in Pre
Classified Listings 1.0 allows remote attackers to inject arbitrary
web script or HTML via the address parameter.
|
| CVE-2008-6885 |
Cross-site scripting (XSS) vulnerability in pmlite.php in XOOPS 2.3.1
and 2.3.2a allows remote attackers to inject arbitrary web script or
HTML via a STYLE attribute in a URL BBcode tag in a private message.
|
| CVE-2008-6879 |
Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0,
3.1, and 4.0 allows remote attackers to inject arbitrary web script or
HTML via the q parameter in a search action.
|
| CVE-2008-6876 |
Cross-site scripting (XSS) vulnerability in login.php in EsPartenaires
1.0 allows remote attackers to inject arbitrary web script or HTML via
the msg parameter. NOTE: the EsContacts 1.0 issue is covered in
CVE-2008-2037.
|
| CVE-2008-6868 |
Cross-site scripting (XSS) vulnerability in default/login.php in
EditeurScripts EsBaseAdmin 2.1 allows remote attackers to inject
arbitrary web script or HTML via the msg parameter. NOTE: the
EsContacts 1.0 issue is covered in CVE-2008-2037.
|
| CVE-2008-6850 |
Cross-site scripting (XSS) vulnerability in messages.php in PHP-Fusion
6.01.17 and 7.00.3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-6848 |
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards
3.7 allows remote attackers to inject arbitrary web script or HTML via
the category parameter in a select action.
|
| CVE-2008-6847 |
Cross-site scripting (XSS) vulnerability in Employee/emp_login.asp in
Pre ASP Job Board allows remote attackers to inject arbitrary web
script or HTML via the msg parameter.
|
| CVE-2008-6839 |
Multiple cross-site scripting (XSS) vulnerabilities in TGS Content
Management 0.3.2r2 allow remote attackers to inject arbitrary web
script or HTML via the (1) msg and (2) goodmsg parameters to (a)
login.php and (b) index.php, and the (3) dir and (4) id parameters to
index.php. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-6838 |
Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1
allows remote attackers to inject arbitrary web script or HTML via the
_off parameter. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2008-6835 |
Cross-site scripting (XSS) vulnerability in OpenID 5.x before 5.x-1.2,
a module for Drupal, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-6831 |
Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA
Enterprise Edition 3.13 allow remote attackers to inject arbitrary web
script or HTML via the (1) fullname (Full Name) parameter in the
ViewProfile page or (2) returnUrl parameter in a form, as demonstrated
using secure/AddComment!default.jspa (aka "Add Comment").
|
| CVE-2008-6767 |
wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote
attackers to upgrade the application, and possibly cause a denial of
service (application outage), via a direct request.
|
| CVE-2008-6764 |
Cross-site scripting (XSS) vulnerability in login.php in Silentum
LoginSys 1.0.0 allows remote attackers to inject arbitrary web script
or HTML via the message parameter.
|
| CVE-2008-6762 |
Open redirect vulnerability in wp-admin/upgrade.php in WordPress,
probably 2.6.x, allows remote attackers to redirect users to arbitrary
web sites and conduct phishing attacks via a URL in the backto
parameter.
|
| CVE-2008-6758 |
Cross-site request forgery (CSRF) vulnerability in cart_save.php in
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack
the authentication of arbitrary users for requests that conduct
persistent cross-site scripting (XSS) attacks via the cart_name
parameter in a save action.
|
| CVE-2008-6757 |
Cross-site scripting (XSS) vulnerability in manuals_search.php in
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject
arbitrary web script or HTML via the manuals_search parameter.
|
| CVE-2008-6746 |
Cross-site scripting (XSS) vulnerability in the contact display view
in Turba Contact Manager H3 before 2.2.1 allows remote attackers to
inject arbitrary web script or HTML via the contact name.
|
| CVE-2008-6733 |
Cross-site scripting (XSS) vulnerability in the error handling page in
DotNetNuke 4.6.2 through 4.8.3 allows remote attackers to inject
arbitrary web script or HTML via the querystring parameter.
|
| CVE-2008-6732 |
Cross-site scripting (XSS) vulnerability in the Language skin object
in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary
web script or HTML via "newly generated paths."
|
| CVE-2008-6727 |
Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB)
2.2.2, 2.2.1, and earlier 2.x versions allows remote attackers to
inject arbitrary web script or HTML via the User-Agent HTTP header.
|
| CVE-2008-6724 |
Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste
1.0 allows remote attackers to inject arbitrary web script or HTML via
the language parameter. NOTE: some of these details are obtained from
third party information.
|
| CVE-2008-6715 |
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal
2.0 and earlier allow remote attackers to inject arbitrary web script
or HTML via the msg parameter to (1) homeadmin/adminhome.php and (2)
homeadmin/signinform.php.
|
| CVE-2008-6700 |
Multiple cross-site scripting (XSS) vulnerabilities in Butterfly
Organizer 2.0.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) mytable parameter to view.php, (2) mytable
parameter to viewdb2.php, (3) tablehere parameter to
category-rename.php, and (4) letter parameter to module-contacts.php.
|
| CVE-2008-6699 |
Cross-site scripting (XSS) vulnerability in Resource Library
(tjs_reslib) 0.1.0 and earlier extension for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-6698 |
Cross-site scripting (XSS) vulnerability in TARGET-E WorldCup Bets
(worldcup) 2.0.0 and earlier extension for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-6688 |
Cross-site scripting (XSS) vulnerability in JobControl (dmmjobcontrol)
1.15.0 and earlier extension for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-6687 |
Cross-site scripting (XSS) vulnerability in DCD GoogleMap
(dcdgooglemap) 1.1.0 and earlier extension for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-6683 |
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment
Search Script allows remote attackers to inject arbitrary web script
or HTML via the r parameter.
|
| CVE-2008-6682 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts
2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to
inject arbitrary web script or HTML via vectors associated with
improper handling of (1) " (double quote) characters in the href
attribute of an s:a tag and (2) parameters in the action attribute of
an s:url tag.
|
| CVE-2008-6681 |
Cross-site scripting (XSS) vulnerability in dijit.Editor in Dojo
before 1.1 allows remote attackers to inject arbitrary web script or
HTML via XML entities in a TEXTAREA element.
|
| CVE-2008-6675 |
Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite
1.8.5 allow remote attackers to inject arbitrary web script or HTML
via (1) the close parameter to showThumb.aspx; (2) SB_redirect and (3)
SB_feedback parameters in process_send.asp, as reachable through
default.asp; (4) paramCode and (5) cColor parameters to picker.asp;
and the (6) query string, (7) Referer header, and (8) X-FORWARDED-FOR
header to rss.asp.
|
| CVE-2008-6666 |
Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA
allow remote attackers to inject arbitrary web script or HTML via the
description field to (1) servlet/com.threeis.webta.H710selProject and
(2) servlet/com.threeis.webta.H720editProjectInfo. NOTE: BID:29610
states that the initial report was incorrect, but the reason for this
conclusion is unknown.
|
| CVE-2008-6655 |
Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL
2 allow remote attackers to inject arbitrary web script or HTML via
the (1) nom_branche and (2) nom parameters to php/prenom.php; the (3)
nom_branche parameter to php/index.php; and the (4) nom_branche, (5)
nom, and (6) prenom parameters to php/info.php.
|
| CVE-2008-6654 |
Cross-site scripting (XSS) vulnerability in search_results.php in
InfoBiz Server allows remote attackers to inject arbitrary web script
or HTML via the keywords parameter.
|
| CVE-2008-6646 |
Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix
phpAddressBook 2.0 allows remote attackers to inject arbitrary web
script or HTML via the username parameter.
|
| CVE-2008-6645 |
Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel
0.7 allows remote attackers to inject arbitrary web script or HTML via
the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not
properly handled when displaying log files.
|
| CVE-2008-6644 |
Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke
4.8.3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO.
|
| CVE-2008-6637 |
Multiple cross-site scripting (XSS) vulnerabilities in forgotPW.php in
Library Video Company SAFARI Montage 3.1.x allow remote attackers to
inject arbitrary web script or HTML via the (1) school and (2) email
parameters.
|
| CVE-2008-6631 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
BlogPHP 2.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) user parameter in a sendmessage action and the (2)
username parameter when registering a new user, different vectors than
CVE-2008-0679.
|
| CVE-2008-6629 |
Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN
Multi Languages WebShop Online 1.02 allows remote attackers to inject
arbitrary web script or HTML via the name parameter.
|
| CVE-2008-6620 |
Multiple cross-site scripting (XSS) vulnerabilities in
javascript/editor/editor/filemanager/browser/mcpuk/connectors/php/connector.php
in GraFX miniCWB 2.1.1 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) errcontext, (2) _GET, (3)
_POST, (4) _SESSION, (5) _SERVER, and (6) fckphp_config[Debug_SERVER]
parameters.
|
| CVE-2008-6616 |
Cross-site scripting (XSS) vulnerability in index.php in Zen Software
Zen Cart 2008 allows remote attackers to inject arbitrary web script
or HTML via the keyword parameter in the advanced_search_result page.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-6609 |
Cross-site scripting (XSS) vulnerability in phpcksec.php in Stefan Ott
phpcksec 0.2 allows remote attackers to inject arbitrary web script or
HTML via the path parameter.
|
| CVE-2008-6607 |
Cross-site scripting (XSS) vulnerability in view.php in MatPo Link 1.2
Beta allows remote attackers to inject arbitrary web script or HTML
via the thema parameter.
|
| CVE-2008-6600 |
Cross-site scripting (XSS) vulnerability in the search feature in
XMLPortal 3.0 allows remote attackers to inject arbitrary web script
or HTML via the query parameter.
|
| CVE-2008-6597 |
Cross-site scripting (XSS) vulnerability in upload/install/index.php
in PHCDownload 1.1 allows remote attackers to inject arbitrary web
script or HTML via the step parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-6589 |
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no
database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2,
allow remote attackers to inject arbitrary web script or HTML via the
page parameter to (1) index.php and (2) LightNEasy.php.
|
| CVE-2008-6571 |
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before
1.3.4 might allow remote attackers to inject arbitrary web script or
HTML via (1) new_images.php, (2) login.php, and unspecified vectors.
|
| CVE-2008-6570 |
Cross-site scripting (XSS) vulnerability in the RSS reader in Cybozu
Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary
web script or HTML via a crafted RSS feed.
|
| CVE-2008-6567 |
Multiple cross-site scripting (XSS) vulnerabilities in Gallarific Free
Edition allow remote attackers to inject arbitrary web script or HTML
via (1) the e-mail address, (2) a comment, which is not properly
handled during moderation, and (3) the tag parameter to
gallery/tags.php.
|
| CVE-2008-6565 |
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1
and earlier allows remote attackers to inject arbitrary web script or
HTML via an IFRAME tag in the signature.
|
| CVE-2008-6562 |
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack
(tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary
web script or HTML via the cat parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-6550 |
Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire
2.0 allows remote attackers to inject arbitrary web script or HTML via
the letter parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-6533 |
Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related
content when an input format is deleted, which prevents the content
from being properly filtered and allows remote attackers to conduct
cross-site scripting (XSS) attacks via unspecified vectors.
|
| CVE-2008-6529 |
Cross-site scripting (XSS) vulnerability in listtest.php in
eZoneScripts Living Local 1.1 allows remote attackers to inject
arbitrary web script or HTML via the r parameter.
|
| CVE-2008-6515 |
Cross-site scripting (XSS) vulnerability in Fritz Berger yet another
php photo album - next generation (yappa-ng) allows remote attackers
to inject arbitrary web script or HTML via the query string to the
default URI.
|
| CVE-2008-6510 |
Cross-site scripting (XSS) vulnerability in login.jsp in the Admin
Console in Openfire 3.6.0a and earlier allows remote attackers to
inject arbitrary web script or HTML via the url parameter.
|
| CVE-2008-6503 |
Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop
1.1.0.3 allow remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to (1) admin/login.php and (2) order.php.
|
| CVE-2008-6502 |
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows
remote authenticated users to select an arbitrary local PHP script as
an avatar via a .. (dot dot) in the avatar parameter, and cause other
users to execute this script by using sendData.php to send a message
to (1) an individual user or (2) a room, leading to cross-site request
forgery (CSRF), cross-site scripting (XSS), or other impacts.
|
| CVE-2008-6501 |
Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro
Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web
script or HTML via the gud parameter.
|
| CVE-2008-6500 |
Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart
Script allows remote attackers to inject arbitrary web script or HTML
via the query string to the default URI.
|
| CVE-2008-6495 |
Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger
yet another php photo album - next generation (yappa-ng) 2.3.2 allows
remote attackers to inject arbitrary web script or HTML via the album
parameter.
|
| CVE-2008-6476 |
Cross-site scripting (XSS) vulnerability in blog/search.aspx in
BlogEngine.NET allows remote attackers to inject arbitrary web script
or HTML via the q parameter.
|
| CVE-2008-6465 |
Multiple cross-site scripting (XSS) vulnerabilities in login.php in
webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remote
attackers to inject arbitrary web script or HTML via the (1) err, (2)
errorcode, and (3) login parameters.
|
| CVE-2008-6450 |
Cross-site scripting (XSS) vulnerability in Under Construction, Baby
(UCB) PC2M 0.9.22.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-6448 |
Cross-site scripting (XSS) vulnerability in install.cgi in SKYARC
System MTCMS WYSIWYG Editor allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-6439 |
Cross-site scripting (XSS) vulnerability in search_results.php in
ABK-Soft AbleDating 2.4 allows remote attackers to inject arbitrary
web script or HTML via the keyword parameter.
|
| CVE-2008-6437 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum
1.0 RC2 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) message parameter to error.php, and the (2)
nickname and (3) randomid parameters to part/menu.php.
|
| CVE-2008-6436 |
Cross-site scripting (XSS) vulnerability in the Web Server in Xerox
WorkCentre 7132, 7228, 7235, and 7245 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-6435 |
Multiple cross-site scripting (XSS) vulnerabilities in phpSQLiteCMS 1
RC2 allow remote attackers to inject arbitrary web script or HTML via
the (1) lang[home], (2) lang[admin_menu], and (3)
lang[admin_menu_page_overview] parameters to
cms/includes/header.inc.php; and the (4) lang[login_username] and (5)
lang[login_password] parameters to cms/includes/login.inc.php.
|
| CVE-2008-6433 |
Cross-site scripting (XSS) vulnerability in index.cfm in Blue River
Interactive Group Sava CMS before 5.0.122 allows remote attackers to
inject arbitrary web script or HTML via the keywords parameter in a
search action.
|
| CVE-2008-6431 |
Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6
allow remote attackers to inject arbitrary web script or HTML via the
(1) outpused parameter to index.php, the (2) footer_copyright and (3)
verandproname parameters to newtem/footer/bsd01footer.php, and the (4)
topads and (5) myplugin parameters to newtem/header/bsd01header.php.
|
| CVE-2008-6428 |
The CGI framework in Kaya 0.4.0 allows remote attackers to inject
arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks
via unspecified vectors.
|
| CVE-2008-6416 |
Multiple cross-site scripting (XSS) vulnerabilities in
GreenSQL-Console before 0.3.5 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors related to
"internal pages."
|
| CVE-2008-6413 |
Cross-site scripting (XSS) vulnerability in the Answers module
5.x-1.x-dev and possibly other 5.x versions, a module for Drupal,
allows remote attackers to inject arbitrary web script or HTML via a
Simple Answer to a question.
|
| CVE-2008-6406 |
Cross-site scripting (XSS) vulnerability in admin.php in DataLife
Engine (DLE) 7.2 allows remote attackers to inject arbitrary web
script or HTML via the query string.
|
| CVE-2008-6404 |
Cross-site scripting (XSS) vulnerability in add_calendars.php in
eXtrovert Software Thyme 1.3 allows remote attackers to inject
arbitrary web script or HTML via the callback parameter.
|
| CVE-2008-6400 |
Cross-site scripting (XSS) vulnerability in refbase before 0.9.5
allows remote attackers to inject arbitrary web script or HTML via the
headerMsg parameter to (1) show.php and (2) search.php. NOTE: some of
these details are obtained from third party information.
|
| CVE-2008-6396 |
Cross-site scripting (XSS) vulnerability in account.php in Celerondude
Uploader 6.1 allows remote attackers to inject arbitrary web script or
HTML via the username parameter. NOTE: some of these details are
obtained from third party information.
|
| CVE-2008-6386 |
Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange
1.0 allows remote attackers to inject arbitrary web script or HTML via
the id parameter.
|
| CVE-2008-6385 |
Cross-site scripting (XSS) vulnerability in index.php in W3matter
RevSense 1.0 allows remote attackers to inject arbitrary web script or
HTML via the section parameter.
|
| CVE-2008-6370 |
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12
Contact Manager Pro 1.02 allows remote attackers to inject arbitrary
web script or HTML via the DisplayFormat parameter.
|
| CVE-2008-6360 |
Cross-site scripting (XSS) vulnerability in the userranks feature in
modules/system/admin.php in ImpressCMS 1.0.2 final allows remote
attackers to inject arbitrary web script or HTML via the rank_title
parameter. NOTE: some of these details are obtained from third party
information.
|
| CVE-2008-6359 |
Cross-site scripting (XSS) vulnerability in index.php in Max's
Guestbook allows remote attackers to inject arbitrary web script or
HTML via the (1) name, (2) email, and (3) message parameters.
|
| CVE-2008-6351 |
Cross-site scripting (XSS) vulnerability in listtest.php in
TurnkeyForms Local Classifieds allows remote attackers to inject
arbitrary web script or HTML via the r parameter.
|
| CVE-2008-6346 |
Cross-site scripting (XSS) vulnerability in the DR Wiki (dr_wiki)
extension 1.7.1 and earlier for TYPO3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-6343 |
Cross-site scripting (XSS) vulnerability in the TU-Clausthal ODIN
(tuc_odin) extension 0.0.1, 0.1.0, 0.1.1, and 0.2.0 for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-6341 |
Cross-site scripting (XSS) vulnerability in the SB Universal Plugin
(SBuniplug) extension 2.0.1 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-6340 |
Cross-site scripting (XSS) vulnerability in the Vox populi
(mv_vox_populi) extension 0.3.0 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-6325 |
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz
Classifieds Script allow remote attackers to inject arbitrary web
script or HTML via the (1) radio parameter to showcategory.php, (2)
msg parameter to advertisers/signinform.php, (3) radio parameter to
gallery.php, (4) msg parameter to lostpassword.php, (5) radio
parameter to showcategory.php, (6) msg parameter to
admin/adminhome.php, and (7) msg parameter to admin/index.php. NOTE:
a different signinform.php file is already covered by CVE-2008-6306.
|
| CVE-2008-6306 |
Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz
Classifieds Script allows remote attackers to inject arbitrary web
script or HTML via the msg parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-6299 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7
and earlier allow remote authenticated users with certain privileges
to inject arbitrary web script or HTML via (1) the title and
description parameters to the com_weblinks module and (2) unspecified
vectors in the com_content module related to "article submission."
|
| CVE-2008-6297 |
Cross-site scripting (XSS) vulnerability in order.php in DHCart allows
remote attackers to inject arbitrary web script or HTML via the (1)
domain and (2) d1 parameters.
|
| CVE-2008-6295 |
Multiple cross-site scripting (XSS) vulnerabilities in Camera Life
2.6.2b8 allow remote attackers to inject arbitrary web script or HTML
via the q parameter to (1) search.php and (2) rss.php; the query
string after the image name in (3) photos/photo; the path parameter to
(4) folder.php; page parameter and REQUEST_URI to (5) login.php; ver
parameter to (6) media.php; theme parameter to (7)
modules/iconset/iconset-debug.php; and the REQUEST_URI to (8)
index.php.
|
| CVE-2008-6283 |
Cross-site scripting (XSS) vulnerability in Subtext 2.0 allows remote
attackers to inject arbitrary web script or HTML via a comment,
related to "the feature which converts URLs to anchor tags."
|
| CVE-2008-6280 |
Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys
WRT160N allows remote attackers to inject arbitrary web script or HTML
via the action parameter in a DHCP_Static operation.
|
| CVE-2008-6278 |
Multiple cross-site scripting (XSS) vulnerabilities in product.php in
RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote
attackers to inject arbitrary web script or HTML via the (1)
category_id and (2) subcategory_id parameters.
|
| CVE-2008-6275 |
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x
before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal,
allows remote attackers to inject arbitrary web script or HTML via
unspecified messages.
|
| CVE-2008-6267 |
Cross-site scripting (XSS) vulnerability in detail.php in Multi
Languages WebShop Online 1.02 allows remote attackers to inject
arbitrary web script or HTML via the name parameter.
|
| CVE-2008-6259 |
Cross-site scripting (XSS) vulnerability in search.asp in QuadComm
Q-Shop 3.0, and possibly earlier, allows remote attackers to inject
arbitrary web script or HTML via the srkeys parameter.
|
| CVE-2008-6248 |
Cross-site scripting (XSS) vulnerability in all.php in Galatolo
WebManager 1.3a and earlier allows remote attackers to inject
arbitrary web script or HTML via the tag parameter.
|
| CVE-2008-6240 |
Cross-site scripting (XSS) vulnerability in data/views/index.html in
OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote
attackers to inject arbitrary web script or HTML via the catalogid
parameter.
|
| CVE-2008-6238 |
Cross-site scripting (XSS) vulnerability in
archive/savedqueries/savequeryfinish.html in OpenEdit Digital Asset
Management (DAM) before 5.2014 allows remote attackers to inject
arbitrary web script or HTML via the name parameter.
|
| CVE-2008-6229 |
Cross-site scripting (XSS) vulnerability in the administrative
interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10
and 6.x before 6.x-2.0, a module for Drupal, allows remote
authenticated users with "administer content" permissions to inject
arbitrary web script or HTML via (1) field labels and (2) content-type
names.
|
| CVE-2008-6217 |
Cross-site scripting (XSS) vulnerability in index.php in Extrakt
Framework 0.7 allows remote attackers to inject arbitrary web script
or HTML via the plugins[file][id] parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-6215 |
Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in
Venalsur Booking Centre Booking System for Hotels Group allows remote
attackers to inject arbitrary web script or HTML via the OfertaID
parameter.
|
| CVE-2008-6212 |
Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats
0.1.9.1 allows remote attackers to inject arbitrary web script or HTML
via the (1) sel_mese and (2) sel_anno parameters in a systems action.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-6211 |
Multiple cross-site scripting (XSS) vulnerabilities in PhpForums.net
mcGallery 1.1 allow remote attackers to inject arbitrary web script or
HTML via the lang parameter to (1) admin.php, (2) index.php, (3)
sess.php, (4) stats.php, (5) detail.php, (6) resize.php, and (7)
show.php. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-6208 |
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 CMS
0.7.11 allows remote attackers to inject arbitrary web script or HTML
via the (1) author_name, (2) itemtitle, and (3) item parameters. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-6205 |
Cross-site scripting (XSS) vulnerability in seeurl.php in Xavier
Flahaut URLStreet 1.0 allows remote attackers to inject arbitrary web
script or HTML via the (1) language, (2) order, and (3) filter
parameters. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-6200 |
Multiple cross-site scripting (XSS) vulnerabilities in Swiki 1.5 allow
remote attackers to inject arbitrary web script or HTML via (1) the
query string and (2) a new wiki entry.
|
| CVE-2008-6192 |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified
Portlets in Sun Java System Portal Server 7.0 and 7.1 allow remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-6190 |
Cross-site scripting (XSS) vulnerability in index.php in EEBCMS 0.95
allows remote attackers to inject arbitrary web script or HTML via the
content parameter.
|
| CVE-2008-6174 |
Cross-site scripting (XSS) vulnerability in admin/postlister/index.php
in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web
script or HTML via the liste parameter.
|
| CVE-2008-6173 |
Cross-site scripting (XSS) vulnerability in fullscreen.php in
ClipShare Pro 4.0 allows remote attackers to inject arbitrary web
script or HTML via the title parameter.
|
| CVE-2008-6170 |
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and
6.x before 6.6 allows remote authenticated users with create book
content or edit node book hierarchy permissions to inject arbitrary
web script or HTML via the book page title.
|
| CVE-2008-6168 |
Cross-site scripting (XSS) vulnerability in search.php in miniPortail
2.2 and earlier allows remote attackers to inject arbitrary web script
or HTML via an unspecified argument, probably the search string.
|
| CVE-2008-6164 |
Cross-site scripting (XSS) vulnerability in index.php in DreamCost
HostAdmin 3.1.1 allows remote attackers to inject arbitrary web script
or HTML via the page parameter.
|
| CVE-2008-6161 |
Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM)
before 3.5.1 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2008-6144 |
Multiple cross-site scripting (XSS) vulnerabilities in the WEC
Discussion Forum (wec_discussion) extension 1.7.0 and earlier for
TYPO3 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors, a different issue than CVE-2008-3029.
|
| CVE-2008-6135 |
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a
module for Drupal, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-6131 |
Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows
remote attackers to hijack web sessions by setting the PHPSESSID
parameter.
|
| CVE-2008-6130 |
Cross-site scripting (XSS) vulnerability in index.php in moziloWiki
1.0.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via the (1) action and (2) page parameters.
|
| CVE-2008-6129 |
Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and
earlier allows remote attackers to read arbitrary files via a .. (dot
dot) in the page parameter.
|
| CVE-2008-6127 |
Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS
1.10.2 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) page and (2) query parameters to (a)
index.php, (3) cat and (4) file parameters to (b) download.php, (5)
gal parameter to gallery.php, and the (6) URL to admin/login.php.
|
| CVE-2008-6113 |
Cross-site scripting (XSS) vulnerability in SemanticScuttle before
0.90 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, related to the (1) username and (2) profile
page.
|
| CVE-2008-6108 |
Cross-site scripting (XSS) vulnerability in result.php in Galatolo
WebManager (GWM) 1.0 allows remote attackers to inject arbitrary web
script or HTML via the key parameter.
|
| CVE-2008-6105 |
Cross-site scripting (XSS) vulnerability in IBM Workplace for Business
Controls and Reporting 2.x and IBM Workplace Web Content Management
6.x allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: some of these details are obtained from
third party information.
|
| CVE-2008-6097 |
Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before
1.7.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) key parameter to index.php/Special/Main/keywordSearch, (2)
revNum parameter to index.php/Edit/Main/Home, (3) to parameter to
index.php/Special/Main/WhatLinksHere, (4) user parameter to
index.php/Special/Main/UserEdits, and (5) the PATH_INFO to index.php.
|
| CVE-2008-6096 |
Cross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS
before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject
arbitrary web script or HTML via the user name parameter to the (1)
web interface login page or the (2) telnet login page.
|
| CVE-2008-6095 |
Cross-site scripting (XSS) vulnerability in surveillanceView.htm in
OpenNMS 1.5.94 allows remote attackers to inject arbitrary web script
or HTML via the viewName parameter.
|
| CVE-2008-6094 |
Cross-site scripting (XSS) vulnerability in user.do in Celoxis
Technologies Celoxis allows remote attackers to inject arbitrary web
script or HTML via the ni.smessage parameter.
|
| CVE-2008-6087 |
Cross-site scripting (XSS) vulnerability in topic.php in Camera Life
2.6.2b4 allows remote attackers to inject arbitrary web script or HTML
via the name parameter.
|
| CVE-2008-6062 |
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary
Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the
Insert Flash Video feature is used, allows remote attackers to inject
arbitrary web script or HTML via an asfunction: URI in the skinName
parameter. NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or
CVE-2007-6637.
|
| CVE-2008-6061 |
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary
Shockwave Flash (SWF) controller files created by Techsmith Camtasia
Studio before 5 allows remote attackers to inject arbitrary additional
SWF content via a URL in the csPreloader parameter.
|
| CVE-2008-6060 |
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary
Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows
remote attackers to inject arbitrary additional SWF content via a URL
in the SRC attribute of an IMG element in the dataURL parameter.
|
| CVE-2008-6056 |
Multiple cross-site scripting (XSS) vulnerabilities in World Recipe
2.11 allow remote attackers to inject arbitrary web script or HTML via
the (1) n parameter to emailrecipe.aspx, (2) id parameter to
recipedetail.aspx, and the (3) catid parameter to
validatefieldlength.aspx.
|
| CVE-2008-6047 |
Cross-site scripting (XSS) vulnerability in ADbNewsSender before 1.5.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to (1) subscribing and (2) unsubscribing.
|
| CVE-2008-6044 |
Cross-site scripting (XSS) vulnerability in advanced_search_result.php
in xt:Commerce 3.0.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via the keywords parameter.
|
| CVE-2008-6041 |
Multiple cross-site scripting (XSS) vulnerabilities in Index.asp in
Dataspade 1.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) ViewName, (2) TableName, (3) OrderBy, and (4)
FilterField parameters.
|
| CVE-2008-6035 |
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo
1.3.2-STABLE allows remote attackers to inject arbitrary web script or
HTML via the atknodetype parameter.
|
| CVE-2008-6034 |
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo
1.3.2 allows remote attackers to inject arbitrary web script or HTML
via the atkaction parameter. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2008-6027 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) whl, (2) var_1, and (3)
search parameters.
|
| CVE-2008-6004 |
Cross-site scripting (XSS) vulnerability in search.php in AJ Auction
Pro Platinum 2 allows remote attackers to inject arbitrary web script
or HTML via the product parameter.
|
| CVE-2008-5999 |
Cross-site scripting (XSS) vulnerability in the Ajax Checklist module
5.x before 5.x-1.1 for Drupal allows remote authenticated users, with
create and edit permissions for posts, to inject arbitrary web script
or HTML via unspecified vectors involving the ajax_checklist filter.
|
| CVE-2008-5996 |
Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x
before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal,
allows remote authenticated users, with "administer taxonomy"
permissions, to inject arbitrary web script or HTML via a Newsletter
category field.
|
| CVE-2008-5995 |
Cross-site scripting (XSS) vulnerability in the freeCap CAPTCHA
(sr_freecap) extension before 1.0.4 for TYPO3 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-5994 |
Cross-site scripting (XSS) vulnerability in index.php in Check Point
Connectra NGX R62 HFA_01 allows remote attackers to inject arbitrary
web script or HTML via the dir parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-5979 |
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12
Mailing List Manager Gold allows remote attackers to inject arbitrary
web script or HTML via the Email parameter.
|
| CVE-2008-5976 |
Multiple cross-site scripting (XSS) vulnerabilities in
siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to
inject arbitrary web script or HTML via (1) the adname parameter in a
Submit action or (2) the UserName field.
|
| CVE-2008-5971 |
Cross-site scripting (XSS) vulnerability in profile_social.php in
i-Net Solution Orkut Clone allows remote authenticated users to inject
arbitrary web script or HTML via the id parameter.
|
| CVE-2008-5961 |
Cross-site scripting (XSS) vulnerability in index.php in Tribiq CMS
Community 5.0.10B and 5.0.11E allows remote attackers to inject
arbitrary web script or HTML via the cID parameter in a document
action. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-5944 |
Cross-site scripting (XSS) vulnerability in modules.php in NavBoard 16
(2.6.0) allows remote attackers to inject arbitrary web script or HTML
via the module parameter.
|
| CVE-2008-5942 |
Multiple cross-site scripting (XSS) vulnerabilities in MODx before
0.9.6.3 allow remote attackers to inject arbitrary web script or HTML
via vectors related to (1) the preserveUrls function and (2) "username
input." NOTE: vector 2 may be related to CVE-2008-5939.
|
| CVE-2008-5939 |
Cross-site scripting (XSS) vulnerability in index.php in MODx CMS
0.9.6.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via a JavaScript event in the username field, possibly
related to snippet.ditto.php. NOTE: some sources list the id
parameter as being affected, but this is probably incorrect based on
the original disclosure.
|
| CVE-2008-5933 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
CMS ISWEB 3.0 allow remote attackers to inject arbitrary web script or
HTML via (1) the strcerca parameter (aka the input field for the cerca
action) or (2) the id_oggetto parameter. NOTE: some of these details
are obtained from third party information.
|
| CVE-2008-5918 |
Cross-site scripting (XSS) vulnerability in the
getParameterisedSelfUrl function in index.php in WebSVN 2.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO.
|
| CVE-2008-5917 |
Cross-site scripting (XSS) vulnerability in the XSS filter
(framework/Text_Filter/Filter/xss.php) in Horde Application Framework
3.2.2 and 3.3, when Internet Explorer is being used, allows remote
attackers to inject arbitrary web script or HTML via unknown vectors
related to style attributes.
|
| CVE-2008-5893 |
Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in
ClickAndEmail allows remote attackers to inject arbitrary web script
or HTML via the tablename parameter in an update action.
|
| CVE-2008-5891 |
Cross-site scripting (XSS) vulnerability in the profile editing
functionality in Injader before 2.1.2 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors. NOTE:
some of these details are obtained from third party information.
|
| CVE-2008-5889 |
Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank
allows remote attackers to inject arbitrary web script or HTML via the
action parameter.
|
| CVE-2008-5879 |
Cross-site scripting (XSS) vulnerability in index.php in
Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote
attackers to inject arbitrary web script or HTML via the page
parameter and other unspecified vectors.
|
| CVE-2008-5869 |
Cross-site scripting (XSS) vulnerability in the Proxim Wireless
Tsunami MP.11 2411 with firmware 3.0.3 allows remote authenticated
users to inject arbitrary web script or HTML via the system.sysName.0
SNMP OID.
|
| CVE-2008-5858 |
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree
before 3.5.4a allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors, a different issue than CVE-2007-4281.
|
| CVE-2008-5854 |
Multiple cross-site scripting (XSS) vulnerabilities in login.php in
myPHPscripts Login Session 2.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) ls_user and (2) ls_email
parameters (aka the User form) in an ls_register action. NOTE: some of
these details are obtained from third party information.
|
| CVE-2008-5845 |
Multiple cross-site scripting (XSS) vulnerabilities in Six Apart
Movable Type (MT) before 4.23 allow remote attackers to inject
arbitrary web script or HTML via a (1) MTEntryAuthorUsername, (2)
MTAuthorDisplayName, (3) MTEntryAuthorDisplayName, or (4)
MTCommenterName field in a Profile View template; a (5) listing screen
or (6) edit screen in the CMS app; (7) a TrackBack title, related to
the HTML sanitization library; or (8) a user archive name (aka archive
title) on a published Community Blog template.
|
| CVE-2008-5842 |
Multiple cross-site scripting (XSS) vulnerabilities in Fujitsu-Siemens
WebTransactions 7.0, 7.1, and possibly other versions allow remote
attackers to inject arbitrary web script or HTML via vectors
associated with (1) a demo application shipped with WebTransactions
and possibly (2) an unspecified "dynamic application."
|
| CVE-2008-5814 |
Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and
earlier, when display_errors is enabled, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors. NOTE:
because of the lack of details, it is unclear whether this is related
to CVE-2006-0208.
|
| CVE-2008-5808 |
Cross-site scripting (XSS) vulnerability in Six Apart Movable Type
Enterprise (MTE) 1.x before 1.56; Movable Type (MT) 3.x before 3.38;
and Movable Type, Movable Type Open Source (MTOS), and Movable Type
Enterprise 4.x before 4.23 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, possibly related to
"application management."
|
| CVE-2008-5807 |
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before
1.8 RC1 allow remote attackers to inject arbitrary web script or HTML
via (1) Testproject Names and (2) Testplan Names in planEdit.php, and
possibly (3) Testcaseprefixes in projectview.tpl.
|
| CVE-2008-5799 |
Cross-site scripting (XSS) vulnerability in the Wir ber uns
(fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-5795 |
Cross-site scripting (XSS) vulnerability in the eluna Page Comments
(eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-5786 |
Cross-site scripting (XSS) vulnerability in the Silva Find extension
1.1.5 and earlier in Silva 1.x before 1.6.3.2, Silva 2.0 before
2.0.12.2, and Silva 2.1 before 2.1.0.2 allows remote attackers to
inject arbitrary web script or HTML via the fulltext parameter.
|
| CVE-2008-5770 |
Cross-site scripting (XSS) vulnerability in config/make_config.php in
PHP Weather 2.2.2 allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO.
|
| CVE-2008-5769 |
Multiple cross-site scripting (XSS) vulnerabilities in Kerio
MailServer before 6.6.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) folder parameter to mailCompose.php or the
(2) daytime parameter to calendarEdit.php. NOTE: some of these details
are obtained from third party information.
|
| CVE-2008-5761 |
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS
(aka Flatnuke3) 2008-12-11 allow remote attackers to inject arbitrary
web script or HTML via (1) the mod parameter to the default URI; (2)
the foto parameter to photo.php in the 05_Foto module; or (3) the name
parameter in an insertrecord action to index.php in the 08_Files
module, as demonstrated by injection within a SRC attribute of an
IFRAME element.
|
| CVE-2008-5760 |
Cross-site scripting (XSS) vulnerability in error413.php in Kerio
MailServer before 6.6.2 allows remote attackers to inject arbitrary
web script or HTML via the sent parameter. NOTE: some of these details
are obtained from third party information.
|
| CVE-2008-5759 |
Cross-site scripting (XSS) vulnerability in FlatnuX CMS (aka
Flatnuke3) 2008-12-11 allows remote attackers to inject arbitrary web
script or HTML via the name parameter in an updaterecord action to
index.php in the 08_Files module. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-5757 |
Cross-site scripting (XSS) vulnerability in textarea/index.php in
Textpattern (aka Txp CMS) 4.0.6 and earlier allows remote
authenticated users to inject arbitrary web script or HTML via the
Body parameter in an article action. NOTE: some of these details are
obtained from third party information.
|
| CVE-2008-5734 |
Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp
Software Merak Mail Server 9.3.2 allows remote attackers to inject
arbitrary web script or HTML via an IMG element in an HTML e-mail
message.
|
| CVE-2008-5729 |
Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat
3.12 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) form and (2) control parameters to
FCKeditor/neditor.php, and the (3) path parameter to
admin/siteinfo/iframe.inc.php.
|
| CVE-2008-5720 |
Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.23 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors involving the default error page for the
org.seasar.mayaa.impl.engine.PageNotFoundException exception and
possibly other exceptions.
|
| CVE-2008-5719 |
Cross-site scripting (XSS) vulnerability in Hitachi Groupmax Web
Workflow SDK Set for Active Server Pages before 06-52-/C and Hitachi
Groupmax Workflow - Development Kit for Active Server Pages before
06-52-/A allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2008-5717 |
Cross-site scripting (XSS) vulnerability in Hitachi JP1/Integrated
Management - Service Support 08-10 through 08-10-05, 08-11 through
08-11-03, and 08-50 through 08-50-03 on Windows allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-5682 |
Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows
remote attackers to inject arbitrary web script or HTML via built-in
XSLT templates.
|
| CVE-2008-5668 |
Multiple cross-site scripting (XSS) vulnerabilities in Textpattern
(aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web
script or HTML via (1) the PATH_INFO to setup/index.php or (2) the
name parameter to index.php in the comments preview section.
|
| CVE-2008-5656 |
Cross-site scripting (XSS) vulnerability in the frontend plugin for
the felogin system extension in TYPO3 4.2.0, 4.2.1 and 4.2.2 allows
remote attackers to inject arbitrary web script or HTML via unknown
vectors.
|
| CVE-2008-5644 |
Cross-site scripting (XSS) vulnerability in the file backend module in
TYPO3 4.2.2 allows remote attackers to inject arbitrary web script or
HTML via unknown vectors.
|
| CVE-2008-5591 |
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall
Personal Diary 1.0 allows remote attackers to inject arbitrary web
script or HTML via the username parameter and possibly other "login
fields." NOTE: some of these details are obtained from third party
information.
|
| CVE-2008-5584 |
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) a message, (2) a milestone, or (3) a display name in a
profile, or the (4) a or (5) c parameter to index.php.
|
| CVE-2008-5569 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop
1.4 allow remote attackers to inject arbitrary web script or HTML via
the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3)
shop_kunden_mgmt.php or (4) SHOP_KONFIGURATION.php in shop/Admin/.
|
| CVE-2008-5566 |
Cross-site scripting (XSS) vulnerability in index.php in Triangle
Solutions PHP Multiple Newsletters 2.7 allows remote attackers to
inject arbitrary web script or HTML via the PATH_INFO.
|
| CVE-2008-5556 |
** DISPUTED **
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not
recognize attack patterns designed to operate against web pages that
are encoded with utf-7, which allows remote attackers to bypass the
XSS protection mechanism and conduct XSS attacks by injecting crafted
utf-7 content. NOTE: the vendor reportedly disputes this issue,
stating "Behaviour is by design."
|
| CVE-2008-5555 |
Microsoft Internet Explorer 8.0 Beta 2 relies on the
XDomainRequestAllowed HTTP header to authorize data exchange between
domains, which allows remote attackers to bypass the product's XSS
Filter protection mechanism, and conduct XSS and cross-domain attacks,
by injecting this header after a CRLF sequence, related to
"XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has
reportedly stated that the XSS Filter intentionally does not attempt
to "address every conceivable XSS attack scenario."
|
| CVE-2008-5554 |
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not
properly handle some HTTP headers that appear after a CRLF sequence in
a URI, which allows remote attackers to bypass the XSS protection
mechanism and conduct XSS or redirection attacks, as demonstrated by
the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has
reportedly stated that the XSS Filter intentionally does not attempt
to "address every conceivable XSS attack scenario."
|
| CVE-2008-5553 |
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables
itself upon encountering a certain X-XSS-Protection HTTP header, which
allows remote attackers to bypass the XSS protection mechanism and
conduct XSS attacks by injecting this header after a CRLF sequence.
NOTE: the vendor has reportedly stated that the XSS Filter
intentionally does not attempt to "address every conceivable XSS
attack scenario."
|
| CVE-2008-5552 |
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote
attackers to bypass the XSS protection mechanism and conduct XSS
attacks via a CRLF sequence in conjunction with a crafted Content-Type
header, as demonstrated by a header with a utf-7 charset value. NOTE:
the vendor has reportedly stated that the XSS Filter intentionally
does not attempt to "address every conceivable XSS attack scenario."
|
| CVE-2008-5551 |
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote
attackers to bypass the XSS protection mechanism and conduct XSS
attacks by injecting data at two different positions within an HTML
document, related to STYLE elements and the CSS expression property,
aka a "double injection."
|
| CVE-2008-5513 |
Unspecified vulnerability in the session-restore feature in Mozilla
Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote
attackers to bypass the same origin policy, inject content into
documents associated with other domains, and conduct cross-site
scripting (XSS) attacks via unknown vectors related to restoration of
SessionStore data.
|
| CVE-2008-5511 |
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird
2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote
attackers to bypass the same origin policy and conduct cross-site
scripting (XSS) attacks via an XBL binding to an "unloaded document."
|
| CVE-2008-5487 |
Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms
Text Link Sales allows remote attackers to inject arbitrary web script
or HTML via the id parameter.
|
| CVE-2008-5435 |
Cross-site scripting (XSS) vulnerability in moderate.php in PunBB
before 1.3.1 allows remote attackers to inject arbitrary web script or
HTML via a topic subject.
|
| CVE-2008-5433 |
Cross-site scripting (XSS) vulnerability in login.php in PunBB 1.3 and
1.3.1 allows remote attackers to inject arbitrary web script or HTML
via the password field.
|
| CVE-2008-5432 |
Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7
before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote
attackers to inject arbitrary web script or HTML via a Wiki page name
(aka page title).
|
| CVE-2008-5399 |
Cross-site scripting (XSS) vulnerability in the listonlineusers (aka
"Who's online") component in mvnForum before 1.2.1 GA allows remote
attackers to inject arbitrary web script or HTML via unspecified
parameters.
|
| CVE-2008-5338 |
Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite
(aka Bandsite portal system) 1.5 allows remote attackers to inject
arbitrary web script or HTML via the section parameter.
|
| CVE-2008-5330 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0
before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1
versions before 7.0.1.3, allow remote attackers to inject arbitrary
web script or HTML via the PATH_INFO of a URI associated with a VOB
page.
|
| CVE-2008-5325 |
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM
Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-5324 |
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM
Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-5323 |
Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg
1.0 allows remote attackers to inject arbitrary web script or HTML via
the s parameter.
|
| CVE-2008-5304 |
Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows
remote attackers to inject arbitrary web script or HTML via the
%URLPARAM{}% variable.
|
| CVE-2008-5290 |
Cross-site scripting (XSS) vulnerability in full_txt.php in Werner
Hilversum Clean CMS 1.5 allows remote attackers to inject arbitrary
web script or HTML via the id parameter.
|
| CVE-2008-5278 |
Cross-site scripting (XSS) vulnerability in the self_link function in
in the RSS Feed Generator (wp-includes/feed.php) for WordPress before
2.6.5 allows remote attackers to inject arbitrary web script or HTML
via the Host header (HTTP_HOST variable).
|
| CVE-2008-5271 |
Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman
SyndeoCMS 2.6.0 allows remote attackers to inject arbitrary web script
or HTML via the section parameter.
|
| CVE-2008-5266 |
Cross-site scripting (XSS) vulnerability in
configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin
interface in Sun Java System Application Server 9.1_01 build b09d-fcs
and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary
web script or HTML via the name parameter, a different vector than
CVE-2008-2751.
|
| CVE-2008-5264 |
Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado
Knowledge Retrieval System 4.2 and earlier allows remote attackers to
inject arbitrary web script or HTML via the p parameter in a root
action.
|
| CVE-2008-5250 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11,
1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer
is used and uploads are enabled, or an SVG scripting browser is used
and SVG uploads are enabled, allows remote authenticated users to
inject arbitrary web script or HTML by editing a wiki page.
|
| CVE-2008-5249 |
Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.0 through
1.13.2 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2008-5228 |
Cross-site scripting (XSS) vulnerability in IBM Workplace Content
Management (WCM) 6.0G and 6.1 before CF8, when a Page Navigation
Component shows menu entries, allows remote attackers to inject
arbitrary web script or HTML via unspecified parameters in the URI,
related to parameters "not being encoded."
|
| CVE-2008-5225 |
Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare
6 and earlier allow remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to the default URI under (1) SearchResults/ and
(2) Services/ in dsdn/dsweb/, and (3) the default URI under
unspecified docushare/dsweb/ServicesLib/Group-#/ directories.
|
| CVE-2008-5224 |
Cross-site scripting (XSS) vulnerability in Kent Web Mart 1.61 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2008-5214 |
Cross-site scripting (XSS) vulnerability in service/calendrier.php in
ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web
script or HTML via the annee parameter.
|
| CVE-2008-5211 |
Cross-site scripting (XSS) vulnerability in search.php in Sphider
1.3.4, when the search suggestion feature is enabled, allows remote
attackers to inject arbitrary web script or HTML via the query
parameter, a different vector than CVE-2006-2506.
|
| CVE-2008-5205 |
Cross-site scripting (XSS) vulnerability in edit.php in wellyblog
allows remote attackers to inject arbitrary web script or HTML via the
articleid parameter in an add action.
|
| CVE-2008-5203 |
Cross-site scripting (XSS) vulnerability in external_vote.php in
PowerAward 1.1.0 RC1 allows remote attackers to inject arbitrary web
script or HTML via the l_vote_done parameter.
|
| CVE-2008-5202 |
Cross-site scripting (XSS) vulnerability in index.php in OTManager CMS
24a allows remote attackers to inject arbitrary web script or HTML via
the conteudo parameter.
|
| CVE-2008-5193 |
Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4
Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web
script or HTML via the searchterms parameter. NOTE: this might overlap
CVE-2007-4024.
|
| CVE-2008-5172 |
Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum
Software 3.x allow remote attackers to inject arbitrary web script or
HTML via the (1) q parameter to (a) search.jsp, and the (2) msg
parameter to (b) error.jsp and (c) userAccount.jsp. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-5164 |
Multiple cross-site scripting (XSS) vulnerabilities in The Rat CMS
Pre-Alpha 2 allow remote attackers to inject arbitrary web script or
HTML via the (1) id parameter to (a) viewarticle.php and (b)
viewarticle2.php and the (2) PATH_INFO to viewarticle.php.
|
| CVE-2008-5163 |
Multiple SQL injection vulnerabilities in The Rat CMS Pre-Alpha 2
allow remote attackers to execute arbitrary SQL commands via the id
parameter to (1) viewarticle.php and (2) viewarticle2.php.
|
| CVE-2008-5126 |
Cross-site scripting (XSS) vulnerability in search.php in BoutikOne
CMS allows remote attackers to inject arbitrary web script or HTML via
the search_query parameter.
|
| CVE-2008-5119 |
Cross-site scripting (XSS) vulnerability in search.php in
Scripts4Profit DXShopCart 4.30mc allows remote attackers to inject
arbitrary web script or HTML via the keyword parameter.
|
| CVE-2008-5114 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System
Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-5098 |
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging
Server 6.2 and 6.3 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, a different vulnerability than
CVE-2007-2904.
|
| CVE-2008-5095 |
Cross-site scripting (XSS) vulnerability in the Novell User
Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based
Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject
arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-5093 |
Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack
(HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers
to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-5080 |
awstats.pl in AWStats 6.8 and earlier does not properly remove quote
characters, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via the query_string parameter. NOTE: this
issue exists because of an incomplete fix for CVE-2008-3714.
|
| CVE-2008-5068 |
Multiple cross-site scripting (XSS) vulnerabilities in Kmita Gallery
allow remote attackers to inject arbitrary web script or HTML via the
(1) begin parameter to index.php and the (2) searchtext parameter to
search.php. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-5067 |
Cross-site scripting (XSS) vulnerability in search.php in Kmita
Catalogue 2.x allows remote attackers to inject arbitrary web script
or HTML via the q parameter. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2008-5061 |
Cross-site scripting (XSS) vulnerability in php/cal_default.php in
Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject
arbitrary web script or HTML via the URL.
|
| CVE-2008-5059 |
Cross-site scripting (XSS) vulnerability in index.php in ModernBill
4.4 and earlier allows remote attackers to inject arbitrary web script
or HTML via a Javascript event in the new_language parameter in a
login action.
|
| CVE-2008-5056 |
Cross-site scripting (XSS) vulnerability in
department_offline_context.php in ActiveCampaign TrioLive before
1.58.7 allows remote attackers to inject arbitrary web script or HTML
via the department_id parameter to index.php.
|
| CVE-2008-5043 |
Multiple cross-site scripting (XSS) vulnerabilities in the web-based
interface in IBM Metrica Service Assurance Framework allow remote
authenticated users to inject arbitrary web script or HTML via (1) the
elementid parameter in a generatedreportresults action to the
ReportTree program, (2) the jnlpname parameter to the Launch program,
or (3) the :tasklabel parameter to the ReportRequest program, related
to the name of a report.
|
| CVE-2008-5039 |
Cross-site scripting (XSS) vulnerability in the League module for
PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary
web script or HTML via the tid parameter in a team action to
modules.php.
|
| CVE-2008-5026 |
Microsoft SharePoint uses URLs with the same hostname and port number
for a web site's primary files and individual users' uploaded files
(aka attachments), which allows remote authenticated users to leverage
same-origin relationships and conduct cross-site scripting (XSS)
attacks by uploading HTML documents.
|
| CVE-2008-5019 |
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and
2.x before 2.0.0.18 allows remote attackers to violate the same origin
policy to conduct cross-site scripting (XSS) attacks and execute
arbitrary JavaScript with chrome privileges via unknown vectors.
|
| CVE-2008-5011 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus
Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, possibly related to qpconfig_sample.xml, aka SPR CWIR7KMPVP
and THES7F9NVR, a different vulnerability than CVE-2008-2163 and
CVE-2008-3860.
|
| CVE-2008-4931 |
Cross-site scripting (XSS) vulnerability in the account module in
firmCHANNEL Digital Signage 3.24, and possibly earlier versions,
allows remote attackers to inject arbitrary web script or HTML via the
action parameter to index.php.
|
| CVE-2008-4930 |
MyBB (aka MyBulletinBoard) 1.4.2 does not properly handle an uploaded
file with a nonstandard file type that contains HTML sequences, which
allows remote attackers to cause that file to be processed as HTML by
Internet Explorer's content inspection, aka "Incomplete protection
against MIME-sniffing." NOTE: this could be leveraged for XSS and
other attacks.
|
| CVE-2008-4928 |
Cross-site scripting (XSS) vulnerability in the redirect function in
functions.php in MyBB (aka MyBulletinBoard) 1.4.2 allows remote
attackers to inject arbitrary web script or HTML via the url parameter
in a removesubscriptions action to moderation.php, related to use of
the ajax option to request a JavaScript redirect. NOTE: this can be
leveraged to execute PHP code and bypass cross-site request forgery
(CSRF) protection.
|
| CVE-2008-4918 |
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced
before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190,
allows remote attackers to inject arbitrary web script or HTML into
arbitrary web sites via a URL to a site that is blocked based on
content filtering, which is not properly handled in the CFS block
page, aka "universal website hijacking."
|
| CVE-2008-4903 |
Cross-site scripting (XSS) vulnerability in the leave comment
(feedback) feature in Typo 5.1.3 and earlier allows remote attackers
to inject arbitrary web script or HTML via the (1) comment[author]
(Name) and (2) comment[url] (Website) parameters.
|
| CVE-2008-4898 |
Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3
allows remote attackers to inject arbitrary web script or HTML via the
rate parameter in a submit rate action.
|
| CVE-2008-4896 |
Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in
Logz CMS 1.3.1 allows remote attackers to inject arbitrary web script
or HTML via the art parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4893 |
Cross-site scripting (XSS) vulnerability in
templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in
Tribiq CMS 5.0.10a, when register_globals is enabled, allows remote
attackers to inject arbitrary web script or HTML via the template_path
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-4892 |
Cross-site scripting (XSS) vulnerability in gallery.inc.php in
Planetluc MyGallery 1.7.2 and earlier, and possibly other versions
before 1.8.1, allows remote attackers to inject arbitrary web script
or HTML via the mghash parameter. NOTE: some of these details are
obtained from third party information.
|
| CVE-2008-4891 |
Cross-site scripting (XSS) vulnerability in signme.inc.php in
Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject
arbitrary web script or HTML via the hash parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2008-4888 |
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0
and earlier allows remote attackers to inject arbitrary web script or
HTML via the error parameter to index.php. NOTE: some of these
details are obtained from third party information.
|
| CVE-2008-4876 |
Cross-site scripting (XSS) vulnerability in the web server component
in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and
1.0.4.80 allows remote attackers to inject arbitrary web script or
HTML via the request URL, which is not properly handled in a 404 web
error page.
|
| CVE-2008-4872 |
Cross-site scripting (XSS) vulnerability in bidhistory.php in
iTechBids Gold 5.0 allows remote attackers to inject arbitrary web
script or HTML via the item_id parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4871 |
Cross-site scripting (XSS) vulnerability in My Little Forum 1.75 and
2.0 Beta 23 allows remote attackers to inject arbitrary web script or
HTML via BBcode IMG tags.
|
| CVE-2008-4823 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player
9.0.124.0 and earlier allows remote attackers to inject arbitrary web
script or HTML via vectors related to loose interpretation of an
ActionScript attribute.
|
| CVE-2008-4818 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player
9.0.124.0 and earlier allows remote attackers to inject arbitrary web
script or HTML via vectors involving HTTP response headers.
|
| CVE-2008-4805 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus
Connections 2.x before 2.0.1 allow remote attackers to inject
arbitrary web script or HTML via (1) the community title, (2) API
input, and vectors related to the (3) Homepage, (4) Blogs, (5)
Profiles, (6) Dogear, (7) Activities, and (8) Global Search
components. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-4803 |
Cross-site scripting (XSS) vulnerability in index.php in Simple PHP
Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject
arbitrary web script or HTML via the gallery parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-4802 |
Cross-site scripting (XSS) vulnerability in complete.php in Simple PHP
Scripts blog 0.3 allows remote attackers to inject arbitrary web
script or HTML via the id parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4795 |
The links panel in Opera before 9.62 processes Javascript within the
context of the "outermost page" of a frame, which allows remote
attackers to inject arbitrary web script or HTML via cross-site
scripting (XSS) attacks.
|
| CVE-2008-4775 |
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin
3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when
register_globals is enabled, allows remote attackers to inject
arbitrary web script or HTML via the db parameter, a different vector
than CVE-2006-6942 and CVE-2007-5977.
|
| CVE-2008-4774 |
Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS
allows remote attackers to inject arbitrary web script or HTML via the
cx parameter.
|
| CVE-2008-4763 |
Multiple cross-site scripting (XSS) vulnerabilities in sample.php in
WiKID wClient-PHP 3.0-2 and earlier allow remote attackers to inject
arbitrary web script or HTML via the PHP_SELF variable.
|
| CVE-2008-4761 |
Cross-site scripting (XSS) vulnerability in
includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako
eSupport 3.20.2 allows remote attackers to inject arbitrary web script
or HTML via the jsMakeSrc parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information. NOTE: this issue is probably in the HTMLArea
HTMLTidy (HTML Tidy) plugin, not eSupport.
|
| CVE-2008-4756 |
Cross-site scripting (XSS) vulnerability in add_prest_date.php in
PHP-Daily allows remote attackers to inject arbitrary web script or
HTML via the date parameter.
|
| CVE-2008-4751 |
Cross-site scripting (XSS) vulnerability in index.php in iPei
Guestbook 2.0 allows remote attackers to inject arbitrary web script
or HTML via the pg parameter, a different vector than CVE-2005-4597.
|
| CVE-2008-4745 |
Cross-site scripting (XSS) vulnerability in emailFriend.asp in Uniwin
eCart Professional 2.0.17 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-4742 |
Multiple cross-site scripting (XSS) vulnerabilities in
interface/Login.php in TimeTrex 2.2.11 allow remote attackers to
inject arbitrary web script or HTML via the (1) password and (2)
user_name parameters.
|
| CVE-2008-4737 |
Cross-site scripting (XSS) vulnerability in wholite.cgi in WhoDomLite
1.1.3 allows remote attackers to inject arbitrary web script or HTML
via the dom parameter.
|
| CVE-2008-4733 |
Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP
Comment Remix plugin before 1.4.4 for WordPress allows remote
attackers to inject arbitrary web script or HTML via the (1)
replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5)
maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9)
tagheaderlabel parameters.
|
| CVE-2008-4730 |
Cross-site scripting (XSS) vulnerability in MyID.php in phpMyID 0.9
allows remote attackers to inject arbitrary web script or HTML via the
openid_trust_root parameter and an inconsistent openid_return_to
parameter, which is not properly handled in an error message.
|
| CVE-2008-4727 |
Cross-site scripting (XSS) vulnerability in the contact update page
(ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3
allows remote attackers to inject arbitrary web script or HTML via the
addr1 parameter. NOTE: this might be resultant from a CSRF
vulnerability, but there are insufficient details to be sure.
|
| CVE-2008-4725 |
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52
allows remote attackers to inject arbitrary web script or HTML via the
query string, which is not properly escaped before storage in the
History Search database (aka md.dat), a different vector than
CVE-2008-4696. NOTE: some of these issues were addressed before 9.60.
|
| CVE-2008-4724 |
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome
0.2.149.30 allow remote attackers to inject arbitrary web script or
HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF,
or (3) TXT file. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2008-4723 |
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox
3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web
script or HTML via an ftp:// URL for an HTML document within a (1)
JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4710 |
Cross-site scripting (XSS) vulnerability in the stock quotes page in
Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-4697 |
The Fast Forward feature in Opera before 9.61, when a page is located
in a frame, executes a javascript: URL in the context of the outermost
page instead of the page that contains this URL, which allows remote
attackers to conduct cross-site scripting (XSS) attacks.
|
| CVE-2008-4696 |
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before
9.61 allows remote attackers to inject arbitrary web script or HTML
via the anchor identifier (aka the "optional fragment"), which is not
properly escaped before storage in the History Search database (aka
md.dat).
|
| CVE-2008-4672 |
Cross-site scripting (XSS) vulnerability in search_results.php in
buymyscripts Lyrics Script allows remote attackers to inject arbitrary
web script or HTML via the k parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4671 |
Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in
Wordpress MU (WPMU) before 2.6 allows remote attackers to inject
arbitrary web script or HTML via the (1) s and (2) ip_address
parameters.
|
| CVE-2008-4670 |
Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol
Clickbank Portal allows remote attackers to inject arbitrary web
script or HTML via the search box. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4669 |
Cross-site scripting (XSS) vulnerability in search.php in Dan Fletcher
Recipe Script allows remote attackers to inject arbitrary web script
or HTML via the keyword parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4663 |
Cross-site scripting (XSS) vulnerability in analysis.cgi 1.44, as used
in K's CGI Access Log Kaiseki (1) jcode.pl and (2) Jcode.pm, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-4661 |
Cross-site scripting (XSS) vulnerability in the Page Improvements
(sm_pageimprovements) 1.1.0 and earlier extension for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-4648 |
Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS
2008.1 revision 2204 allows remote attackers to inject arbitrary web
script or HTML via the (1) PATH_INFO or the (2) option, (3) Itemid,
(4) id, (5) task, (6) bid, and (7) contact_id parameters. NOTE: the
error might be located in modules/mod_language.php, and index.php
might be the interaction point.
|
| CVE-2008-4637 |
Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors in the advanced search feature. NOTE: this is probably
a variant of CVE-2008-4121.
|
| CVE-2008-4634 |
Cross-site scripting (XSS) vulnerability in Movable Type 4 through
4.21 allows remote attackers to inject arbitrary web script or HTML
via unknown vectors related to the administrative page, a different
vulnerability than CVE-2008-4079.
|
| CVE-2008-4629 |
Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS 1.2.0
and earlier allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2008-4612 |
Cross-site scripting (XSS) vulnerability in PortalApp 4.0 allows
remote attackers to inject arbitrary web script or HTML via the
keywords parameter to (1) forums.asp and (2) content.asp.
|
| CVE-2008-4601 |
Cross-site scripting (XSS) vulnerability in the login feature in
Habari CMS 0.5.1 allows remote attackers to inject arbitrary web
script or HTML via the habari_username parameter.
|
| CVE-2008-4598 |
Unspecified vulnerability in Shindig-Integrator 5.x, a module for
Drupal, has unspecified impact and remote attack vectors related to
"numerous flaws" that are not related to XSS or access control, a
different vulnerability than CVE-2008-4596 and CVE-2008-4597.
|
| CVE-2008-4596 |
Cross-site scripting (XSS) vulnerability in Shindig-Integrator 5.x, a
module for Drupal, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors in generated
pages.
|
| CVE-2008-4591 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote
attackers to inject arbitrary web script or HTML via the (1)
lang[access_forbiden] and (2) lang[ident_title] parameters.
|
| CVE-2008-4571 |
Cross-site scripting (XSS) vulnerability in the LiveSearch module in
Plone before 3.0.4 allows remote attackers to inject arbitrary web
script or HTML via the Description field for search results, as
demonstrated using the onerror Javascript even in an IMG tag.
|
| CVE-2008-4542 |
Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before
4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows
remote authenticated administrators to inject arbitrary web script or
HTML by entering it in the database (aka data store).
|
| CVE-2008-4537 |
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver1 1.4.6 and
earlier, Ver1 Beta 1.5.0-beta and earlier, Ver2 2.1.2a and earlier,
Ver2 Beta(RC) 2.1.1-beta and earlier, Community Edition 1.3.4 and
earlier, and Community Edition Nightly-Build r17336 and earlier allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different issue than CVE-2008-4535 and
CVE-2008-4536.
|
| CVE-2008-4536 |
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver1 1.4.6 and
earlier, Ver1 Beta 1.5.0-beta and earlier, Ver2 2.1.2a and earlier,
Ver2 Beta(RC) 2.2.0-beta and earlier, Community Edition 1.3.4 and
earlier, and Community Edition Nightly-Build r17319 and earlier allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different issue than CVE-2008-4535 and
CVE-2008-4537.
|
| CVE-2008-4535 |
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver2 2.1.2a and
earlier, EC-CUBE Ver2 Beta(RC) 2.2.0-beta and earlier, and EC-CUBE
Community Edition Nighly-Build r17623 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, a different issue than CVE-2008-4536 and CVE-2008-4537.
|
| CVE-2008-4533 |
Cross-site scripting (XSS) vulnerability in Kantan WEB Server 1.8 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unknown vectors.
|
| CVE-2008-4532 |
Cross-site scripting (XSS) vulnerability in index.php in MaxiScript
Website Directory allows remote attackers to inject arbitrary web
script or HTML via the keyword parameter in a search action.
|
| CVE-2008-4530 |
Cross-site scripting (XSS) vulnerability in Brilliant Gallery 5.x
before 5.x-4.2, a module for Drupal, allows remote authenticated users
with permissions to inject arbitrary web script or HTML via
unspecified vectors related to posting of answers.
|
| CVE-2008-4520 |
Cross-site scripting (XSS) vulnerability in bulk_update.pl in
AutoNessus before 1.2.2 allows remote attackers to inject arbitrary
web script or HTML via the remark parameter.
|
| CVE-2008-4513 |
Cross-site scripting (XSS) vulnerability in BBcode API module in
Phorum 5.2.8 allows remote attackers to inject arbitrary web script or
HTML via nested BBcode image tags.
|
| CVE-2008-4488 |
Cross-site scripting (XSS) vulnerability in ap-pages.php in Atarone
CMS 1.2.0 allows remote attackers to inject arbitrary web script or
HTML via the (1) name and (2) id parameters. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-4485 |
Cross-site scripting (XSS) vulnerability in the ICAP patience page in
Blue Coat Security Gateway OS (SGOS) 4.2 before 4.2.9, 5.2 before
5.2.5, and 5.3 before 5.3.1.7 allows remote attackers to inject
arbitrary web script or HTML via the URL.
|
| CVE-2008-4481 |
Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-4456 |
Cross-site scripting (XSS) vulnerability in the command-line client in
MySQL 5.0.26 through 5.0.45, and other versions including versions
later than 5.0.45, when the --html option is enabled, allows attackers
to inject arbitrary web script or HTML by placing it in a database
cell, which might be accessed by this client when composing an HTML
document. NOTE: as of 20081031, the issue has not been fixed in MySQL
5.0.67.
|
| CVE-2008-4450 |
Cross-site scripting (XSS) vulnerability in adodb.php in XAMPP for
Windows 1.6.8 allows remote attackers to inject arbitrary web script
or HTML via the (1) dbserver, (2) host, (3) user, (4) password, (5)
database, and (6) table parameters. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4447 |
Cross-site scripting (XSS) vulnerability in actions.php in Positive
Software H-Sphere WebShell 4.3.10 allows remote attackers to inject
arbitrary web script or HTML via (1) the fn parameter during a dload
action, (2) the mask parameter during a search action, and (3) the tab
parameter during a sysinfo action.
|
| CVE-2008-4446 |
Cross-site scripting (XSS) vulnerability in Nucleus EUC-JP 3.31 SP1
and earlier allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2008-4438 |
Cross-site scripting (XSS) vulnerability in search.php in Datafeed
Studio 1.6.2 allows remote attackers to inject arbitrary web script or
HTML via the q parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-4435 |
Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT
Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote
attackers to inject arbitrary web script or HTML via the (1) key
parameter to search.php and the (2) id parameter to down.php.
|
| CVE-2008-4432 |
Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT
MiniShop module 1.0 for Xoops allows remote attackers to inject
arbitrary web script or HTML via the itemsxpag parameter.
|
| CVE-2008-4426 |
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's
Personal Information Manager (pPIM) 1.0 allows remote attackers to
inject arbitrary web script or HTML via the date parameter in a new
action.
|
| CVE-2008-4424 |
Cross-site scripting (XSS) vulnerability in index.php in Domain Group
Network GooCMS 1.02 allows remote attackers to inject arbitrary web
script or HTML via the s parameter in a comments action. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-4411 |
Cross-site scripting (XSS) vulnerability in HP System Management
Homepage (SMH) before 2.1.15.210 on Linux and Windows allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, a different vulnerability than CVE-2008-1663.
|
| CVE-2008-4408 |
Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0,
and possibly other versions before 1.13.2 allows remote attackers to
inject arbitrary web script or HTML via the useskin parameter to an
unspecified component.
|
| CVE-2008-4393 |
Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery
Management System (DMS) 5.0 and earlier allows remote attackers to
inject arbitrary web script or HTML via the action parameter to
zodiac/servlet/zodiac.
|
| CVE-2008-4379 |
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy
Hot Links SQL-PHP 3.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the id parameter.
|
| CVE-2008-4372 |
Cross-site scripting (XSS) vulnerability in articles.php in
AvailScript Article Script allows remote attackers to inject arbitrary
web script or HTML via the aIDS parameter.
|
| CVE-2008-4370 |
Multiple cross-site scripting (XSS) vulnerabilities in Availscript
Photo Album allow remote attackers to inject arbitrary web script or
HTML via the (1) sid parameter to pics.php and the (2) a parameter to
view.php.
|
| CVE-2008-4365 |
Cross-site scripting (XSS) vulnerability in search.php in Siteman
1.1.11 and earlier allows remote attackers to inject arbitrary web
script or HTML via unknown vectors. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4349 |
Multiple cross-site scripting (XSS) vulnerabilities in news.php in
s0nic Paranews 3.4 allow remote attackers to inject arbitrary web
script or HTML via the (1) id or (2) page parameter in a details
action.
|
| CVE-2008-4337 |
Cross-site scripting (XSS) vulnerability in Bitweaver 2.0.2 allows
remote attackers to inject arbitrary web script or HTML via the URL
parameter to (1) edit.php and (2) list.php in articles/; (3)
list_blogs.php and (4) rankings.php in blogs/; (5) calendar/index.php;
(6) calendar.php, (7) index.php, and (8) list_events.php in events/;
(9) index.php and (10) list_galleries.php in fisheye/; (11)
liberty/list_content.php; (12) newsletters/edition.php; (13)
pigeonholes/list.php; (14) recommends/index.php; (15) rss/index.php;
(16) stars/index.php; (17) users/remind_password.php; (18)
wiki/orphan_pages.php; and (19) stats/index.php, different vectors
than CVE-2007-0526 and CVE-2005-4379. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4336 |
Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo
Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web
script or HTML via the apa_album_ID parameter.
|
| CVE-2008-4333 |
Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus
allows remote attackers to inject arbitrary web script or HTML via the
isname parameter in a newtopic action.
|
| CVE-2008-4326 |
The PMA_escapeJsString function in libraries/js_escape.lib.php in
phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows
remote attackers to bypass cross-site scripting (XSS) protection
mechanisms and conduct XSS attacks via a NUL byte inside a "</script"
sequence.
|
| CVE-2008-4320 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before
1.5.94 allow remote attackers to inject arbitrary web script or HTML
via (1) the j_username parameter to j_acegi_security_check, (2) the
username parameter to notification/list.jsp, and (3) the filter
parameter to event/list.
|
| CVE-2008-4196 |
Cross-site scripting (XSS) vulnerability in Opera before 9.52 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-4184 |
Cross-site scripting (XSS) vulnerability in index.php in webCMS Portal
Edition allows remote attackers to inject arbitrary web script or HTML
via the patron parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-4182 |
Cross-site scripting (XSS) vulnerability in imp/test.php in Horde
Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and
possibly other Horde Project products, allows remote attackers to
inject arbitrary web script or HTML via the User field in an IMAP
session.
|
| CVE-2008-4179 |
Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow
remote attackers to inject arbitrary web script or HTML via the (1)
page_id parameter to smileys.php and the (2) q parameter to
search.php.
|
| CVE-2008-4174 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary
web script or HTML via the (1) currentpath, (2) invert, (3) search,
and (4) sort parameters.
|
| CVE-2008-4168 |
Cross-site scripting (XSS) vulnerability in verify_login.jsp in
Pro2col Stingray FTS allows remote attackers to inject arbitrary web
script or HTML via the form_username parameter (aka user name field).
|
| CVE-2008-4152 |
Cross-site scripting (XSS) vulnerability in the Talk module 5.x before
5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote
authenticated users to inject arbitrary web script or HTML via a node
title.
|
| CVE-2008-4149 |
Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to
Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated
users to inject arbitrary web script or HTML via the "Link page
header" field.
|
| CVE-2008-4147 |
Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x
before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via an e-mail
message with an attached file that has a modified Content-Type.
|
| CVE-2008-4140 |
Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart
3.1 allows remote attackers to inject arbitrary web script or HTML via
the query string.
|
| CVE-2008-4139 |
Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution
Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web
script or HTML via the query string.
|
| CVE-2008-4130 |
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6
allows remote attackers to inject arbitrary web script or HTML via a
crafted Flash animation, related to the ability of the animation to
"interact with the embedding page."
|
| CVE-2008-4121 |
Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce
before 1.2.4 allow remote attackers to inject arbitrary web script or
HTML via (1) the search parameter in a search.quick action to
search.php and (2) the name parameter in a sendtofriend action to
sendtofriend.php.
|
| CVE-2008-4120 |
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804
allow remote attackers to inject arbitrary web script or HTML via the
(1) user or (2) pass parameter to login.php, or the (3) name parameter
to contact.php.
|
| CVE-2008-4119 |
Multiple cross-site scripting (XSS) vulnerabilities in CA Service Desk
11.2 and CMDB 11.0 through 11.2 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors involving
"multiple web forms."
|
| CVE-2008-4118 |
Cross-site scripting (XSS) vulnerability in High Norm Sound Master 2nd
1.0 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-4089 |
Cross-site scripting (XSS) vulnerability in print.php in myPHPNuke
(MPN) before 1.8.8_8rc2 allows remote attackers to inject arbitrary
web script or HTML via the sid parameter.
|
| CVE-2008-4083 |
Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in
Brim 2.0 allows remote authenticated users to inject arbitrary web
script or HTML via the name parameter in an addItemPost action to
index.php. NOTE: some of these details are obtained from third party
information.
|
| CVE-2008-4079 |
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x
through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x
through 4.20, and 1.54 and earlier; and Movable Type Community
Solution allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2008-4076 |
Cross-site scripting (XSS) vulnerability in (1) Tor World Tor Board
1.3 and earlier, (2) Topics BBS 1.11 and earlier, (3) Simple BBS 1.86
and earlier, and (4) Interactive BBS 1.57 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, a different issue than CVE-2008-0917.
|
| CVE-2008-4066 |
Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows
remote attackers to bypass cross-site scripting (XSS) protection
mechanisms and conduct XSS attacks via HTML-escaped low surrogate
characters that are ignored by the HTML parser, as demonstrated by a
"jav�ascript" sequence, aka "HTML escaped low surrogates bug."
|
| CVE-2008-4065 |
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird
before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to
bypass cross-site scripting (XSS) protection mechanisms and conduct
XSS attacks via byte order mark (BOM) characters that are removed from
JavaScript code before execution, aka "Stripped BOM characters bug."
|
| CVE-2008-4056 |
Cross-site scripting (XSS) vulnerability in admin/login.php in
Matterdaddy Market 1.1 allows remote attackers to inject arbitrary web
script or HTML via the msg parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-4053 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote
attackers to inject arbitrary web script or HTML via the (1) param,
(2) cat_id, and (3) view parameters.
|
| CVE-2008-4051 |
Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart
Survey 1.0 allows remote attackers to inject arbitrary web script or
HTML via the sid parameter. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2008-4045 |
Multiple cross-site scripting (XSS) vulnerabilities in @Mail 5.42
allow remote attackers to inject arbitrary web script or HTML via the
(1) file and (2) HelpFile parameters to parse.php, the (3) Folder and
(4) start parameters to showmail.php, and the (5) abookview parameter
to abook.php.
|
| CVE-2008-4020 |
Cross-site scripting (XSS) vulnerability in Microsoft Office XP SP3
allows remote attackers to inject arbitrary web script or HTML via a
document that contains a "Content-Disposition: attachment" header and
is accessed through a cdo: URL, which renders the content instead of
raising a File Download dialog box, aka "Vulnerability in
Content-Disposition Header Vulnerability."
|
| CVE-2008-3968 |
Cross-site scripting (XSS) vulnerability in userlist.php in PunBB
before 1.2.20 allows remote attackers to inject arbitrary web script
or HTML via the p parameter.
|
| CVE-2008-3966 |
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka
MyBulletinBoard) before 1.4.1 allow remote attackers to inject
arbitrary web script or HTML via (1) a certain referrer field in
usercp2.php, (2) a certain location field in inc/functions_online.php,
and certain (3) tsubject and (4) psubject fields in moderation.php.
|
| CVE-2008-3948 |
SQL injection vulnerability in admin/users/self-2.php in XRMS allows
remote attackers to execute arbitrary SQL commands and modify name and
email fields via unspecified vectors.
|
| CVE-2008-3941 |
Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the page parameter in a search action to the default URI.
|
| CVE-2008-3937 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Media
Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject
arbitrary web script or HTML via the (1) user_id parameter in an edit
action to user_admin.php, the (2) title parameter to listings.php, and
the (3) redirect_url parameter to user_profile.php.
|
| CVE-2008-3935 |
Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and
earlier and shop_v52 2.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-3923 |
Multiple cross-site scripting (XSS) vulnerabilities in statistics.php
in Content Management Made Easy (CMME) 1.12 allow remote attackers to
inject arbitrary web script or HTML via the (1) page and (2) year
parameters in an hstat_year action.
|
| CVE-2008-3921 |
Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals
1.0 through 1.14 allow remote attackers to inject arbitrary web script
or HTML via the (1) month and (2) year parameter.
|
| CVE-2008-3917 |
Cross-site scripting (XSS) vulnerability in index.php in Ovidentia
6.6.5 allows remote attackers to inject arbitrary web script or HTML
via the field parameter in a search action.
|
| CVE-2008-3886 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
dotProject 2.1.2 allow remote attackers to inject arbitrary web script
or HTML via (1) the inactive parameter in a tasks action, (2) the date
parameter in a calendar day_view action, (3) the callback parameter in
a public calendar action, or (4) the type parameter in a ticketsmith
action.
|
| CVE-2008-3884 |
Cross-site scripting (XSS) vulnerability in Blogn (BURO GUN) 1.9.7 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, a different issue than CVE-2006-6176.
|
| CVE-2008-3881 |
Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder
1.23.3 and earlier allow remote attackers to inject arbitrary web
script or HTML via unspecified "zm_html_view_*.php" files.
|
| CVE-2008-3874 |
Cross-site scripting (XSS) vulnerability in account.php in Lussumo
Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated
users to inject arbitrary web script or HTML via the Value field (aka
Label ==> Value pairs). NOTE: some of these details are obtained from
third party information.
|
| CVE-2008-3860 |
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG
editors, (2) during local group creation, (3) during HTML redirects,
(4) in the HTML import, (5) in the Rich text editor, and (6) in
link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before
Hotfix 15 allow remote attackers to inject arbitrary web script or
HTML via unknown vectors, including (7) the Imported Page. NOTE: the
vulnerability in the WYSIWYG editors may exist because of an
incomplete fix for CVE-2008-2163.
|
| CVE-2008-3850 |
Cross-site scripting (XSS) vulnerability in Accellion File Transfer
FTA_7_0_135 allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to courier/forgot_password.html.
|
| CVE-2008-3849 |
Cross-site scripting (XSS) vulnerability in the calendar controller in
Civic Website Manager before 1.0.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, probably
involving (1) month, (2) day, and (3) year fields.
|
| CVE-2008-3847 |
Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook
(ANG) before 0.7.6 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-3846 |
Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2008-3843 |
Request Validation (aka the ValidateRequest filters) in ASP.NET in
Microsoft .NET Framework with the MS07-040 update does not properly
detect dangerous client input, which allows remote attackers to
conduct cross-site scripting (XSS) attacks, as demonstrated by a query
string containing a "<~/" (less-than tilde slash) sequence followed by
a crafted STYLE element.
|
| CVE-2008-3842 |
Request Validation (aka the ValidateRequest filters) in ASP.NET in
Microsoft .NET Framework without the MS07-040 update does not properly
detect dangerous client input, which allows remote attackers to
conduct cross-site scripting (XSS) attacks, as demonstrated by a query
string containing a "</" (less-than slash) sequence.
|
| CVE-2008-3841 |
Cross-site scripting (XSS) vulnerability in admin/search_links.php in
Freeway eCommerce 1.4.1.171 allows remote attackers to inject
arbitrary web script or HTML via the search_link parameter.
|
| CVE-2008-3824 |
Cross-site scripting (XSS) vulnerability in (1)
Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x
before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier
allows remote attackers to inject arbitrary web script or HTML by
using / (slash) characters as replacements for spaces in an HTML
e-mail message.
|
| CVE-2008-3823 |
Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in
the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers
to inject arbitrary web script or HTML via the filename of a MIME
attachment in an e-mail message.
|
| CVE-2008-3821 |
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server
in Cisco IOS 11.0 through 12.4 allow remote attackers to inject
arbitrary web script or HTML via (1) the query string to the ping
program or (2) unspecified other aspects of the URI.
|
| CVE-2008-3786 |
Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO
Photo Cart 3.9 allows remote attackers to inject arbitrary web script
or HTML via the qtitle parameter (aka "Gallery or event name" field)
in a search action.
|
| CVE-2008-3782 |
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php
in ACG-PTP 1.0.6 allow remote authenticated administrators to inject
arbitrary web script or HTML via the (1) Category name field under
Advertisement Packages, the (2) Reason field under Credit/Debit Users,
and the (3) FAQ question and (4) FAQ answer fields under Add New FAQ
Entry.
|
| CVE-2008-3781 |
Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-3779 |
Cross-site scripting (XSS) vulnerability in search/index.php in Five
Star Review Script allows remote attackers to inject arbitrary web
script or HTML via the words parameter in a search action.
|
| CVE-2008-3773 |
Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and
3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is
enabled, allows remote authenticated users to inject arbitrary web
script or HTML via a private message subject (aka newpm[title]).
|
| CVE-2008-3771 |
Cross-site scripting (XSS) vulnerability in members.php in Pars4u
Videosharing 1 allows remote attackers to inject arbitrary web script
or HTML via the PageNo parameter.
|
| CVE-2008-3758 |
Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla
1.1.4 and earlier (1) allow remote attackers to inject arbitrary web
script or HTML via the NewPassword parameter to people.php, and allow
remote authenticated users to inject arbitrary web script or HTML via
the (2) Account picture and (3) Icon fields in account.php. NOTE: some
of these details are obtained from third party information.
|
| CVE-2008-3741 |
The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4
trusts the MIME type sent by a web browser, which allows remote
authenticated users to conduct cross-site scripting (XSS) attacks by
uploading files containing arbitrary web script or HTML.
|
| CVE-2008-3740 |
Cross-site scripting (XSS) vulnerability in the output filter in
Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-3739 |
Cross-site scripting (XSS) vulnerability in (1) System Consultants
La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, possibly involving upload of files containing
XSS sequences.
|
| CVE-2008-3735 |
Cross-site scripting (XSS) vulnerability in index.php in PHPizabi
before 848 Core HotFix Pack 3 allows remote attackers to inject
arbitrary web script or HTML via the query parameter in a blogs.search
action.
|
| CVE-2008-3730 |
Cross-site scripting (XSS) vulnerability in Nordicwind Document
Management System (NOAH) before 3.2.2 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-3726 |
Cross-site scripting (XSS) vulnerability in Web Based Administration
in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote
attackers to inject arbitrary web script or HTML via the URI.
|
| CVE-2008-3715 |
Cross-site scripting (XSS) vulnerability in
inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and
earlier, when register_globals is enabled, allows remote attackers to
inject arbitrary web script or HTML via the PreviousColorsString
parameter.
|
| CVE-2008-3714 |
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8
allows remote attackers to inject arbitrary web script or HTML via the
query_string, a different vulnerability than CVE-2006-3681 and
CVE-2006-1945.
|
| CVE-2008-3712 |
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and
4.6.5, when register_globals is enabled, allow remote attackers to
inject arbitrary web script or HTML via the (1) query string to
mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php
and the (2) mosConfig_sitename parameter to
administrator/popups/index3pop.php.
|
| CVE-2008-3709 |
Multiple cross-site scripting (XSS) vulnerabilities in CyBoards PHP
Lite 1.21 allow remote attackers to inject arbitrary web script or
HTML via the (1) lOptionsOptions, (2) lNavAdminOptions, or (3)
lNavReturn parameter to options.php; or the (4) lNavReturn parameter
to subscribe.php.
|
| CVE-2008-3700 |
Multiple cross-site scripting (XSS) vulnerabilities in Kayako
SupportSuite 3.20.02 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) the sessionid parameter in a
livesupport startclientchat action to visitor/index.php; (2) the
filter parameter in a news view action to index.php; or the Full Name
field in a (3) account creation, (4) ticket opening, or (5) chat
request operation.
|
| CVE-2008-3679 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject
arbitrary web script or HTML via the catid parameter in a (1)
user_add, (2) recip, (3) tellafriend, or (4) contact action, or (5) in
a request without an action; or (6) the id parameter in a tellafriend
action. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-3678 |
Cross-site scripting (XSS) vulnerability in admin/search_links.php in
Freeway before 1.4.2.197 allows remote attackers to inject arbitrary
web script or HTML via the URL.
|
| CVE-2008-3668 |
Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt
Social Network module 3.2 rc1 for XOOPS allow remote attackers to
inject arbitrary web script or HTML via the uid parameter to (1)
friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5)
index.php, or (6) tribes.php; or (7) the description field of a new
scrap.
|
| CVE-2008-3664 |
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow
remote attackers to inject arbitrary web script or HTML via (1) the
real name field, related to the user list; (2) the target parameter to
login.php, (3) the title parameter to activities/some.php, (4) the
company_name parameter to companies/some.php, (5) the last_name
parameter to contacts/some.php, (6) the campaign_title parameter to
campaigns/some.php, (7) the opportunity_title parameter to
opportunities/some.php, (8) the case_title parameter to
cases/some.php, (9) the file_id parameter to files/some.php, or (10)
the starting parameter to reports/custom/mileage.php, a related issue
to CVE-2008-1129.
|
| CVE-2008-3650 |
Multiple unspecified vulnerabilities in Horde Groupware Webmail before
Edition 1.1.1 (final) have unknown impact and attack vectors related
to "unescaped output," possibly cross-site scripting (XSS), in the (1)
object browser and (2) contact view.
|
| CVE-2008-3622 |
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac
OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary
web script or HTML via an e-mail message that reaches a mailing-list
archive, aka "persistent JavaScript injection."
|
| CVE-2008-3596 |
Cross-site scripting (XSS) vulnerability in Harmoni before 1.4.7
allows remote attackers to inject arbitrary web script or HTML via the
Username field, which is inserted into logs that could be rendered
when viewed by an administrator.
|
| CVE-2008-3587 |
Cross-site scripting (XSS) vulnerability in result.php in Chris
Bunting Homes 4 Sale allows remote attackers to inject arbitrary web
script or HTML via the r parameter.
|
| CVE-2008-3581 |
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links
allows remote attackers to inject arbitrary web script or HTML via the
login_message parameter in a login action.
|
| CVE-2008-3574 |
Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2,
when register_globals is enabled, allow remote attackers to inject
arbitrary web script or HTML via the (1) lang_footer parameter to (a)
data/inc/footer.php; the (2) pluck_version, (3) lang_install22, (4)
titelkop, (5) lang_kop1, (6) lang_kop2, (7) lang_modules, (8)
lang_kop4, (9) lang_kop15, (10) lang_kop5, and (11) titelkop
parameters to (b) data/inc/header.php; the pluck_version and titelkop
parameters to (c) data/inc/header2.php; and the (14) lang_theme6
parameter to (d) data/inc/themeinstall.php.
|
| CVE-2008-3572 |
Cross-site scripting (XSS) vulnerability in index.php in Pligg 9.9.5
allows remote attackers to inject arbitrary web script or HTML via the
category parameter.
|
| CVE-2008-3569 |
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7,
when register_globals is enabled, allow remote attackers to inject
arbitrary web script or HTML via the text parameter to (1) iart.php
and (2) ming.php.
|
| CVE-2008-3567 |
Cross-zone scripting vulnerability in the NowPlaying functionality in
NullSoft Winamp before 5.541 allows remote attackers to conduct
cross-site scripting (XSS) attacks via an MP3 file with JavaScript in
id3 tags.
|
| CVE-2008-3566 |
Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7
allows remote attackers to inject arbitrary web script or HTML via the
acuparam parameter to (1) the default URI or (2) index.php, or (3) the
PATH_INFO to index.php. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-3565 |
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room
Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary
web script or HTML via the area parameter to (1) day.php, (2)
week.php, (3) month.php, (4) search.php, (5) report.php, and (6)
help.php. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-3560 |
Cross-site scripting (XSS) vulnerability in kshop_search.php in the
Kshop module 2.22 for Xoops allows remote attackers to inject
arbitrary web script or HTML via the search parameter.
|
| CVE-2008-3559 |
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice
allow remote attackers to inject arbitrary web script or HTML via the
(1) filename parameter to search.asp and the (2) page parameter to
order.asp. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-3550 |
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote
attackers to obtain potentially sensitive information (page source
code) via a combination of ?script? and ?/script? sequences in the id
field, possibly related to a cross-site scripting (XSS) vulnerability.
|
| CVE-2008-3516 |
Multiple cross-site scripting (XSS) vulnerabilities in files generated
by Adobe Presenter 6 and 7 before 7.0.1 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors involving
(1) viewer.swf and (2) loadflash.js, a different vulnerability than
CVE-2008-3515.
|
| CVE-2008-3515 |
Multiple cross-site scripting (XSS) vulnerabilities in files generated
by Adobe Presenter 6 and 7 before 7.0.1 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors involving
(1) viewer.swf and (2) loadflash.js, a different vulnerability than
CVE-2008-3516.
|
| CVE-2008-3511 |
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image
Gallery (Photo Gallery) allow remote attackers to inject arbitrary web
script or HTML via the (1) latest parameter to (a) index.php, (b)
images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2)
msg parameter to index.php, images.php, and suggest_image.php, and (e)
index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php,
(i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/.
NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-3510 |
Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty
Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject
arbitrary web script or HTML via the department parameter.
|
| CVE-2008-3505 |
Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the nr parameter to the default URI.
|
| CVE-2008-3501 |
Cross-site scripting (XSS) vulnerability in the WebAccess simple
interface in Novell Groupwise 7.0.x allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-3500 |
Cross-site scripting (XSS) vulnerability in the Suggested Terms module
5.x before 5.x-1.2 for Drupal allows remote authenticated users to
inject arbitrary web script or HTML via crafted Taxonomy terms.
|
| CVE-2008-3483 |
Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and
2.0.30 allows remote attackers to inject arbitrary web script or HTML
via error messages in the "/admin.aspx - System Log" page.
|
| CVE-2008-3482 |
Cross-site scripting (XSS) vulnerability in the error page feature in
Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531,
BB-HCM580, BB-HCM581, BB-HCM527, and BB-HCM515 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-3457 |
Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin
before 2.11.8 allows user-assisted remote attackers to inject
arbitrary web script or HTML via crafted setup arguments. NOTE: this
issue can only be exploited in limited scenarios in which the attacker
must be able to modify config/config.inc.php.
|
| CVE-2008-3448 |
Cross-site scripting (XSS) vulnerability in index.php in common
solutions csphonebook 1.02 allows remote attackers to inject arbitrary
web script or HTML via the letter parameter.
|
| CVE-2008-3422 |
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net
class libraries in Mono 2.0 and earlier allow remote attackers to
inject arbitrary web script or HTML via crafted attributes related to
(1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs
(RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4)
HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect
(RenderChildren).
|
| CVE-2008-3404 |
Cross-site scripting (XSS) vulnerability in guestbook.js.php in
MJGuest 6.8 GT allows remote attackers to inject arbitrary web script
or HTML via the link parameter.
|
| CVE-2008-3400 |
XRMS CRM 1.99.2 allows remote attackers to obtain configuration
information via a direct request to tests/info.php, which calls the
phpinfo function.
|
| CVE-2008-3399 |
PHP remote file inclusion vulnerability in
activities/workflow-activities.php in XRMS CRM 1.99.2, when
register_globals is enabled, allows remote attackers to execute
arbitrary PHP code via the include_directory parameter.
|
| CVE-2008-3398 |
Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2
allow remote attackers to inject arbitrary web script or HTML via the
msg parameter to unspecified components, possibly including login.php.
NOTE: this may overlap CVE-2008-1129.
|
| CVE-2008-3397 |
Cross-site scripting (XSS) vulnerability in Runesoft Cerberus CMS
before 3_1.4_0.9 allows remote attackers to inject arbitrary web
script or HTML via a cerberus_user cookie.
|
| CVE-2008-3394 |
Multiple cross-site scripting (XSS) vulnerabilities in search.cfm in
BookMine allow remote attackers to inject arbitrary web script or HTML
via the (1) gallery and (2) search_string parameters.
|
| CVE-2008-3391 |
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum
9.5 allow remote attackers to inject arbitrary web script or HTML via
the mode parameter to (1) admin_group_details.asp and (2)
admin_category_details.asp.
|
| CVE-2008-3381 |
Multiple cross-site scripting (XSS) vulnerabilities in
macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-3380 |
Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in
MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers
to inject arbitrary web script or HTML via the rs parameter.
|
| CVE-2008-3379 |
Cross-site scripting (XSS) vulnerability in Snark VisualPic 0.3.1
allows remote attackers to inject arbitrary web script or HTML via the
pic parameter to the default URI. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-3367 |
Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web
Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote
attackers to inject arbitrary web script or HTML via the email
parameter.
|
| CVE-2008-3358 |
Cross-site scripting (XSS) vulnerability in Web Dynpro (WD) in the SAP
NetWeaver portal, when Internet Explorer 7.0.5730 is used, allows
remote attackers to inject arbitrary web script or HTML via a crafted
URI, which causes the XSS payload to be reflected in a text/plain
document.
|
| CVE-2008-3353 |
Multiple cross-site scripting (XSS) vulnerabilities in Pure Software
Lore before 1.7.0 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors related to the (1) article
comments feature and the (2) search log feature.
|
| CVE-2008-3348 |
Cross-site scripting (XSS) vulnerability in
staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0
trial edition (tr) allows remote attackers to inject arbitrary web
script or HTML via the year parameter.
|
| CVE-2008-3347 |
SQL injection vulnerability in staticpages/easycalendar/index.php in
MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote
attackers to execute arbitrary SQL commands via the read parameter.
|
| CVE-2008-3345 |
SQL injection vulnerability in staticpages/easyecards/index.php in
MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a, when
magic_quotes_gpc is disabled, allows remote attackers to execute
arbitrary SQL commands via the sid parameter in a pickup action.
|
| CVE-2008-3344 |
Multiple cross-site scripting (XSS) vulnerabilities in
staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial
edition (tr) and 3.10a allow remote attackers to inject arbitrary web
script or HTML via the (1) ResultHtml, (2) dir, (3) SenderName, (4)
RecipientName, (5) SenderMail, and (6) RecipientMail parameters.
|
| CVE-2008-3343 |
SQL injection vulnerability in staticpages/easypublish/index.php in
MyioSoft EasyPublish 3.0tr (trial edition) allows remote attackers to
execute arbitrary SQL commands via the read parameter in a search
action.
|
| CVE-2008-3342 |
Cross-site scripting (XSS) vulnerability in
staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr allows
remote attackers to inject arbitrary web script or HTML via the read
parameter in an edp_News action.
|
| CVE-2008-3340 |
Cross-site scripting (XSS) vulnerability in search_result.cfm in
Jobbex JobSite allows remote attackers to inject arbitrary web script
or HTML via the searchFor variable (possibly the opt parameter.)
|
| CVE-2008-3336 |
Multiple cross-site scripting (XSS) vulnerabilities in PunBB before
1.2.19 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors in (1) include/parser.php and (2)
moderate.php.
|
| CVE-2008-3334 |
Cross-site scripting (XSS) vulnerability in MyBB 1.2.x before 1.2.14
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, possibly involving search.php.
|
| CVE-2008-3331 |
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php
in Mantis before 1.1.2 allows remote attackers to inject arbitrary web
script or HTML via the filter_target parameter.
|
| CVE-2008-3330 |
Cross-site scripting (XSS) vulnerability in
services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote
attackers to inject arbitrary web script or HTML via the contact name.
|
| CVE-2008-3328 |
Cross-site scripting (XSS) vulnerability in the wiki engine in Trac
before 0.10.5 allows remote attackers to inject arbitrary web script
or HTML via unknown vectors.
|
| CVE-2008-3326 |
Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle
1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to
inject arbitrary web script or HTML via the etitle parameter (blog
entry title).
|
| CVE-2008-3316 |
Cross-site scripting (XSS) vulnerability in the search feature in the
Forum plugin before 2.7.1 for Geeklog allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, probably
related to (1) public_html/index.php, (2) config.php, and (3)
functions.inc.
|
| CVE-2008-3315 |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline
1.8.10 allow remote attackers to inject arbitrary web script or HTML
via the (1) query string to (a) announcements/messages.php; (b)
lostPassword.php and (c) profile.php in auth/; (d)
calendar/myagenda.php; (e) group/group.php; (f) learningPath.php, (g)
learningPathList.php, and (h) module.php in learnPath/; (i)
phpbb/index.php; (j) courseLog.php, (k) course_access_details.php, (l)
delete_course_stats.php, (m) userLog.php, and (n)
user_access_details.php in tracking/; (o) user/user.php; and (p)
user/userInfo.php; the (2) view parameter to (q)
tracking/courseLog.php; and the (3) toolId parameter to (r)
tracking/toolaccess_details.php. NOTE: this may overlap CVE-2006-3257
and CVE-2005-1374.
|
| CVE-2008-3305 |
Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno
YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web
script or HTML via the m parameter.
|
| CVE-2008-3301 |
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1
allow remote authenticated administrators to inject arbitrary web
script or HTML via the (1) content parameter to admin/update.php,
related to conflicting code in widget.php; and allow remote attackers
to inject arbitrary web script or HTML via the (2) titleId parameter
to head.php, reachable through index.php; the (3)
t_lang[lang_copyright] parameter to footer.php; the (4) content
parameter to the default URI under admin/; the (5) url, (6)
t_lang[lang_admin_help], (7) t_lang[lang_admin_clear_cache], (8)
t_lang[lang_admin_home], and (9) t_lang[lang_admin_logout] parameters
to admin/homelink.php; and the (10) t_lang[lang_admin_new_post]
parameter to admin/post.php. NOTE: some of these details are obtained
from third party information.
|
| CVE-2008-3295 |
Cross-site scripting (XSS) vulnerability in modules/system/admin.php
in XOOPS 2.0.18.1 allows remote attackers to inject arbitrary web
script or HTML via the fct parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-3260 |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline
before 1.8.10 allow remote attackers to inject arbitrary web script or
HTML via (1) the cwd parameter in a rqMkHtml action to
document/rqmkhtml.php, or the query string to (2)
announcements/announcements.php, (3) calendar/agenda.php, (4)
course/index.php, (5) course_description/index.php, (6)
document/document.php, (7) exercise/exercise.php, (8)
group/group_space.php, (9) phpbb/newtopic.php, (10) phpbb/reply.php,
(11) phpbb/viewtopic.php, (12) wiki/wiki.php, or (13) work/work.php in
claroline/.
|
| CVE-2008-3255 |
Cross-site scripting (XSS) vulnerability in LunarNight Laboratory
WebProxy 1.7.8 and earlier allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-3253 |
Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces
in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0;
Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP
integrated Citrix XenServer (Select and Enterprise) 4.1.0 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-3237 |
Cross-site scripting (XSS) vulnerability in forward_to_friend.php in
ITechBids 7.0 Gold allows remote attackers to inject arbitrary web
script or HTML via the productid parameter.
|
| CVE-2008-3233 |
Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN
development versions only, allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-3219 |
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before
6.3 does not "prevent use of the object HTML tag in administrator
input," which has unknown impact and attack vectors, probably related
to an insufficient cross-site scripting (XSS) protection mechanism.
|
| CVE-2008-3218 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x
before 6.3 allow remote attackers to inject arbitrary web script or
HTML via vectors related to (1) free tagging taxonomy terms, which are
not properly handled on node preview pages, and (2) unspecified OpenID
values.
|
| CVE-2008-3202 |
Cross-site scripting (XSS) vulnerability in index.php in Xomol CMS 1.2
allows remote attackers to inject arbitrary web script or HTML via the
current_url parameter in a tellafriend action. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-3201 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Pagefusion 1.5 allow remote attackers to inject arbitrary web script
or HTML via the (1) acct_fname and (2) acct_lname parameters in an
edit action, and the (3) PID, (4) PGID, and (5) rez parameters. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-3186 |
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog
(Blogger) allow remote attackers to inject arbitrary web script or
HTML via the membername parameter to (1) members.php, (2)
comments.php, (3) photos.php, (4) archive.php, or (5) cat.php. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-3184 |
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin
3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow
remote attackers to inject arbitrary web script or HTML via (1) the
PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by
requests to upload/admincp/faq.php. NOTE: this issue can be leveraged
to execute arbitrary PHP code.
|
| CVE-2008-3180 |
Multiple cross-site scripting (XSS) vulnerabilities in
upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remote
attackers to inject arbitrary web script or HTML via the (1) pageid
parameter or (2) PATH_INFO.
|
| CVE-2008-3161 |
Multiple cross-site scripting (XSS) vulnerabilities in
jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote
attackers to inject arbitrary web script or HTML via the (1) Accept,
(2) Accept-Language, (3) UA-CPU, (4) Accept-Encoding, (5) User-Agent,
or (6) Cookie HTTP header. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-3130 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
OpenCart 0.7.7 allow remote attackers to inject arbitrary web script
or HTML via the (1) firstname and (2) search parameters. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-3121 |
Multiple cross-site scripting (XSS) vulnerabilities in Xerox
CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-3101 |
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM
5.0.4 allow remote attackers to inject arbitrary web script or HTML
via (1) the parenttab parameter in an index action to the Products
module, as reachable through index.php; (2) the user_password
parameter in an Authenticate action to the Users module, as reachable
through index.php; or (3) the query_string parameter in a
UnifiedSearch action to the Home module, as reachable through
index.php.
|
| CVE-2008-3100 |
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve
Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the username parameter in a getpasswd action to register.php.
|
| CVE-2008-3098 |
Cross-site scripting (XSS) vulnerability in admin/usercheck.php in
fuzzylime (cms) before 3.03 allows remote attackers to inject
arbitrary web script or HTML via the user parameter to the login form.
|
| CVE-2008-3097 |
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka
Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML, probably
by creating a crafted taxonomy term.
|
| CVE-2008-3095 |
Cross-site scripting (XSS) vulnerability in the Organic Groups (OG)
module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for
Drupal, allows remote authenticated users, with group owner
permissions, to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-3091 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Autotagger
module 5.x before 5.x-1.8 for Drupal allows remote authenticated
users, with create or edit post permissions, to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-3088 |
Cross-site scripting (XSS) vulnerability in the Files module in
Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject
arbitrary web script or HTML via the cid parameter in a Category
action to index.php.
|
| CVE-2008-3082 |
Cross-site scripting (XSS) vulnerability in
UPM/English/login/login.asp in Commtouch Enterprise Anti-Spam Gateway
4 and 5 allows remote attackers to inject arbitrary web script or HTML
via the PARAMS parameter.
|
| CVE-2008-3073 |
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.x before
1.1.5 and 1.0.x before 1.0.13 has unknown impact and attack vectors,
probably cross-site scripting (XSS), related to "use of the html-tag."
|
| CVE-2008-3069 |
Multiple cross-site scripting (XSS) vulnerabilities in MyBB before
1.2.13 allow remote attackers to inject arbitrary web script or HTML
via unspecified parameters to (1) portal.php and (2)
inc/functions_post.php.
|
| CVE-2008-3037 |
Cross-site scripting (XSS) vulnerability in the Address Directory
(sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-3032 |
Cross-site scripting (XSS) vulnerability in the phpMyAdmin
(phpmyadmin) extension 3.0.1 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-3029 |
Cross-site scripting (XSS) vulnerability in the WEC Discussion Forum
(wec_discussion) extension 1.6.2 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-3028 |
Multiple cross-site scripting (XSS) vulnerabilities in the Send-A-Card
(sr_sendcard) extension 2.2.2 and earlier for TYPO3 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-3023 |
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.6.2 and
earlier, and 3.6.3 dev3 and earlier development versions, when
Internet Explorer is used, allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, a different issue than
CVE-2005-1799.
|
| CVE-2008-2998 |
Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation
module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2997 |
Cross-site scripting (XSS) vulnerability in index.php in Gravity Board
X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web
script or HTML via the subject parameter in a postnewsubmit (aka
create new thread) action.
|
| CVE-2008-2994 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData
1.5.4 allow remote attackers to inject arbitrary web script or HTML
via the (1) annuaire parameter to (a) last_records.php and (b)
annuaire.php and the (2) by and (3) cat_id parameters to annuaire.php.
|
| CVE-2008-2991 |
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6
and 7 allows remote attackers to inject arbitrary web script or HTML
via vectors related to the Help Errors log.
|
| CVE-2008-2988 |
Unrestricted file upload vulnerability in admin/upload.php in Benja
CMS 0.1 allows remote attackers to upload and execute arbitrary PHP
files via unspecified vectors, followed by a direct request to the
file in billeder/.
|
| CVE-2008-2987 |
Multiple cross-site scripting (XSS) vulnerabilities in Benja CMS 0.1
allow remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to (1) admin_edit_submenu.php, (2) admin_new_submenu.php,
and (3) admin_edit_topmenu.php in admin/.
|
| CVE-2008-2984 |
Cross-site scripting (XSS) vulnerability in backend/umleitung.php in
CMReams CMS 1.3.1.1 Beta 2 allows remote attackers to inject arbitrary
web script or HTML via the lang[be_red_text] parameter.
|
| CVE-2008-2980 |
Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design
2.10 RC2 allow remote attackers to inject arbitrary web script or HTML
via the (1) error_meldung parameter to
admin/features/register/register.php, the (2)
feature_language[ueberschrift] parameter to
admin/features/memberlist/memberlist.php, the (3)
language_array[ueberschrift] parameter to
admin/features/lostpassword/lostpassword.php, the (4)
language_feature[titel] parameter to
admin/features/kalender/eingabe.php, and the (5)
language_feature[bildmenu] parameter to
admin/features/fotogalerie/eingabe.php.
|
| CVE-2008-2979 |
Multiple cross-site scripting (XSS) vulnerabilities in phpi/login.php
in Ourvideo CMS 9.5 allow remote attackers to inject arbitrary web
script or HTML via the (1) top_page and (2) end_page parameters.
|
| CVE-2008-2975 |
Cross-site scripting (XSS) vulnerability in
admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to
inject arbitrary web script or HTML via the language parameter.
|
| CVE-2008-2973 |
Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in
MM Chat 1.5 allow remote attackers to inject arbitrary web script or
HTML via the (1) sitename and (2) wmessage parameters.
|
| CVE-2008-2967 |
Multiple cross-site scripting (XSS) vulnerabilities in Academic Web
Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote
attackers to inject arbitrary web script or HTML via the (1) query
string to login.php and the (2) glb_sid parameter to
hta/htmlarea.js.php, and allow remote authenticated users to inject
arbitrary web script or HTML via an unspecified field in room.php.
|
| CVE-2008-2965 |
Cross-site scripting (XSS) vulnerability in viewforum.php in
JaxUltraBB (JUBB) 2.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the forum parameter.
|
| CVE-2008-2962 |
Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow
remote attackers to inject arbitrary web script or HTML via the (1) s
and (2) sort parameters to index.php, and the (3) id parameter to
post.php.
|
| CVE-2008-2960 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7,
when register_globals is enabled and .htaccess support is disabled,
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors involving scripts in libraries/.
|
| CVE-2008-2939 |
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the
mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c
in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions,
allows remote attackers to inject arbitrary web script or HTML via a
wildcard in the last directory component in the pathname in an FTP
URI.
|
| CVE-2008-2929 |
Multiple cross-site scripting (XSS) vulnerabilities in the adminutil
library in the Directory Server Administration Express and Directory
Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1
before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow
remote attackers to inject arbitrary web script or HTML via input
values that use % (percent) escaping.
|
| CVE-2008-2924 |
Cross-site scripting (XSS) vulnerability in Webmatic before 2.8 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-2923 |
Cross-site scripting (XSS) vulnerability in read/search/results in
Lyris ListManager 8.8, 8.95, and 9.3d allows remote attackers to
inject arbitrary web script or HTML via the words parameter.
|
| CVE-2008-2911 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Contenido 4.8.4 allow remote attackers to inject arbitrary web script
or HTML via the (1) contenido, (2) Belang, and (3) username
parameters.
|
| CVE-2008-2879 |
Benja CMS 0.1 does not require authentication for access to admin/,
which allows remote attackers to add or delete a menu.
|
| CVE-2008-2871 |
Multiple cross-site scripting (XSS) vulnerabilities in template2.php
in PEGames allow remote attackers to inject arbitrary web script or
HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt
parameters. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-2861 |
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio
Site Composer (ESC) 2.6 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) topic and (2) button
parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to
login.asp.
|
| CVE-2008-2855 |
Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3
allows remote attackers to inject arbitrary web script or HTML via the
id parameter.
|
| CVE-2008-2852 |
Cross-site scripting (XSS) vulnerability in CGIWrap before 4.1, when
an Internet Explorer based browser is used, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors related to
failure to set the charset in error messages.
|
| CVE-2008-2849 |
Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x
before 5.x-1.4 for Drupal allows remote authenticated users, with
create post permissions, to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-2848 |
Cross-site scripting (XSS) vulnerability in the search functionality
in MindTouch DekiWiki before 8.05.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2842 |
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in
doITLive CMS 2.50 and earlier allows remote attackers to inject
arbitrary web script or HTML via the FILE parameter.
|
| CVE-2008-2839 |
Cross-site scripting (XSS) vulnerability in the search module in
Traindepot 0.1 allows remote attackers to inject arbitrary web script
or HTML via the query parameter to index.php.
|
| CVE-2008-2831 |
Multiple cross-site scripting (XSS) vulnerabilities in the delegated
spam management feature in the Spam Quarantine Management (SQM)
component in MailMarshal SMTP 6.0.3.8 through 6.3.0.0 allow
user-assisted remote authenticated users to inject arbitrary web
script or HTML via (1) the list of blocked senders or (2) the list of
safe senders.
|
| CVE-2008-2825 |
Cross-site scripting (XSS) vulnerability in the embedded Web Server in
Xerox WorkCentre M123, M128, and 133 and WorkCentre Pro 123, 128, and
133 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-2814 |
Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast
Admin Panel 2.0 allows remote attackers to inject arbitrary web script
or HTML via the username parameter to the login interface. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-2808 |
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not
properly escape HTML in file:// URLs in directory listings, which
allows remote attackers to conduct cross-site scripting (XSS) attacks
or have unspecified other impact via a crafted filename.
|
| CVE-2008-2800 |
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow
remote attackers to bypass the Same Origin Policy and conduct
cross-site scripting (XSS) attacks via vectors involving (1) an event
handler attached to an outer window, (2) a SCRIPT element in an
unloaded document, or (3) the onreadystatechange handler in
conjunction with an XMLHttpRequest.
|
| CVE-2008-2797 |
Cross-site scripting (XSS) vulnerability in MainLayout.do in
ManageEngine OpUtils 5.0 allows remote attackers to inject arbitrary
web script or HTML via the hostName parameter, when viewing an SNMP
graph. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-2788 |
Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan
1.2.5 allows remote attackers to inject arbitrary web script or HTML
via the redirection parameter.
|
| CVE-2008-2787 |
Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan
1.2.5 allows remote attackers to inject arbitrary web script or HTML
via the last_message parameter.
|
| CVE-2008-2783 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde
Groupware, Groupware Webmail Edition, and Kronolith allow remote
attackers to inject arbitrary web script or HTML via the timestamp
parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4)
the horde parameter in the PATH_INFO to the default URI. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-2777 |
Cross-site scripting (XSS) vulnerability in Ortro before 1.3.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-2776 |
Cross-site scripting (XSS) vulnerability in search.asp in DT
Centrepiece 4.0 allows remote attackers to inject arbitrary web script
or HTML via the searchFor parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-2773 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Image module
5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-2768 |
Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla
Poll Manager XE allows remote authenticated users with administrator
role privileges to inject arbitrary web script or HTML via unspecified
vectors ("all fields").
|
| CVE-2008-2766 |
Cross-site scripting (XSS) vulnerability in Xigla Absolute Image
Gallery XE allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors in (1) admin/search.asp and (2)
gallery.asp.
|
| CVE-2008-2764 |
Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla
Absolute Live Support XE 5.1 allows remote authenticated
administrators to inject arbitrary web script or HTML via unspecified
vectors ("all fields").
|
| CVE-2008-2761 |
Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute
Banner Manager XE 2.0 allow remote authenticated administrators to
inject arbitrary web script or HTML via the text parameter in (1)
searchbanners.asp and (2) listadvertisers.asp, and other unspecified
fields. NOTE: some of these details are obtained from third party
information.
|
| CVE-2008-2759 |
Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute
Form Processor XE 4.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) showfields, (2) text, and (3) submissions
parameters to search.asp and the (4) name parameter to users.asp.
NOTE: some of these details are obtained from third party information.
|
| CVE-2008-2758 |
Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute
News Manager XE 3.2 allow remote authenticated administrators to
inject arbitrary web script or HTML via the (1) pblname and (2) text
parameters to (a) admin/search.asp, (3) name parameter to (b)
admin/publishers.asp, and other unspecified vectors to (c)
anmviewer.asp and (d) editarticleX.asp in admin/. NOTE: some of these
details are obtained from third party information.
|
| CVE-2008-2756 |
Cross-site scripting (XSS) vulnerability in admin/users.asp in Xigla
Absolute Control Panel XE 1.0 allows remote attackers to inject
arbitrary web script or HTML via the name parameter and other
unspecified parameters. NOTE: some of these details are obtained from
third party information.
|
| CVE-2008-2751 |
Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish
webadmin interface in Sun Java System Application Server 9.1_01 allow
remote attackers to inject arbitrary web script or HTML via the (1)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew,
(2)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType,
(3)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass,
or (4)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc
parameter to (a) resourceNode/customResourceNew.jsf; the (5)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew,
(6)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType,
(7)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass,
(8)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiLookupProp:jndiLookup,
or (9)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc
parameter to (b) resourceNode/externalResourceNew.jsf; the (10)
propertyForm:propertySheet:propertSectionTextField:jndiProp:Jndi, (11)
propertyForm:propertySheet:propertSectionTextField:nameProp:name, or
(12) propertyForm:propertySheet:propertSectionTextField:descProp:desc
parameter to (c) resourceNode/jmsDestinationNew.jsf; the (13)
propertyForm:propertySheet:generalPropertySheet:jndiProp:Jndi or (14)
propertyForm:propertySheet:generalPropertySheet:descProp:cd parameter
to (d) resourceNode/jmsConnectionNew.jsf; the (15)
propertyForm:propertySheet:propertSectionTextField:jndiProp:jnditext
or (16)
propertyForm:propertySheet:propertSectionTextField:descProp:desc
parameter to (e) resourceNode/jdbcResourceNew.jsf; the (17)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:nameProp:name,
(18)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:classNameProp:classname,
or (19)
propertyForm:propertyContentPage:propertySheet:propertSectionTextField:loadOrderProp:loadOrder
parameter to (f) applications/lifecycleModulesNew.jsf; or the (20)
propertyForm:propertyContentPage:propertySheet:generalPropertySheet:jndiProp:name,
(21)
propertyForm:propertyContentPage:propertySheet:generalPropertySheet:resTypeProp:resType,
or (22)
propertyForm:propertyContentPage:propertySheet:generalPropertySheet:dbProp:db
parameter to (g) resourceNode/jdbcConnectionPoolNew1.jsf.
|
| CVE-2008-2744 |
Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors and an "obscure method." NOTE: the vector is probably
in the redirect parameter to the Admin Control Panel
(admincp/index.php).
|
| CVE-2008-2743 |
Cross-site scripting (XSS) vulnerability in the embedded web server in
Xerox 4110, 4590, and 4595 Copier/Printers allows remote attackers to
inject arbitrary web script or HTML via unknown attack vectors.
|
| CVE-2008-2720 |
Cross-site scripting (XSS) vulnerability in Menalto Gallery before
2.2.5 allows remote attackers to inject arbitrary web script or HTML
via the (1) host and (2) path components of a URL.
|
| CVE-2008-2718 |
Cross-site scripting (XSS) vulnerability in fe_adminlib.inc in TYPO3
4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, as
used in extensions such as (1) direct_mail_subscription, (2)
feuser_admin, and (3) kb_md5fepw, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2698 |
Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php
(aka the "add comment" section) in WEBalbum 2.0 and earlier allow
remote attackers to inject arbitrary web script or HTML via the (1)
comment, (2) id, or (3) category parameter.
|
| CVE-2008-2694 |
Cross-site scripting (XSS) vulnerability in search.php in phpInv 0.8.0
allows remote attackers to inject arbitrary web script or HTML via the
keyword parameter.
|
| CVE-2008-2680 |
Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp
in Realm CMS 2.3 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) CmpctedDB and (2) Boyut
parameters.
|
| CVE-2008-2677 |
Cross-site scripting (XSS) vulnerability in edit1.php in Telephone
Directory 2008 allows remote attackers to inject arbitrary web script
or HTML via the action parameter.
|
| CVE-2008-2675 |
Cross-site scripting (XSS) vulnerability in index.php in PHP Image
Gallery allows remote attackers to inject arbitrary web script or HTML
via the action parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-2668 |
Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2
allow remote attackers to inject arbitrary web script or HTML via (1)
the q parameter to search.php, or the n parameter to (2) user.php or
(3) uss.php.
|
| CVE-2008-2652 |
Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b
and 1.4f allow remote attackers to execute arbitrary SQL commands via
the (1) idp and (2) category parameters.
|
| CVE-2008-2646 |
Multiple cross-site scripting (XSS) vulnerabilities in meBiblio 0.4.7
allow remote attackers to inject arbitrary web script or HTML via the
(1) sql parameter to dbadd.inc.php, (2) InsertJournal parameter to
add_journal_mask.inc.php, (3) InsertBibliography parameter to
insert_mask.inc.php, and (4) LabelYear parameter to
search_mask.inc.php.
|
| CVE-2008-2644 |
Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and
1.4f allow remote attackers to inject arbitrary web script or HTML via
the (1) data parameter to catalog.php, the (2) keyword parameter to
search.php, the (3) page parameter to bb.php, and the (4) new_s
parameter to order.php.
|
| CVE-2008-2640 |
Multiple cross-site scripting (XSS) vulnerabilities in the Flex 3
History Management feature in Adobe Flex 3.0.1 SDK and Flex Builder 3,
and generated applications, allow remote attackers to inject arbitrary
web script or HTML via the anchor identifier to (1)
client-side-detection-with-history/history/historyFrame.html, (2)
express-installation-with-history/history/historyFrame.html, or (3)
no-player-detection-with-history/history/historyFrame.html in
templates/html-templates/. NOTE: Firefox 2.0 and possibly other
browsers prevent exploitation.
|
| CVE-2008-2637 |
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL
VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote
attackers to inject arbitrary web script or HTML via quotes in (1) the
css_exceptions parameter in vdesk/admincon/webyfiers.php and (2) the
sql_matchscope parameter in vdesk/admincon/index.php.
|
| CVE-2008-2603 |
Unspecified vulnerability in the Resource Manager component in Oracle
Database 10.1.0.5, 10.2.0.4, and 11.1.0.6, and Database Control in
Enterprise Manager, has unknown impact and remote authenticated attack
vectors. NOTE: the previous information was obtained from the Oracle
July 2008 CPU. Oracle has not commented on reliable researcher claims
that this is a cross-site scripting (XSS) issue that allows remote
attackers to inject arbitrary web script or HTML via the REFRESHCHOICE
parameter in multiple web pages.
|
| CVE-2008-2567 |
Cross-site scripting (XSS) vulnerability in Fenriru Sleipnir 2.7.1
Release2 and earlier, Portable Sleipnir 2.7.1 Release2 and earlier,
and Grani 3.1 and earlier allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors related to a history
mechanism and favorites search, a different vulnerability than
CVE-2007-6002.
|
| CVE-2008-2566 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address
Book 3.1.5 and earlier allow remote attackers to inject arbitrary web
script or HTML via the group parameter to (1) index.php or (2) the
default URI.
|
| CVE-2008-2563 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
dsp_main.php and (2) dsp_task_editor.php in SamTodo 1.1 allow remote
attackers to inject arbitrary web script or HTML via the (a) tid
parameter in a main.taskeditor edit action, and the (b) completed
parameter in a main.default action, to index.php.
|
| CVE-2008-2561 |
Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) PATH_INFO to (a) register.php, (b) reminder.php, and (c)
search.php; the (2) uname, (3) email, and (4) email2 parameters to
register.php; the (5) email parameter to reminder.php; and the (6)
keywords parameter to search.php.
|
| CVE-2008-2557 |
Cross-site scripting (XSS) vulnerability in CRE Loaded 6.2.13.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the (1) Links and (2) Links Submit pages.
|
| CVE-2008-2553 |
Cross-site scripting (XSS) vulnerability in Slashdot Like Automated
Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
userfield parameter.
|
| CVE-2008-2533 |
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View
CMS Pre Alpha2 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) ltarget parameter to (a)
admin/admin_frame.php and the (2) conf parameter to (b)
gbuch.admin.php, (c) links.admin.php, (d) menue.admin.php, (e)
news.admin.php, and (f) todo.admin.php in admin/module/.
|
| CVE-2008-2531 |
Cross-site scripting (XSS) vulnerability in the search script in Build
A Niche Store (BANS) 3.0 allows remote attackers to inject arbitrary
web script or HTML via the q parameter.
|
| CVE-2008-2527 |
Cross-site scripting (XSS) vulnerability in view.php in ActualScripts
ActualAnalyzer Server 8.37 and earlier, ActualAnalyzer Gold 7.74 and
earlier, ActualAnalyzer Pro 6.95 and earlier, and ActualAnalyzer Lite
2.78 and earlier allows remote attackers to inject arbitrary web
script or HTML via the language parameter.
|
| CVE-2008-2526 |
Cross-site scripting (XSS) vulnerability in the WT Gallery (aka
wt_gallery) extension 2.6.2 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-2525 |
Cross-site scripting (XSS) vulnerability in the Event Database (aka
rlmp_eventdb) extension before 1.1.2 for TYPO3 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2518 |
Cross-site scripting (XSS) vulnerability in the advanced search
mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server
6.1 before SP9 and 7.0 before Update 3 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, probably
related to the next parameter.
|
| CVE-2008-2508 |
Cross-site scripting (XSS) vulnerability in news.php in Tr Script News
2.1 allows remote attackers to inject arbitrary web script or HTML via
the "nb" parameter in voir mode.
|
| CVE-2008-2507 |
Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear
Software Calcium 3.10 and 4.0.4 allows remote attackers to inject
arbitrary web script or HTML via the CalendarName parameter in a
ShowIt action.
|
| CVE-2008-2505 |
Cross-site scripting (XSS) vulnerability in result.php in Simpel Side
Weblosning 1 through 4 allows remote attackers to inject arbitrary web
script or HTML via the search parameter.
|
| CVE-2008-2500 |
Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor
(MOStlyCE) component before 3.0 for Mambo allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2496 |
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4
allow remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to (1) index.php, (2) login.php, and (3) credits.php in
admin/, and (4) upgrade/index.php.
|
| CVE-2008-2495 |
Directory traversal vulnerability in index.php in Zina 1.0 RC3 allows
remote attackers to have an unknown impact via a .. (dot dot) in the p
parameter.
|
| CVE-2008-2494 |
Cross-site scripting (XSS) vulnerability in index.php in Zina 1.0 RC3
allows remote attackers to inject arbitrary web script or HTML via the
l parameter.
|
| CVE-2008-2493 |
Cross-site scripting (XSS) vulnerability in post3/Book.asp in Campus
Bulletin Board 3.4 allows remote attackers to inject arbitrary web
script or HTML via the review parameter.
|
| CVE-2008-2490 |
Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2
(aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified "user input."
|
| CVE-2008-2485 |
Cross-site scripting (XSS) vulnerability in the URL redirection script
(inc/url_redirection.inc.php) in PCPIN Chat before 6.11 allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-2462 |
Cross-site scripting (XSS) vulnerability in the viewfile documentation
command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows
remote attackers to inject arbitrary web script or HTML via the file
parameter.
|
| CVE-2008-2458 |
Cross-site scripting (XSS) vulnerability in index.php in Starsgames
Control Panel 4.6.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the st parameter.
|
| CVE-2008-2452 |
Cross-site scripting (XSS) vulnerability in the Questionaire (aka
pbsurvey) extension 1.2.0 and earlier for TYPO3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-2450 |
Multiple cross-site scripting (XSS) vulnerabilities in the Statistics
(aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-2449 |
Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan
phpInstantGallery 2.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) gallery parameter to (a) index.php and (b)
image.php, and the (2) imgnum parameter to image.php. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-2445 |
Cross-site scripting (XSS) vulnerability in profile.php in Web Group
Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allows
remote attackers to inject arbitrary web script or HTML via the userid
parameter in a show action.
|
| CVE-2008-2421 |
Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web
Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA),
and Web Dynpro for BSP allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO to the default URI under
bc/gui/sap/its/webgui/.
|
| CVE-2008-2414 |
Cross-site scripting (XSS) vulnerability in send_email.php in AN
Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web
script or HTML via the postid parameter.
|
| CVE-2008-2413 |
Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News
0.9.1 allows remote attackers to inject arbitrary web script or HTML
via the id parameter.
|
| CVE-2008-2410 |
Cross-site scripting (XSS) vulnerability in the servlet engine and Web
container in the Web Server service in IBM Lotus Domino before 7.0.3
FP1, and 8.x before 8.0.1, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2398 |
Cross-site scripting (XSS) vulnerability in index.php in AppServ Open
Project 2.5.10 and earlier allows remote attackers to inject arbitrary
web script or HTML via the appservlang parameter.
|
| CVE-2008-2397 |
Cross-site scripting (XSS) vulnerability in search-results.dot in
dotCMS 1.x allows remote attackers to inject arbitrary web script or
HTML via the search_query parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-2379 |
Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17
allows remote attackers to inject arbitrary web script or HTML via a
crafted hyperlink in an HTML part of an e-mail message.
|
| CVE-2008-2344 |
Cross-site scripting (XSS) vulnerability in the air_filemanager 0.6.0
and earlier extension for TYPO3 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2335 |
Cross-site scripting (XSS) vulnerability in search_results.php in
Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject
arbitrary web script or HTML via the query parameter. NOTE: some of
these details are obtained from third party information. NOTE: it was
later reported that 1.2.3 is also affected.
|
| CVE-2008-2333 |
Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda
Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to
inject arbitrary web script or HTML via the email parameter.
|
| CVE-2008-2302 |
Cross-site scripting (XSS) vulnerability in the login form in the
administration application in Django 0.91 before 0.91.2, 0.95 before
0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject
arbitrary web script or HTML via the URI of a certain previous
request.
|
| CVE-2008-2295 |
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard
3.0.12, and possibly earlier versions, allows remote attackers to
inject arbitrary web script or HTML via the s_text parameter and other
unspecified vectors.
|
| CVE-2008-2280 |
Cross-site scripting (XSS) vulnerability in admin/index.php in Script
PHP PicEngine 1.0 allows remote attackers to inject arbitrary web
script or HTML via the l parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-2274 |
Cross-site scripting (XSS) vulnerability in the sr_feuser_register
1.4.0, 1.6.0, 2.2.1 to 2.2.7, 2.3.0 to 2.3.6, 2.4.0, and 2.5.0 to
2.5.9 extension for TYPO3 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-2272 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x,
2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2268 |
Open redirect vulnerability in interface/redirect.htm.php in Mjguest
6.7 GT Rev.01 allows user-assisted remote attackers to redirect users
to arbitrary web sites and conduct phishing attacks via a URL in the
goto parameter in a redirect action to mjguest.php. NOTE: this is
user-assisted because there is a delay and a notification before
redirection occurs.
|
| CVE-2008-2264 |
Cross-site scripting (XSS) vulnerability in index.php in CyrixMED 1.4
allows remote attackers to inject arbitrary web script or HTML via the
msg_erreur parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-2248 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
for Exchange Server 2003 SP2 allows remote attackers to inject
arbitrary web script or HTML via unspecified HTML, a different
vulnerability than CVE-2008-2247.
|
| CVE-2008-2247 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
for Exchange Server 2003 SP2 allows remote attackers to inject
arbitrary web script or HTML via unspecified e-mail fields, a
different vulnerability than CVE-2008-2248.
|
| CVE-2008-2236 |
Cross-site scripting (XSS) vulnerability in blosxom.cgi in Blosxom
before 2.1.2 allows remote attackers to inject arbitrary web script or
HTML via the flav parameter (flavour variable). NOTE: some of these
details are obtained from third party information.
|
| CVE-2008-2219 |
Cross-site scripting (XSS) vulnerability in install.php in C-News.fr
C-News 1.0.1 allows remote attackers to inject arbitrary web script or
HTML via the etape parameter.
|
| CVE-2008-2213 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/inc/footer.php in Maian Links 3.1 allow remote attackers to
inject arbitrary web script or HTML via the (1) msg_script2 and (2)
msg_script3 parameters.
|
| CVE-2008-2212 |
Multiple cross-site scripting (XSS) vulnerabilities in Maian Cart 1.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) msg_adminheader, (2) msg_adminheader2, (3) msg_adminheader3, (4)
msg_adminheader4, and unspecified other parameters to
admin/inc/header.php; the (5) msg_script3 and unspecified other
parameters to admin/inc/footer.php; and the (6) keywords parameter to
index.php in a search action.
|
| CVE-2008-2211 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/inc/footer.php in Maian Guestbook 3.2 allow remote attackers to
inject arbitrary web script or HTML via the (1) msg_script2 and (2)
msg_script3 parameters.
|
| CVE-2008-2210 |
Multiple cross-site scripting (XSS) vulnerabilities in Maian Support
1.3 allow remote attackers to inject arbitrary web script or HTML via
the (1) msg_script, (2) msg_script2, and (3) msg_script3 parameters to
admin/inc/footer.php; and the (4) msg_script2 parameter to
admin/inc/header.php.
|
| CVE-2008-2209 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/inc/header.php in Maian Greeting 2.1 allow remote attackers to
inject arbitrary web script or HTML via the (1) msg_script and (2)
msg_script2 parameters.
|
| CVE-2008-2208 |
SQL injection vulnerability in index.php in Maian Greeting 2.1 allows
remote attackers to execute arbitrary SQL commands via the keywords
parameter in a search action.
|
| CVE-2008-2207 |
Cross-site scripting (XSS) vulnerability in admin/index.php in Maian
Gallery 2.0 allows remote attackers to inject arbitrary web script or
HTML via the keywords parameter in a search action.
|
| CVE-2008-2206 |
Multiple cross-site scripting (XSS) vulnerabilities in Maian Music 1.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) keywords parameter in a search action to index.php, and the (2)
msg_script parameter to admin/inc/footer.php.
|
| CVE-2008-2205 |
SQL injection vulnerability in index.php in Maian Music 1.1 allows
remote attackers to execute arbitrary SQL commands via the album
parameter in an album action.
|
| CVE-2008-2204 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/inc/header.php in Maian Search 1.1 allow remote attackers to
inject arbitrary web script or HTML via the (1) header, (2) header2,
(3) header3, (4) header4, (5) header5, (6) header6, (7) header7, (8)
header8, and (9) header9 parameters.
|
| CVE-2008-2203 |
SQL injection vulnerability in search.php in Maian Search 1.1 allows
remote attackers to execute arbitrary SQL commands via the keywords
parameter in a search action.
|
| CVE-2008-2202 |
Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader
4.0 allow remote attackers to inject arbitrary web script or HTML via
the (1) keywords parameter to upload/admin/index.php in a search
action, the (2) msg_charset and (3) msg_header9 parameters to
admin/inc/header.php, and the (4) keywords parameter to index.php in a
search action.
|
| CVE-2008-2201 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/inc/header.php in Maian Recipe 1.2 allow remote attackers to
inject arbitrary web script or HTML via the (1) header, (2) header2,
(3) header3, (4) header4, (5) header5, (6) header6, (7) header7, (8)
header8, and (9) header9 parameters.
|
| CVE-2008-2200 |
Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog
4.0 allow remote attackers to inject arbitrary web script or HTML via
the (1) keywords parameter to admin/index.php in a blogs search
action, the (2) msg_charset and (3) msg_header9 parameters to
admin/inc/header.php, and the (4) keywords parameter to index.php in a
search action.
|
| CVE-2008-2196 |
Cross-site scripting (XSS) vulnerability in admin.php in LifeType
1.2.8 allows remote attackers to inject arbitrary web script or HTML
via the newBlogUserName parameter in an addBlogUser action, a
different vector than CVE-2008-2178.
|
| CVE-2008-2188 |
Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook
1.0 allow remote attackers to inject arbitrary web script or HTML via
the (1) bookCopyright and (2) ver parameters to (a) footer.php, and
the (3) bookName, (4) bookMetaTags, and (5) estiloCSS parameters to
(b) header.php.
|
| CVE-2008-2187 |
Cross-site scripting (XSS) vulnerability in mjguest.php in Mjguest 6.7
GT Rev.01 allows remote attackers to inject arbitrary web script or
HTML via the level parameter in a redirect action, possibly involving
interface/redirect.htm.php.
|
| CVE-2008-2186 |
Cross-site scripting (XSS) vulnerability in index.php in Chilek
Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers
to inject arbitrary web script or HTML via the q parameter.
|
| CVE-2008-2182 |
Cross-site scripting (XSS) vulnerability in the powermail extension
before 1.1.10 for TYPO3 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-2181 |
Multiple cross-site scripting (XSS) vulnerabilities in search.php in
cpLinks 1.03 allow remote attackers to inject arbitrary web script or
HTML via the (1) search_text and (2) search_category parameters. NOTE:
the XSS reportedly occurs in a forced SQL error message. NOTE: some of
these details are obtained from third party information.
|
| CVE-2008-2179 |
Cross-site scripting (XSS) vulnerability in SystemList.jsp in SysAid
5.1.08 allows remote attackers to inject arbitrary web script or HTML
via the searchField parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-2178 |
Cross-site scripting (XSS) vulnerability in admin.php in LifeType
1.2.7 allows remote attackers to inject arbitrary web script or HTML
via the searchTerms parameter in an editArticleCategories operation
(aka an admin category search).
|
| CVE-2008-2176 |
Cross-site scripting (XSS) vulnerability in admin/category.php in
Zomplog 3.8.2 allows remote attackers to inject arbitrary web script
or HTML via the catname parameter.
|
| CVE-2008-2168 |
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier
allows remote attackers to inject arbitrary web script or HTML via
UTF-7 encoded URLs that are not properly handled when displaying the
403 Forbidden error page.
|
| CVE-2008-2167 |
Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows
remote attackers to inject arbitrary web script or HTML via the
Referer header, which is not properly handled in a 404 Error page.
|
| CVE-2008-2166 |
Cross-site scripting (XSS) vulnerability in the search module in Sun
Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows
remote attackers to inject arbitrary web script or HTML via unknown
parameters in index.jsp.
|
| CVE-2008-2165 |
Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in
Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3
allows remote attackers to inject arbitrary web script or HTML via the
msg parameter.
|
| CVE-2008-2163 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1
before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS,
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors related to "WYSIWYG editors."
|
| CVE-2008-2162 |
Cross-site scripting (XSS) vulnerability in SonicWall Email Security
6.1.1 allows remote attackers to inject arbitrary web script or HTML
via the Host header in a request to a non-existent web page, which is
not properly sanitized in an error page.
|
| CVE-2008-2133 |
Cross-site scripting (XSS) vulnerability in the Journal module in
Tru-Zone Nuke ET 3.x allows remote attackers to inject arbitrary web
script or HTML via the title parameter in a new entry, as demonstrated
by a CSS property in the STYLE attribute of a DIV element, a different
vulnerability than CVE-2008-1873.
|
| CVE-2008-2131 |
Cross-site scripting (XSS) vulnerability in mvnForum 1.1 GA allows
remote authenticated users to inject arbitrary web script or HTML via
the topic field, which is later displayed by user/viewthread.jsp
through use of the "quick reply button."
|
| CVE-2008-2127 |
Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon
2.2 Ultimate allows remote attackers to inject arbitrary web script or
HTML via the what parameter. NOTE: some of these details are obtained
from third party information.
|
| CVE-2008-2126 |
Multiple cross-site scripting (XSS) vulnerabilities in Tux CMS 0.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) q parameter to index.php and the (2) returnURL parameter to
tux-login.php.
|
| CVE-2008-2123 |
Cross-site scripting (XSS) vulnerability in WGate in SAP Internet
Transaction Server (ITS) 6.20 allows remote attackers to inject
arbitrary web script or HTML via (1) a "<>" sequence in the ~service
parameter to wgate.dll, or (2) Javascript splicing in the query
string, a different vector than CVE-2006-5114.
|
| CVE-2008-2117 |
Cross-site scripting (XSS) vulnerability in pages/news.page.inc in
Project Alumni 1.0.9 allows remote attackers to inject arbitrary web
script or HTML via the year parameter in a news action to index.php, a
different vector than CVE-2007-6126.
|
| CVE-2008-2115 |
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in
ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) te and (2) dir parameters in
a tempedit action.
|
| CVE-2008-2103 |
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later
allows remote attackers to inject arbitrary web script or HTML via the
id parameter to the "Format for Printing" view or "Long Format" bug
list.
|
| CVE-2008-2082 |
Cross-site scripting (XSS) vulnerability in index.php in Siteman
2.0.x2 allows remote attackers to inject arbitrary web script or HTML
via the module parameter, which leaks the path in an error message.
|
| CVE-2008-2075 |
Cross-site scripting (XSS) vulnerability in pic.php in AstroCam 2.5.0
through 2.7.3 allows remote attackers to inject arbitrary web script
or HTML via the picfile parameter.
|
| CVE-2008-2072 |
Cross-site scripting (XSS) vulnerability in index.php in Virtual
Design Studio vlbook 1.21 allows remote attackers to inject arbitrary
web script or HTML via the l parameter, a different vector than
CVE-2006-3260.
|
| CVE-2008-2071 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM
interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before
11.22.3 allow remote attackers to perform unauthorized actions as
cPanel administrators via requests to cpanel/whm/webmail and other
unspecified vectors.
|
| CVE-2008-2070 |
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22
before 11.22.3 allows remote attackers to bypass XSS protection and
inject arbitrary script or HTML via repeated, improperly-ordered "<"
and ">" characters in the (1) issue parameter to
scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3)
search parameter to scripts2/listaccts, and other unspecified vectors.
|
| CVE-2008-2068 |
Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-2067 |
SQL injection vulnerability in bb_admin.php in miniBB 2.2a allows
remote attackers to execute arbitrary SQL commands via the whatus
parameter in a searchusers2 action. NOTE: it was later reported that
other versions before 3.0.1 are also vulnerable.
|
| CVE-2008-2066 |
Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB
2.2a allows remote attackers to inject arbitrary web script or HTML
via the whatus parameter in a searchusers2 action. NOTE: it was later
reported that other versions before 3.0.1 are also vulnerable.
|
| CVE-2008-2048 |
Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in
Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web
script or HTML via the sayfa parameter.
|
| CVE-2008-2046 |
Cross-site scripting (XSS) vulnerability in index.php in Softpedia
SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary
web script or HTML via the user parameter.
|
| CVE-2008-2037 |
Multiple cross-site scripting (XSS) vulnerabilities in EditeurScripts
EsContacts 1.0 allow remote authenticated users to inject arbitrary
web script or HTML via the msg parameter to (1) login.php, (2)
importer.php, (3) add_groupe.php, (4) contacts.php, (5) groupes.php,
and (6) search.php.
|
| CVE-2008-2035 |
Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1)
BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3)
newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and
earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x,
XOOPS Cube 2.1, and ImpressCMS allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2030 |
Cross-site scripting (XSS) vulnerability in installControl.php3 in F5
FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers
to inject arbitrary web script or HTML via the query string. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-2026 |
Cross-site scripting (XSS) vulnerability in WebID/IISWebAgentIF.dll in
RSA Authentication Agent 5.3.0.258, and other versions before
5.3.3.378, allows remote attackers to inject arbitrary web script or
HTML via a URL-encoded postdata parameter. NOTE: this is different
than CVE-2005-1118, but it might be the same as CVE-2008-1470.
|
| CVE-2008-2025 |
Cross-site scripting (XSS) vulnerability in Apache Struts before
1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2
on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and
before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors related
to "insufficient quoting of parameters."
|
| CVE-2008-2024 |
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2,
and possibly earlier, when register_globals is enabled, allows remote
attackers to inject arbitrary web script or HTML via the glang[]
parameter in a registernew action.
|
| CVE-2008-2022 |
Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software
MegaBBS 2.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) toid parameter to send-private-message.asp and the
(2) redirect parameter to admin/impersonate.asp. NOTE: vector 2
requires authentication.
|
| CVE-2008-2011 |
Cross-site scripting (XSS) vulnerability in the National Rail
Enquiries Live Departure Boards gadget before 1.1 allows remote
National Rail Enquiries servers or man-in-the-middle attackers to
inject arbitrary web script or HTML, and execute arbitrary code, via a
response body, as demonstrated by a SCRIPT element that references a
vbscript: URI.
|
| CVE-2008-1991 |
Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in
Acidcat CMS 3.4.1 allows remote attackers to inject arbitrary web
script or HTML via the field parameter.
|
| CVE-2008-1987 |
Cross-site scripting (XSS) vulnerability in search.php in
EncapsGallery 2.0.2 allows remote attackers to inject arbitrary web
script or HTML via the search parameter.
|
| CVE-2008-1986 |
Cross-site scripting (XSS) vulnerability in liste_article.php in Blog
Pixel Motion (aka PixelMotion) allows remote attackers to inject
arbitrary web script or HTML via the jours parameter.
|
| CVE-2008-1985 |
Cross-site scripting (XSS) vulnerability in base.php in DigitalHive
2.0 RC2 allows remote attackers to inject arbitrary web script or HTML
via the mt parameter, possibly related to membres.php.
|
| CVE-2008-1983 |
Cross-site scripting (XSS) vulnerability in Advanced Electron Forum
(AEF) 1.0.6 allows remote attackers to inject arbitrary web script or
HTML via the beg parameter in a members action to index.php.
|
| CVE-2008-1980 |
Cross-site scripting (XSS) vulnerability in E-Publish 5.x before
5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-1978 |
Cross-site scripting (XSS) vulnerability in the Ubercart 5.x before
5.x-1.0 rc3 module for Drupal allows remote authenticated users to
inject arbitrary web script or HTML via node titles related to
unspecified product features, a different vector than CVE-2008-1428.
|
| CVE-2008-1976 |
Multiple cross-site scripting (XSS) vulnerabilities in the Drupal
modules (1) Internationalization (i18n) 5.x before 5.x-2.3 and 5.x-1.1
and 6.x before 6.x-1.0 beta 1; and (2) Localizer 5.x before 5.x-3.4,
5.x-2.1, and 5.x-1.11; allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-1974 |
Cross-site scripting (XSS) vulnerability in addevent.php in Horde
Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5
allows remote attackers to inject arbitrary web script or HTML via the
url parameter.
|
| CVE-2008-1972 |
Multiple cross-site scripting (XSS) vulnerabilities in the user
account creation feature in Exponent CMS 0.96.6-GA20071003 and
earlier, when the Allow Registration? configuration option is enabled,
allow remote attackers to inject arbitrary web script or HTML via the
(1) username, (2) firstname, (3) lastname, and (4) e-mail address
fields. NOTE: some of these details are obtained from third party
information.
|
| CVE-2008-1969 |
Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1
and 7 allow remote attackers to inject arbitrary web script or HTML
via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3)
TitleParms, (4) WidgetsHeights, (5) WidgetsLinks, and (6)
WidgetsTitles parameters to (b) CznCommon/CznCustomContainer.asp, (7)
CFTARGET parameter to (c) home.asp, (8) PersonOid parameter to (d)
PeopleWeb/Cards/CVCard.asp, (9) DESTLINKOID and PersonOID parameters
to (e) PeopleWeb/Cards/PayrollCard.asp, and the (10) FolderTemplateId
and (11) FolderTemplateName parameters to (f)
PeopleWeb/CznDocFolder/CznDFStartProcess.asp.
|
| CVE-2008-1967 |
Cross-site scripting (XSS) vulnerability in CFLogon/CFLogon.asp in
Cezanne 6.5.1 and 7 allows remote attackers to inject arbitrary web
script or HTML via the SleUserName parameter.
|
| CVE-2008-1960 |
Cross-site scripting (XSS) vulnerability in cgi-bin/contray/search.cgi
in ContRay 3.x allows remote attackers to inject arbitrary web script
or HTML via the search parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-1956 |
Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus
13 2007.2 allows remote attackers to inject arbitrary web script or
HTML via the wiki parameter.
|
| CVE-2008-1955 |
Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER
MyBoard 1.0.12 allows remote attackers to inject arbitrary web script
or HTML via the id parameter.
information.
|
| CVE-2008-1953 |
Cross-site scripting (XSS) vulnerability in the Sitedesigner before
1.1.5 search template in Magnolia Enterprise Edition allows remote
attackers to inject arbitrary web script or HTML via the query
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-1947 |
Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9
through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to
inject arbitrary web script or HTML via the name parameter (aka the
hostname attribute) to host-manager/html/add.
|
| CVE-2008-1941 |
Cross-site scripting (XSS) vulnerability in the profile update feature
in Akiva WebBoard 8.0 allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors in the form
field. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-1917 |
Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) class parameter to (a) methodTable.php, (b) code.php, and (c)
details.php in browser/; and the (2) location parameter to
browser/code.php. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-1916 |
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart
5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to
inject arbitrary web script or HTML via text fields intended for the
(1) address and (2) order information, which are later displayed on
the order view page and unspecified other administrative pages, a
different vulnerability than CVE-2008-1428.
|
| CVE-2008-1906 |
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce
1.1.0 allows remote attackers to inject arbitrary web script or HTML
via the year parameter in a view.year action.
|
| CVE-2008-1896 |
Multiple cross-site scripting (XSS) vulnerabilities in Carbon
Communities 2.4 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) Redirect parameter to login.asp and the
(2) OrderBy parameter to member_send.asp.
|
| CVE-2008-1894 |
Cross-site scripting (XSS) vulnerability in
desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView
XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows remote
attackers to inject arbitrary web script or HTML via the cms
parameter.
|
| CVE-2008-1892 |
Cross-site scripting (XSS) vulnerability in bs_auth.php in
Blogator-script 0.95 and 1.01 allows remote attackers to inject
arbitrary web script or HTML via the msg parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-1888 |
Cross-site scripting (XSS) vulnerability in Microsoft Windows
SharePoint Services 2.0 allows remote attackers to inject arbitrary
web script or HTML via the Picture Source (aka picture object source)
field in the Rich Text Editor.
|
| CVE-2008-1883 |
The server in Blackboard Academic Suite 7.x stores MD5 password hashes
that are provided directly by clients, which makes it easier for
remote attackers to access accounts via a modified client that skips
the javascript/md5.js hash calculation, and instead sends an arbitrary
MD5 string.
|
| CVE-2008-1873 |
Cross-site scripting (XSS) vulnerability in the private message
feature in Nuke ET 3.2 and 3.4, when using Internet Explorer, allows
remote authenticated users to inject arbitrary web script or HTML via
a CSS property in the STYLE attribute of a DIV element in the mensaje
parameter. NOTE: some of these details are obtained from third party
information.
|
| CVE-2008-1850 |
Multiple cross-site scripting (XSS) vulnerabilities in login.php in
Omnistar Interactive OSI Affiliate allow remote attackers to inject
arbitrary web script or HTML via the (1) login, (2) profile, (3)
profile2, and (4) ref parameters.
|
| CVE-2008-1848 |
Cross-site scripting (XSS) vulnerability in the joomlaXplorer
(com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows
remote attackers to inject arbitrary web script or HTML via the error
parameter in a show_error action to index.php.
|
| CVE-2008-1846 |
The default configuration of SAP NetWeaver before 7.0 SP15 does not
enable the "Always Use Secure HTML Editor" (aka Editor Security or
Secure Editing) parameter, which allows remote attackers to conduct
cross-site scripting (XSS) attacks by entering feedback for a file.
|
| CVE-2008-1839 |
Multgiple cross-site scripting (XSS) vulnerabilities in
module/main.php in WORK system e-commerce 4.0.9 allow remote attackers
to inject arbitrary web script or HTML via the (1) day, (2) month, and
(3) year parameters. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-1800 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
DivXDB 2002 0.94b allow remote attackers to inject arbitrary web
script or HTML via the (1) choice, (2) _page_, (3) zone_admin, (4)
general_search, and (5) import parameters. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1795 |
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard
Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow
remote attackers to inject arbitrary web script or HTML via (1) the
searchText parameter in a Course action to
webapps/blackboard/execute/viewCatalog or (2) the
data__announcements___pk1_pk2__subject parameter in an ADD action to
bin/common/announcement.pl.
|
| CVE-2008-1794 |
Multiple cross-site scripting (XSS) vulnerabilities in the Webform
Drupal module 5.x before 5.x-1.10, 5.x-2.x before 5.x-2.0-beta3, and
6.x before 6.x-1.0-beta3 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-1793 |
Multiple cross-site scripting (XSS) vulnerabilities in view.cgi in
Smart Classified ADS Professional, Smart Photo ADS, and Smart Photo
ADS Gold allow remote attackers to inject arbitrary web script or HTML
via the (1) AdNum and (2) Department parameters. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1792 |
Cross-site scripting (XSS) vulnerability in the insertion filter in
the Flickr Drupal module 5.x before 5.x-1.3 and 6.x before
6.x-1.0-alpha allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2008-1787 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Poplar Gedcom Viewer 2.0 allow remote attackers to inject arbitrary
web script or HTML via the (1) text and (2) ul parameters. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-1775 |
Cross-site scripting (XSS) vulnerability in mindex.do in ManageEngine
Firewall Analyzer 4.0.3 allows remote attackers to inject arbitrary
web script or HTML via the displayName parameter. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1757 |
Cross-site scripting (XSS) vulnerability in index.php in the
ConcoursPhoto module for KwsPHP 1.0 allows remote attackers to inject
arbitrary web script or HTML via the VIEW parameter.
|
| CVE-2008-1753 |
Cross-site scripting (XSS) vulnerability in
system/workplace/admin/workplace/sessions.jsp in Alkacon OpenCMS 7.0.3
allows remote attackers to inject arbitrary web script or HTML via the
searchfilter parameter, a different vector than CVE-2008-1510.
|
| CVE-2008-1719 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Nuke ET
3.2 and 3.4 allow remote attackers to perform actions as
administrators, as demonstrated by inserting an XSS sequence into a
document.
|
| CVE-2008-1717 |
WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5
allows remote attackers to obtain the full path via invalid (1) page
and (2) form parameters, which leaks the path from an exception
handler when a valid class cannot be found.
|
| CVE-2008-1716 |
Cross-site scripting (XSS) vulnerability in WoltLab Community
Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote
attackers to inject arbitrary web script or HTML via the (1) page and
(2) form parameters, which are not properly handled when they are
reflected back in an error message.
|
| CVE-2008-1698 |
Cross-site scripting (XSS) vulnerability in gallery.php in Simple
Gallery 2.2 allows remote attackers to inject arbitrary web script or
HTML via the album parameter to index.php. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1663 |
Cross-site scripting (XSS) vulnerability in HP System Management
Homepage (SMH) 2.1.10 and 2.1.11 on Linux and Windows allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-1651 |
Directory traversal vulnerability in admin/login.php in EasyNews 4.0
allows remote attackers to include and execute arbitrary local files
via a .. (dot dot) in the lang parameter.
|
| CVE-2008-1650 |
SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0
allows remote attackers to execute arbitrary SQL commands via the read
parameter in an edp_Help_Internal_News action.
|
| CVE-2008-1649 |
Cross-site scripting (XSS) vulnerability in
staticpages/easypublish/index.php in EasyNews 4.0 allows remote
attackers to inject arbitrary web script or HTML via the read
parameter in an edp_pupublish action.
|
| CVE-2008-1636 |
Cross-site scripting (XSS) vulnerability in index.php in JV2 Quick
Gallery 1.1 allows remote attackers to inject arbitrary web script or
HTML via the f parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-1634 |
Cross-site scripting (XSS) vulnerability in index.php in JV2 Folder
Gallery 3.1 allows remote attackers to inject arbitrary web script or
HTML via the image parameter. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2008-1630 |
Multiple cross-site scripting (XSS) vulnerabilities in CuteFlow 1.5.0
and 2.10.0 allow remote attackers to inject arbitrary web script or
HTML via the language parameter to (1) page/showcirculation.php; and
(2) edittemplate_step2.php, (3) showfields.php, (4) showuser.php, (5)
editmailinglist_step1.php, and (6) showtemplates.php in pages/.
|
| CVE-2008-1629 |
Cross-site scripting (XSS) vulnerability in PHPkrm before 1.5.0 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-1621 |
Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow
remote attackers to inject arbitrary web script or HTML via the id
parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-1604 |
Cross-site scripting (XSS) vulnerability in PerlMailer before 3.02
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-1603 |
Cross-site scripting (XSS) vulnerability in GNB DesignForm before 3.9
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors in the email form.
|
| CVE-2008-1566 |
Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine
Applications Manager 8.x allows remote attackers to inject arbitrary
web script or HTML via the query parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1560 |
Multiple cross-site scripting (XSS) vulnerabilities in Digiappz
DigiDomain 2.2 allow remote attackers to inject arbitrary web script
or HTML via the (1) domain parameter to lookup_result.asp, and the (2)
word1 and (3) word2 parameters to suggest_result.asp.
|
| CVE-2008-1556 |
Multiple cross-site scripting (XSS) vulnerabilities in BolinOS 4.6.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) url parameter to (a)
system/actionspages/_b/contentFiles/gBImageViewer.php, (2) ForEditor
parameter to (b)
system/actionspages/_b/contentFiles/gBselectorContents.php, (3) the
PATH_INFO to (c) gBLoginPage.php and (d) gBPassword.php in
system/actionspages/_b/contentFiles/, (4) formlogin parameter to
system/actionspages/_b/contentFiles/gBLoginPage.php, and the (5)
bolini_searchengine46Search parameter to (e) help/index.php.
|
| CVE-2008-1550 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
CubeCart 4.2.1 allow remote attackers to inject arbitrary web script
or HTML via (1) the _a parameter in a searchStr action and the (2)
Submit parameter.
|
| CVE-2008-1548 |
Multiple cross-site scripting (XSS) vulnerabilities in Aeries Browser
Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information
System allow remote attackers to inject arbitrary web script or HTML
via the (1) UserName parameter to loginproc.asp and the (2) usr
parameter to Login.asp.
|
| CVE-2008-1538 |
Cross-site scripting (XSS) vulnerability in searchAction.do in
ManageEngine EventLog Analyzer 5 allows remote attackers to inject
arbitrary web script or HTML via the searchText parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-1536 |
Cross-site scripting (XSS) vulnerability in index.php in Pictures Pro
(aka Tim Grissett) Photo Cart 4.1 allows remote attackers to inject
arbitrary web script or HTML via the amessage parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2008-1524 |
The SNMP service on ZyXEL Prestige routers, including P-660 and P-661
models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has "public" as
its default community for both (1) read and (2) write operations,
which allows remote attackers to perform administrative actions via
SNMP, as demonstrated by reading the Dynamic DNS service password or
inserting an XSS sequence into the system.sysName.0 variable, which is
displayed on the System Status page.
|
| CVE-2008-1510 |
Cross-site scripting (XSS) vulnerability in
system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS
7.0.3 allows remote attackers to inject arbitrary web script or HTML
via the (1) searchfilter or (2) listSearchFilter parameter.
|
| CVE-2008-1504 |
Cross-site scripting (XSS) vulnerability in setup.php3 in phpHeaven
phpMyChat 0.14.5 allows remote attackers to inject arbitrary web
script or HTML via the Lang parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-1503 |
Cross-site scripting (XSS) vulnerability in the web management
interface in F5 BIG-IP 9.4.3 allows remote attackers to inject
arbitrary web script or HTML via (1) the name of a node object, or the
(2) sysContact or (3) sysLocation SNMP configuration field, aka "Audit
Log XSS." NOTE: these issues might be resultant from cross-site
request forgery (CSRF) vulnerabilities.
|
| CVE-2008-1502 |
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in
KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and
other products, allows remote attackers to bypass HTML filtering and
conduct cross-site scripting (XSS) attacks via a string containing
crafted URL protocols.
|
| CVE-2008-1500 |
Cross-site scripting (XSS) vulnerability in index.php in TinyPortal
0.8.6 and 1.0.3 allows remote attackers to inject arbitrary web script
or HTML via the PHPSESSID parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-1499 |
Cross-site scripting (XSS) vulnerability in frontend/x/manpage.html in
cPanel 11.18.3 and 11.21.0-BETA allows remote attackers to inject
arbitrary web script or HTML via the query string.
|
| CVE-2008-1492 |
Multiple directory traversal vulnerabilities in CoronaMatrix
phpAddressBook 2.11 allow remote attackers to include and execute
arbitrary local files via a .. (dot dot) in the skin parameter to (1)
index.php and (2) install.php. NOTE: it was later reported that
vector 1 is also present in 2.0.
|
| CVE-2008-1487 |
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before
1.3.3 allow remote attackers to inject arbitrary web script or HTML
via (1) ftp/index.php, (2) viewer.php, (3) functions/other.php, (4)
include/left_menu.class.php, and (5) plugins/stats/stats_view.php.
|
| CVE-2008-1485 |
Cross-site scripting (XSS) vulnerability in PunBB 1.2.16 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
get_host parameter to moderate.php.
|
| CVE-2008-1481 |
Cross-site scripting (XSS) vulnerability in index.php in webSPELL
4.1.2 allows remote attackers to inject arbitrary web script or HTML
via the board parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-1479 |
Cross-site scripting (XSS) vulnerability in index.php in
cyberfrogs.net cfnetgs 0.24 allows remote attackers to inject
arbitrary web script or HTML via the directory parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-1477 |
Multiple cross-site scripting (XSS) vulnerabilities in busca.php in
eForum 0.4 allow remote attackers to inject arbitrary web script or
HTML via the (1) busca and (2) link parameters.
|
| CVE-2008-1476 |
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before
1.3 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to received trackbacks.
|
| CVE-2008-1474 |
Multiple unspecified vulnerabilities in Roundup before 1.4.4 have
unknown impact and attack vectors, some of which may be related to
cross-site scripting (XSS).
|
| CVE-2008-1470 |
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID
RSA Authentication Agent 5.3, and possibly earlier, allows remote
attackers to conduct cross-site scripting (XSS) attacks via the
postdata parameter, due to an incomplete fix for CVE-2005-1118.
|
| CVE-2008-1468 |
Cross-site scripting (XSS) vulnerability in namazu.cgi in Namazu
before 2.0.18 allows remote attackers to inject arbitrary web script
or HTML via UTF-7 encoded input, related to failure to set the
charset, a different vector than CVE-2004-1318 and CVE-2001-1350.
NOTE: some of these details are obtained from third party information.
|
| CVE-2008-1463 |
Cross-site scripting (XSS) vulnerability in the management GUI in
Imperva SecureSphere MX Management Server 5.0 allows remote attackers
to inject arbitrary web script or HTML via an invalid or prohibited
request to a web server protected by SecureSphere, which triggers
injection into the "corrective action" section of an alert page.
|
| CVE-2008-1458 |
Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2
allows remote attackers to inject arbitrary web script or HTML via the
q parameter in a products search action. NOTE: it was also reported
that 1.3.5-SP2 trial edition is also affected.
|
| CVE-2008-1432 |
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in
ManageEngine SupportCenter Plus 7.0.0 allows remote attackers to
inject arbitrary web script or HTML via the searchText parameter, a
related issue to CVE-2008-1299. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-1428 |
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart
5.x before 5.x-1.0-beta7 module for Drupal allow remote attackers to
inject arbitrary web script or HTML via a text attribute value for a
product.
|
| CVE-2008-1414 |
Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS)
5.0 and earlier allows remote attackers to inject arbitrary web script
or HTML via the tab parameter to (1) index.php, as demonstrated using
mixed case and encoded whitespace characters in the tag; or (2)
clientinfo.php, (3) invoices.php, (4) smartlinks.php, and (5)
todo.php, as demonstrated using a META tag.
|
| CVE-2008-1413 |
Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus
2.1 through 2.4 allows remote attackers to inject arbitrary web script
or HTML via the query parameter.
|
| CVE-2008-1399 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Clansphere 2008 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-1386 |
Multiple cross-site scripting (XSS) vulnerabilities in the installer
in Serendipity (S9Y) 1.3 allow remote attackers to inject arbitrary
web script or HTML via (1) unspecified path fields or (2) the database
host field. NOTE: the timing window for exploitation of this issue
might be limited.
|
| CVE-2008-1385 |
Cross-site scripting (XSS) vulnerability in the Top Referrers (aka
referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote
attackers to inject arbitrary web script or HTML via the Referer HTTP
header.
|
| CVE-2008-1360 |
Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows
remote attackers to inject arbitrary web script or HTML via unknown
vectors to unspecified CGI scripts, a different issue than
CVE-2007-5624.
|
| CVE-2008-1359 |
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB
or IP.Board) 2.3.4 before 2008-03-13 allows remote attackers to inject
arbitrary web script or HTML via nested BBCodes, a different vector
than CVE-2008-0913.
|
| CVE-2008-1355 |
Cross-site scripting (XSS) vulnerability in index.php in Jeebles
Technology Jeebles Directory 2.9.60 allows remote attackers to inject
arbitrary web script or HTML via the path parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-1348 |
Cross-site scripting (XSS) vulnerability in index.php in the eWebsite
eWeather (Weather) module for PHP-Nuke allows remote attackers to
inject arbitrary web script or HTML via the chart parameter to
modules.php.
|
| CVE-2008-1347 |
Multiple cross-site scripting (XSS) vulnerabilities in
staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and
earlier allow remote attackers to inject arbitrary web script or HTML
via (1) the PATH_INFO or (2) the q parameter in an about action to the
help system.
|
| CVE-2008-1345 |
Cross-site scripting (XSS) vulnerability in
plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr
and earlier allows remote attackers to inject arbitrary web script or
HTML via the day parameter in a dayview action.
|
| CVE-2008-1342 |
Multiple cross-site scripting (XSS) vulnerabilities in the search
feature in Polymita BPM-Suite and CollagePortal allow remote attackers
to inject arbitrary web script or HTML via the (1) _q and (2)
lucene_index_field_value parameters. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-1326 |
Cross-site scripting (XSS) vulnerability in search.php in Gallarific
allows remote attackers to inject arbitrary web script or HTML via the
query parameter. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2008-1306 |
Multiple cross-site scripting (XSS) vulnerabilities in Savvy Content
Manager (CM) allow remote attackers to inject arbitrary web script or
HTML via the searchterms parameter to (1) searchresults.cfm, (2)
search_results.cfm, and (3) search_results/index.cfm. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-1304 |
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) inviteemail parameter in an invite action to wp-admin/users.php
and the (2) to parameter in a sent action to wp-admin/invites.php.
|
| CVE-2008-1301 |
Absolute path traversal vulnerability in
system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp
in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated
administrators to read arbitrary files via a full pathname in the
filePath.0 parameter.
|
| CVE-2008-1300 |
Cross-site scripting (XSS) vulnerability in the Logfile Viewer
Settings function in
system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp
in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote attackers to inject
arbitrary web script or HTML via the filePath.0 parameter in a save
action, a different vector than CVE-2008-1045.
|
| CVE-2008-1299 |
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in
ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows
remote attackers to inject arbitrary web script or HTML via the
searchText parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-1296 |
Multiple cross-site scripting (XSS) vulnerabilities in EncapsGallery
1.11.2 allow remote attackers to inject arbitrary web script or HTML
via the file parameter to (1) watermark.php and (2)
catalog_watermark.php in core/. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-1285 |
Cross-site scripting (XSS) vulnerability in Sun Java Server Faces
(JSF) 1.2 before 1.2_08 allows remote attackers to inject arbitrary
web script or HTML via unknown vectors.
|
| CVE-2008-1283 |
Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0
allows remote attackers to inject arbitrary web script or HTML via the
URI, which is not properly handled in the 404 error page.
|
| CVE-2008-1273 |
Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7
allow remote attackers to inject arbitrary web script or HTML via the
path parameter to (1) popup.php, (2) test/dir2.php, (3)
admin/upload.php, and (4) dirxml.php in upload/. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1258 |
Cross-site scripting (XSS) vulnerability in prim.htm on the D-Link
DI-604 router allows remote attackers to inject arbitrary web script
or HTML via the rf parameter.
|
| CVE-2008-1257 |
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the
ZyXEL P-660HW series router allows remote attackers to inject
arbitrary web script or HTML via the PingIPAddr parameter.
|
| CVE-2008-1253 |
Cross-site scripting (XSS) vulnerability in cgi-bin/webcm on the
D-Link DSL-G604T router allows remote attackers to inject arbitrary
web script or HTML via the var:category parameter, as demonstrated by
a request for advanced/portforw.htm on the fwan page.
|
| CVE-2008-1251 |
Cross-site scripting (XSS) vulnerability in the web interface on the
central phone server for the Snom 320 SIP Phone allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-1250 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the web
interface on the central phone server for the Snom 320 SIP Phone allow
remote attackers to perform actions as the phone user, as demonstrated
by inserting an address-book entry containing an XSS sequence.
|
| CVE-2008-1243 |
Cross-site scripting (XSS) vulnerability on the Linksys WRT300N router
with firmware 2.00.20, when Mozilla Firefox or Apple Safari is used,
allows remote attackers to inject arbitrary web script or HTML via the
dyndns_domain parameter to the default URI.
|
| CVE-2008-1234 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before
2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9
allows remote attackers to inject arbitrary web script or HTML via
event handlers, aka "Universal XSS using event handlers."
|
| CVE-2008-1232 |
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0
through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows
remote attackers to inject arbitrary web script or HTML via a crafted
string that is used in the message argument to the
HttpServletResponse.sendError method.
|
| CVE-2008-1229 |
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki
2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web
script or HTML via the editor parameter, a different vector than
CVE-2007-5120.b.
|
| CVE-2008-1228 |
Cross-site scripting (XSS) vulnerability in admin.php in MG2 (formerly
Minigal) allows remote attackers to inject arbitrary web script or
HTML via the list parameter in an import action.
|
| CVE-2008-1226 |
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra
Collaboration Suite (ZCS) 4.0.3, 4.5.6, and possibly other versions
before 4.5.10 allow remote attackers to inject arbitrary web script or
HTML via an e-mail attachment, possibly involving a (1) .jpg or (2)
.gif image attachment.
|
| CVE-2008-1225 |
Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus
Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote
authenticated users to inject arbitrary web script or HTML via a (1)
mail message or (2) discussion board message. NOTE: this might overlap
CVE-2005-1076.
|
| CVE-2008-1224 |
Cross-site scripting (XSS) vulnerability in account.php in
BosClassifieds Classified Ads System 3.0 allows remote attackers to
inject arbitrary web script or HTML via the returnTo parameter. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-1222 |
Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-1216 |
IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not
properly identify URIs containing cross-site scripting (XSS) attack
strings, which allows remote attackers to inject arbitrary web script
or HTML via a Calendar OpenDocument action to main.nsf with a Count
parameter containing a JavaScript event in a malformed element, as
demonstrated by an onload event in an IFRAME element.
|
| CVE-2008-1213 |
Cross-site scripting (XSS) vulnerability in Numara FootPrints for
Linux 8.1 allows remote attackers to inject arbitrary web script or
HTML via the Title form field when setting an appointment. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-1212 |
Cross-site scripting (XSS) vulnerability in set_permissions.php in
Podcast Generator 0.96.2 allows remote attackers to inject arbitrary
web script or HTML via the scriptlang parameter. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1211 |
Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x
allows remote attackers to inject arbitrary web script or HTML via (1)
the type parameter in calendar.php and (2) the category parameter in
calendar_search.php. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2008-1209 |
Cross-site scripting (XSS) vulnerability in redirect.do in Xitex
WebContent M1 allows remote attackers to inject arbitrary web script
or HTML via the sid parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-1208 |
Cross-site scripting (XSS) vulnerability in the login page in Check
Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to
inject arbitrary web script or HTML via the user parameter.
|
| CVE-2008-1204 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Administration Console in Sun Java System Access Manager 7.1 and 7
2005Q4 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to the (1) Help and (2) Version
windows.
|
| CVE-2008-1202 |
Cross-site scripting (XSS) vulnerability in the web management
interface in Adobe LiveCycle Workflow 6.2 allows remote attackers to
inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2008-1183 |
Multiple cross-site scripting (XSS) vulnerabilities in Crafty Syntax
Live Help (CSLH) before 2.14.6 allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters to (1)
livehelp.php, (2) user_questions.php, and (3) leavemessage.php. NOTE:
the lostsheep.php vector is covered by CVE-2008-0848.
|
| CVE-2008-1182 |
Cross-site scripting (XSS) vulnerability in BSD Perimeter pfSense
before 1.2 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2008-1180 |
Cross-site scripting (XSS) vulnerability in
dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000
5.5 R1 build 11711 allows remote attackers to inject arbitrary web
script or HTML via the delivery_mode parameter.
|
| CVE-2008-1179 |
Multiple cross-site scripting (XSS) vulnerabilities in
include/common/javascript/color_picker.php in Centreon 1.4.2.3 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) name and (2) title parameters. NOTE: some of these details
are obtained from third party information.
|
| CVE-2008-1176 |
Cross-site scripting (XSS) vulnerability in function/sideblock.php in
Affiliate Market (affmarket) 0.1 BETA allows remote attackers to
inject arbitrary web script or HTML via the sideblock4 parameter.
|
| CVE-2008-1175 |
Cross-site scripting (XSS) vulnerability in AuthentiX 6.3b1 Trial
allows remote attackers to inject arbitrary web script or HTML via the
username parameter to aspAdmin/deleteUser.asp, a different vector than
CVE-2008-1174. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2008-1174 |
Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX
6.3b1 Trial allows remote attackers to inject arbitrary web script or
HTML via the username parameter.
|
| CVE-2008-1173 |
Cross-site scripting (XSS) vulnerability in account-inbox.php in
TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary
web script or HTML via the msg parameter.
|
| CVE-2008-1168 |
Cross-site scripting (XSS) vulnerability in Squid Analysis Report
Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary
web script or HTML via the User-Agent header, which is not properly
handled when displaying the Squid proxy log. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1165 |
Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9
through 0.9.9.4 allow remote attackers to inject arbitrary web script
or HTML via (1) a forced SQL error message or (2) old_value and
new_value database fields in task summaries, related to the
item_summary parameter in a details action in index.php. NOTE: some of
these details are obtained from third party information.
|
| CVE-2008-1133 |
The Drupal.checkPlain function in Drupal 6.0 only escapes the first
instance of a character in ECMAScript, which allows remote attackers
to conduct cross-site scripting (XSS) attacks.
|
| CVE-2008-1131 |
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote
authenticated users to inject arbitrary web script or HTML via titles
in content edit forms.
|
| CVE-2008-1129 |
Cross-site scripting (XSS) vulnerability in admin/users/self.php in
XRMS CRM allows remote attackers to inject arbitrary web script or
HTML via the msg parameter. NOTE: some of these details are obtained
from third party information.
|
| CVE-2008-1098 |
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) certain input processed by formatter/text_gedit.py (aka
the gui editor formatter); (2) a page name, which triggers an
injection in PageEditor.py when the page is successfully deleted by a
victim in a DeletePage action; or (3) the destination page name for a
RenamePage action, which triggers an injection in PageEditor.py when a
victim's rename attempt fails because of a duplicate name. NOTE: the
AttachFile XSS issue is already covered by CVE-2008-0781, and the
login XSS issue is already covered by CVE-2008-0780.
|
| CVE-2008-1082 |
Opera before 9.26 allows remote attackers to "bypass sanitization
filters" and conduct cross-site scripting (XSS) attacks via crafted
attribute values in an XML document, which are not properly handled
during DOM presentation.
|
| CVE-2008-1076 |
Cross-site scripting (XSS) vulnerability in search.php in Interspire
Shopping Cart 1.x allows remote attackers to inject arbitrary web
script or HTML via the search_query parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1075 |
Cross-site scripting (XSS) vulnerability in index.php in Maian Cart
1.1 allows remote attackers to inject arbitrary web script or HTML via
the keywords parameter in a search command. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2008-1073 |
Cross-site scripting (XSS) vulnerability in the report interface in
Internet Security Systems (ISS) Internet Scanner 7.0 Service Pack 2
Build 7.2.2005.52 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-1064 |
Cross-site scripting (XSS) vulnerability in images.php in the Red
Mexico RMSOFT Gallery System (GS) 2.0 module (aka rmgs) for XOOPS
allows remote attackers to inject arbitrary web script or HTML via the
q parameter.
|
| CVE-2008-1063 |
Cross-site scripting (XSS) vulnerability index.php in the
XM-Memberstats (xmmemberstats) module for XOOPS allows remote
attackers to inject arbitrary web script or HTML via the sortby
parameter.
|
| CVE-2008-1061 |
Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets
1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) text parameter to (a)
warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and
possibly (d) modules/execute.php; the (2) url parameter to (e)
view/admin/submenu.php; and the (3) page parameter to (f)
view/admin/pager.php.
|
| CVE-2008-1048 |
Cross-site scripting (XSS) vulnerability in manager/xmedia.php in
Plume CMS 1.2.2 allows remote attackers to inject arbitrary web script
or HTML via the dir parameter.
|
| CVE-2008-1047 |
Cross-site scripting (XSS) vulnerability in tiki-edit_article.php in
TikiWiki before 1.9.10.1 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-1045 |
Cross-site scripting (XSS) vulnerability in the file tree navigation
function in system/workplace/views/explorer/tree_files.jsp in Alkacon
OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script
or HTML via the resource parameter.
|
| CVE-2008-1041 |
Cross-site scripting (XSS) vulnerability in mwhois.php in Matt Wilson
Matt's Whois (MWhois) allows remote attackers to inject arbitrary web
script or HTML via the domain parameter.
|
| CVE-2008-1037 |
Cross-site scripting (XSS) vulnerability in the file listing function
in the web management interface in Packeteer PacketShaper and
PolicyCenter 8.2.2 allows remote attackers to inject arbitrary web
script or HTML via the FILELIST parameter to an arbitrary component,
which triggers injection into an Error Report page.
|
| CVE-2008-1036 |
The International Components for Unicode (ICU) library in Apple Mac OS
X before 10.5.3, Red Hat Enterprise Linux 5, and other operating
systems omits some invalid character sequences during conversion of
some character encodings, which might allow remote attackers to
conduct cross-site scripting (XSS) attacks.
|
| CVE-2008-1025 |
Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in
Safari before 3.1.1, allows remote attackers to inject arbitrary web
script or HTML via a crafted URL with a colon in the hostname portion.
|
| CVE-2008-1011 |
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple
Safari before 3.1, allows remote attackers to inject arbitrary web
script or HTML via a frame that calls a method instance in another
frame.
|
| CVE-2008-1009 |
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple
Safari before 3.1, allows remote attackers to inject arbitrary
JavaScript by modifying the history object.
|
| CVE-2008-1008 |
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple
Safari before 3.1, allows remote attackers to inject arbitrary web
script or HTML via the document.domain property.
|
| CVE-2008-1007 |
WebCore, as used in Apple Safari before 3.1, does not enforce the
frame navigation policy for Java applets, which allows remote
attackers to conduct cross-site scripting (XSS) attacks.
|
| CVE-2008-1006 |
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple
Safari before 3.1, allows remote attackers to inject arbitrary web
script or HTML by using the window.open function to change the
security context of a web page.
|
| CVE-2008-1004 |
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple
Safari before 3.1, allows remote attackers to inject arbitrary web
script or HTML via unknown vectors related to the Web Inspector.
|
| CVE-2008-1003 |
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple
Safari before 3.1, allows remote attackers to inject arbitrary web
script or HTML via unknown vectors related to sites that set the
document.domain property or have the same document.domain.
|
| CVE-2008-1002 |
Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1
allows remote attackers to inject arbitrary web script or HTML via a
crafted javascript: URL.
|
| CVE-2008-1001 |
Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1,
when running on Windows XP or Vista, allows remote attackers to inject
arbitrary web script or HTML via a crafted URL that is not properly
handled in the error page.
|
| CVE-2008-0982 |
Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to
obtain sensitive information via a direct request for
spyce/examples/automaton.spy, which reveals the path in an error
message.
|
| CVE-2008-0981 |
Open redirect vulnerability in spyce/examples/redirect.spy in Spyce -
Python Server Pages (PSP) 2.1.3 allows remote attackers to redirect
users to arbitrary web sites and conduct phishing attacks via a URL in
the url parameter.
|
| CVE-2008-0980 |
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python
Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary
web script or HTML via (1) the url or type parameter to
docs/examples/redirect.spy; (2) the x parameter to
docs/examples/handlervalidate.spy; (3) the name parameter to
spyce/examples/request.spy; (4) the Name parameter to
spyce/examples/getpost.spy; (5) the mytextarea parameter, the mypass
parameter, or an empty parameter to spyce/examples/formtag.spy; (6)
the newline parameter to the default URI under demos/chat/; (7) the
text1 parameter to docs/examples/formintro.spy; or (8) the mytext or
mydate parameter to docs/examples/formtag.spy.
|
| CVE-2008-0971 |
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in
Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver
before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before
3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to
inject arbitrary web script or HTML via (1) the Policy Name field in
Search Based Retention Policy in Message Archiver; unspecified
parameters in the (2) IP Configuration, (3) Administration, (4)
Journal Accounts, (5) Retention Policy, and (6) GroupWise Sync
components in Message Archiver; (7) input to search operations in Web
Filter; and (8) input used in error messages and (9) hidden INPUT
elements in (a) Spam Firewall, (b) IM Firewall, and (c) Web Filter.
|
| CVE-2008-0941 |
Cross-site scripting (XSS) vulnerability in Eagle Software Aeries
Browser Interface (ABI) 3.8.2.8 allows remote authenticated users to
inject arbitrary web script or HTML via an event.
|
| CVE-2008-0940 |
Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before
7.4.24 allows remote attackers to inject arbitrary web script or HTML
when creating a username, a different vulnerability than
CVE-2007-0407.
|
| CVE-2008-0925 |
Cross-site scripting (XSS) vulnerability in the iMonitor interface in
Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2
ftf2, allows remote attackers to inject arbitrary web script or HTML
via unspecified parameters that are used within "error messages of the
HTTP stack."
|
| CVE-2008-0920 |
SQL injection vulnerability in port/modifyportform.php in Open Source
Security Information Management (OSSIM) 0.9.9 rc5 allows remote
authenticated users to execute arbitrary SQL commands via the portname
parameter, which is not properly handled by a validation regular
expression.
|
| CVE-2008-0919 |
Cross-site scripting (XSS) vulnerability in session/login.php in Open
Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
dest parameter.
|
| CVE-2008-0917 |
Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1
and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier,
Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and
earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier,
Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote
1.2 and earlier allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2008-0914 |
Multiple cross-site scripting (XSS) vulnerabilities in the Mediation
server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before
2.3.2.14 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2008-0913 |
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB
or IP.Board) 2.3.4 allows remote attackers to inject arbitrary web
script or HTML via crafted BBCodes in an unspecified context.
|
| CVE-2008-0909 |
Cross-site scripting (XSS) vulnerability in browse.asp in Schoolwires
Academic Portal allows remote attackers to inject arbitrary web script
or HTML via the c parameter. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2008-0902 |
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic
Server and Express 6.1 through 10.0 MP1 allow remote attackers to
inject arbitrary web script or HTML via unspecified samples. NOTE:
this might be the same issue as CVE-2007-2694.
|
| CVE-2008-0899 |
Cross-site scripting (XSS) vulnerability in the Administration Console
in BEA WebLogic Server and Express 9.0 through 10.0 allows remote
attackers to inject arbitrary web script or HTML via URLs that are not
properly handled by the Unexpected Exception Page.
|
| CVE-2008-0877 |
Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media
Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or
HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme,
and (5) set_theme parameters to (a) index.php; the frontend, theme,
and (6) language parameters to (b) ajax_request.php; the jz_path
parameter to (c) slim.php; the frontend, theme, and jz_path parameters
to (d) popup.php; the (13) PATH_INFO to index.php and (e) slim.php;
and the (14) query parameter in a playlistedit action and (15)
siteNewsData parameter in a sitenews action to (f) popup.php.
|
| CVE-2008-0872 |
Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail
Enterprise 4.3 allows remote attackers to inject arbitrary web script
or HTML via a STYLE attribute of an element in the Subject field of an
e-mail message.
|
| CVE-2008-0869 |
Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1
through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote
attackers to inject arbitrary web script or HTML via a "framework
defined request parameter" when using WebLogic Workshop or Apache
Beehive NetUI framework with page flows.
|
| CVE-2008-0868 |
Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic
Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote
authenticated users to inject arbitrary web script or HTML via unknown
vectors.
|
| CVE-2008-0867 |
Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA
AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0
through SP1 allows remote attackers to inject arbitrary web script or
HTML via the name parameter.
|
| CVE-2008-0866 |
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic
Workshop allow remote attackers to inject arbitrary web script or HTML
via an invalid action URI, which is not properly handled by NetUI page
flows.
|
| CVE-2008-0861 |
Cross-site scripting (XSS) vulnerability in leg/Main.nsf in IBM Lotus
Quickplace 7.0 allows remote attackers to inject arbitrary web script
or HTML via an h_SearchString sub-parameter in the PreSetFields
parameter of an EditDocument action.
|
| CVE-2008-0851 |
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4
allow remote attackers to inject arbitrary web script or HTML via the
(1) username parameter to inscription.php, (2) courseCode parameter to
main/calendar/myagenda.php, (3) category parameter to
main/admin/course_category.php, (4) message parameter to
main/admin/session_list.php in a show_message action, and (5) an
avatar image to main/auth/profile.php.
|
| CVE-2008-0848 |
Cross-site scripting (XSS) vulnerability in lostsheep.php in Crafty
Syntax Live Help (CSLH) before 2.14.16, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors. NOTE:
the versions claimed by the original researcher are probably
incorrect.
|
| CVE-2008-0838 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
administration interface in Sophos ES1000 and ES4000 Email Security
Appliance 2.1.0.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) error and (2) go parameters to the login
page.
|
| CVE-2008-0837 |
Cross-site scripting (XSS) vulnerability in the log feature in the
John Godley Search Unleashed 0.2.10 plugin for WordPress allows remote
attackers to inject arbitrary web script or HTML via the s parameter,
which is not properly handled when the administrator views the log
file.
|
| CVE-2008-0834 |
Cross-site scripting (XSS) vulnerability in Lotus Quickr for i5/OS
before 8.0.0.2 Hotfix 11, when anonymous access is disabled on HTTP
ports, allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2008-0828 |
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.5
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) attributes such as style and onmouseover in (a) forum
post or (b) mail; or (2) the website field of the profile.
|
| CVE-2008-0826 |
Cross-site scripting (XSS) vulnerability in Claroline before 1.8.9
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-0820 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in index.php in Etomite
0.6.1.4 Final allows remote attackers to inject arbitrary web script
or HTML via $_SERVER['PHP_INFO']. NOTE: the vendor disputes this issue
in a followup, stating that the affected variable is
$_SERVER['PHP_SELF'], and "This is not an Etomite specific exploit and
I would like the report rescinded."
|
| CVE-2008-0809 |
Cross-site scripting (XSS) vulnerability in the htmlscrubber in
Ikiwiki before 1.1.46 allows remote attackers to inject arbitrary web
script or HTML via title contents.
|
| CVE-2008-0808 |
Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki
before 1.1.47 allows remote attackers to inject arbitrary web script
or HTML via meta tags.
|
| CVE-2008-0793 |
Multiple cross-site scripting (XSS) vulnerabilities in search.asp in
Tendenci CMS allow remote attackers to inject arbitrary web script or
HTML via the (1) category, (2) searchtext, (3) jobcategoryid, (4)
contactcompany, and unspecified other parameters. NOTE: some of these
details are obtained from third party information. NOTE: it is not
clear whether this affects Tendenci Enterprise Edition in addition to
the product's deployment on Tendenci's own server farm. If only the
latter was affected, then this issue should not be included in CVE.
|
| CVE-2008-0783 |
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7
before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject
arbitrary web script or HTML via (1) the view_type parameter to
graph.php; (2) the filter parameter to graph_view.php; (3) the action
parameter to the draw_navigation_text function in lib/functions.php,
reachable through index.php (aka the login page) or data_input.php; or
(4) the login_username parameter to index.php.
|
| CVE-2008-0781 |
Multiple cross-site scripting (XSS) vulnerabilities in
action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote
attackers to inject arbitrary web script or HTML via (1) message, (2)
pagename, and (3) target filenames.
|
| CVE-2008-0780 |
Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x through
1.5.8 and 1.6.x before 1.6.1 allows remote attackers to inject
arbitrary web script or HTML via the login action.
|
| CVE-2008-0775 |
Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple
Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote
attackers to inject arbitrary web script or HTML via strings to the
shoutbox form that start with "&#", contain the desired script, and
end with ";".
|
| CVE-2008-0774 |
Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel
Reservation System 3.01 and possibly earlier allows remote attackers
to inject arbitrary web script or HTML via the hotel_name parameter.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2008-0769 |
Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through
9.7.0 and possibly earlier does not set the charset, which allows
remote attackers to inject arbitrary web script or HTML via UTF-7
encoded input.
|
| CVE-2008-0765 |
Multiple cross-site scripting (XSS) vulnerabilities in artmedic
webdesign weblog allow remote attackers to inject arbitrary web script
or HTML via the (1) date parameter to artmedic_print.php and the (2)
jahrneu parameter to index.php.
|
| CVE-2008-0757 |
Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard
1.1.5 allows remote attackers to inject arbitrary web script or HTML
via the message parameter (aka the message text area), which leads to
an injection in the messenger during private message (PM) preview.
NOTE: some of these details are obtained from third party information.
|
| CVE-2008-0751 |
Cross-site scripting (XSS) vulnerability in the Freetag before 2.96
plugin for S9Y Serendipity, when using Internet Explorer 6 or 7,
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to plugin/tag/.
|
| CVE-2008-0749 |
Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS
3.3 allows remote attackers to inject arbitrary web script or HTML via
the id parameter in a calimero_webpage action.
|
| CVE-2008-0737 |
SQL injection vulnerability in admin/utilities_ConfigHelp.asp in
CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows
remote attackers to execute arbitrary SQL commands via the helpfield
parameter.
|
| CVE-2008-0736 |
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly
other 4.x and 3.x versions, allows remote attackers to obtain the path
via a certain value of the FedExAccount parameter.
|
| CVE-2008-0723 |
Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews
1.6.4, and other earlier 1.6.x versions, allows remote attackers to
inject arbitrary web script or HTML via the hash parameter in an admin
action to index.php, a different vulnerability than CVE-2006-2208.1.
|
| CVE-2008-0722 |
Cross-site scripting (XSS) vulnerability in index.php in Pagetool
1.0.7 allows remote attackers to inject arbitrary web script or HTML
via the search_term parameter in a pagetool_search action. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-0720 |
Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and
Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary
web script or HTML via the search parameter to webmin_search.cgi (aka
the search section), and possibly other components accessed through a
"search box" or "open file box." NOTE: some of these details are
obtained from third party information.
|
| CVE-2008-0717 |
Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1
through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are
enabled, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors that trigger injection into an error
response.
|
| CVE-2008-0700 |
Cross-site scripting (XSS) vulnerability in search.php in Crux
Software CruxCMS 3.0 allows remote attackers to inject arbitrary web
script or HTML via the search parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-0694 |
Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM
OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary
web script or HTML via the Expect HTTP header.
|
| CVE-2008-0691 |
Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php
in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1)
wp_footnotes_current_settings[priority], (2)
wp_footnotes_current_settings[style_rules], (3)
wp_footnotes_current_settings[pre_footnotes], and (4)
wp_footnotes_current_settings[post_footnotes] parameters.
|
| CVE-2008-0688 |
Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript
Domain Trader 2.0 allows remote attackers to inject arbitrary web
script or HTML via the id parameter in a viewcategory action.
|
| CVE-2008-0687 |
Cross-site scripting (XSS) vulnerability in
siteadmin/editor_files/includes/load_message.php in the Youtube Clone
Script allows remote attackers to inject arbitrary web script or HTML
via the lang[please_wait] parameter.
|
| CVE-2008-0684 |
Cross-site scripting (XSS) vulnerability in ViewCat.php in
iTechClassifieds 3.0 allows remote attackers to inject arbitrary web
script or HTML via the CatID parameter.
|
| CVE-2008-0679 |
Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0
allows remote attackers to inject arbitrary web script or HTML via the
search parameter.
|
| CVE-2008-0676 |
Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2
allows remote attackers to inject arbitrary web script or HTML via the
words parameter.
|
| CVE-2008-0669 |
Cross-site scripting (XSS) vulnerability in search.cgi in Sift Unity
allows remote attackers to inject arbitrary web script or HTML via the
qt parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-0644 |
Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to
bypass the cross-site scripting (XSS) protection mechanism for
applications via unspecified vectors related to the setEncoding
function.
|
| CVE-2008-0643 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and
ColdFusion 8 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2008-0642 |
Cross-site scripting (XSS) vulnerability in files created by Adobe
RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5
(WebHelp5Ext) or (2) WildFire (WildFireExt) extension, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, a different vulnerability than CVE-2007-1280.
|
| CVE-2008-0622 |
Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to the ulang parameter.
|
| CVE-2008-0618 |
Multiple cross-site scripting (XSS) vulnerabilities in the
DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote
attackers to inject arbitrary web script or HTML via the (1) gbname,
(2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified
programs. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-0617 |
Multiple cross-site scripting (XSS) vulnerabilities in the
DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) file parameter to
wp-admin/admin.php, or the (2) messagefield parameter in the guestbook
page, and the (3) title parameter in the messagearea.
|
| CVE-2008-0605 |
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft
HelpDesk before 1.95.228 allow remote attackers to inject arbitrary
web script or HTML via the (1) txtSearch parameter to
operator/article/article_search_results.asp and the (2) Attach_Id
parameter to operator/article/article_attachment.asp. NOTE: for
vector 2, the XSS occurs in a forced SQL error message.
|
| CVE-2008-0578 |
Cross-site scripting (XSS) vulnerability in the web management login
page in Tripwire Enterprise 7.0 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-0576 |
Cross-site scripting (XSS) vulnerability in the Project Issue Tracking
module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and
earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x
series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors that write to summary table pages.
|
| CVE-2008-0574 |
Cross-site scripting (XSS) vulnerability in index.php in webSPELL
4.01.02 allows remote attackers to inject arbitrary web script or HTML
via the sort parameter in a whoisonline action.
|
| CVE-2008-0564 |
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before
2.1.10b1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to (1) editing templates and (2) the
list's "info attribute" in the web administrator interface, a
different vulnerability than CVE-2006-3636.
|
| CVE-2008-0558 |
Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional
before 2.0.16 allows remote attackers to inject arbitrary web script
or HTML via the rp parameter to cartView.asp and unspecified other
components. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2008-0552 |
Cross-site scripting (XSS) vulnerability in index.php in eTicket
1.5.6-RC4 allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO.
|
| CVE-2008-0547 |
Cross-site scripting (XSS) vulnerability in
admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and
probably earlier 4.x and 3.x versions, allows remote attackers to
inject arbitrary web script or HTML via the helpfield parameter.
|
| CVE-2008-0546 |
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26,
and earlier 4.1.x versions, allow remote attackers to execute
arbitrary SQL commands via the (1) idProduct and (2) options
parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid
parameter to (b) ajax/ajax_getBrands.asp.
|
| CVE-2008-0541 |
Multiple cross-site scripting (XSS) vulnerabilities in forum.php in
Gerd Tentler Simple Forum 3.2 allow remote attackers to inject
arbitrary web script or HTML via the (1) open and (2) date_show
parameters.
|
| CVE-2008-0540 |
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0
allow remote attackers to inject arbitrary web script or HTML via the
query string to index.php in (1) user/ or (2) maint/.
|
| CVE-2008-0539 |
Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php
in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote
attackers to inject arbitrary web script or HTML via the report_type
parameter.
|
| CVE-2008-0533 |
Multiple cross-site scripting (XSS) vulnerabilities in
securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before
4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS
Solution Engine allow remote attackers to inject arbitrary web script
or HTML via an argument located immediately after the Help argument,
and possibly unspecified other vectors.
|
| CVE-2008-0523 |
Multiple cross-site scripting (XSS) vulnerabilities in SoftCart.exe in
SoftCart 5.1.2.2 allow remote attackers to inject arbitrary web script
or HTML via the (1) License_Plate, (2) License_State, (3) Ticket_Date,
and (4) Ticket_Number parameters. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-0522 |
Cross-site scripting (XSS) vulnerability in multiple Hal Networks
shopping-cart products allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-0508 |
Cross-site request forgery (CSRF) vulnerability in
deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0
plugin for WordPress allows remote attackers to modify the
oldstructure (aka dean_pm_config[oldstructure]) configuration setting
as administrators via the old_struct parameter in a
deans_permalinks_migration.php action to wp-admin/options-general.php,
as demonstrated by placing an XSS sequence in this setting.
|
| CVE-2008-0505 |
Multiple cross-site scripting (XSS) vulnerabilities in
docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow
remote attackers to inject arbitrary web script or HTML via the (1) h
and (2) t parameters.
|
| CVE-2008-0497 |
Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS
3.31 allows remote attackers to inject arbitrary web script or HTML
via the PATH_INFO, which is not quoted when processing PHP_SELF.
|
| CVE-2008-0496 |
Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0
allows remote attackers to inject arbitrary web script or HTML via the
limit parameter in a search action.
|
| CVE-2008-0494 |
Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in
Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web
script or HTML via the psearch parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-0474 |
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine
Applications Manager 8.1 build 8100 allow remote attackers to inject
arbitrary web script or HTML via the (1) showlink parameter to
jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3)
attributeToSelect, (4) redirectto, and (5) resourceid parameters to
(a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7)
redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8)
haid and (9) returnpath parameters to (c) showTile.do. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2008-0463 |
Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before
4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors involving node properties.
|
| CVE-2008-0462 |
Cross-site scripting (XSS) vulnerability in the Archive 5.x before
5.x-1.8 module for Drupal allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-0460 |
Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki
1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and
1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier;
when Internet Explorer is used, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-0456 |
CRLF injection vulnerability in the mod_negotiation module in the
Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and
earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x
series allows remote authenticated users to inject arbitrary HTTP
headers and conduct HTTP response splitting attacks by uploading a
file with a multi-line name containing HTTP header sequences and a
file extension, which leads to injection within a (1) "406 Not
Acceptable" or (2) "300 Multiple Choices" HTTP response when the
extension is omitted in a request for the file.
|
| CVE-2008-0455 |
Cross-site scripting (XSS) vulnerability in the mod_negotiation module
in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series,
2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the
1.3.x series allows remote authenticated users to inject arbitrary web
script or HTML by uploading a file with a name containing XSS
sequences and a file extension, which leads to injection within a (1)
"406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when
the extension is omitted in a request for the file.
|
| CVE-2008-0454 |
Cross-zone scripting vulnerability in the Internet Explorer web
control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on
Windows allows user-assisted remote attackers to inject arbitrary web
script or HTML in the Local Machine Zone via the Title field of a (1)
Dailymotion and possibly (2) Metacafe movie in the Skype video
gallery, accessible through a search within the "Add video to chat"
dialog, aka "videomood XSS."
|
| CVE-2008-0451 |
Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote
authenticated users to execute arbitrary SQL commands via the id
parameter to (1) siteadmin/article-edit.php; and unspecified
parameters to (2) submitted-edit.php, (3) page-edit.php, (4)
section-edit.php, (5) staff-edit.php, and (6) staff-access.php in
siteadmin/.
|
| CVE-2008-0444 |
Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG)
before 2.7.0 allows remote attackers to inject arbitrary web script or
HTML via subtext parameter to unspecified components.
|
| CVE-2008-0439 |
Cross-site scripting (XSS) vulnerability in
templates/default/admincp/attachments_header.php in DeluxeBB 1.1
allows remote attackers to inject arbitrary web script or HTML via the
lang_listofmatches parameter.
|
| CVE-2008-0438 |
Cross-site scripting (XSS) vulnerability in the font rendering
functionality in Novemberborn sIFR 2.0.2 allows remote attackers to
inject arbitrary web script or HTML via the txt parameter to a Flash
(SWF) file, as demonstrated by fonts/FuturaLt.swf.
|
| CVE-2008-0436 |
Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp
in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject
arbitrary web script or HTML via the target parameter.
|
| CVE-2008-0433 |
PHP remote file inclusion vulnerability in
theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21
and earlier allows remote attackers to execute arbitrary PHP code via
a URL in the loadpage parameter, a different vector than
CVE-2007-6614.
|
| CVE-2008-0432 |
Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo
2.21 and earlier allows remote attackers to inject arbitrary web
script or HTML via the cat parameter.
|
| CVE-2008-0426 |
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in
PacerCMS before 0.6.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) name, (2) headline, or (3) text field in a
message.
|
| CVE-2008-0416 |
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox
before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before
1.1.8 allow remote attackers to inject arbitrary web script or HTML
via certain character encodings, including (1) a backspace character
that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and
(3) "zero-length non-ASCII sequences" in certain Asian character sets.
|
| CVE-2008-0415 |
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and
SeaMonkey before 1.1.8 allows remote attackers to execute script
outside of the sandbox and conduct cross-site scripting (XSS) attacks
via multiple vectors including the XMLDocument.load function, aka
"JavaScript privilege escalation bugs."
|
| CVE-2008-0409 |
Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS)
before 2.2c allows remote attackers to inject arbitrary web script or
HTML via the userinfo subcomponent of a URL.
|
| CVE-2008-0404 |
Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows
remote attackers to inject arbitrary web script or HTML via vectors
related to the "Most active bugs" summary.
|
| CVE-2008-0400 |
Cross-site scripting (XSS) vulnerability in header.tpl.php in the
modern template for Singapore 0.10.1 allows remote attackers to inject
arbitrary web script or HTML via the gallery parameter to default.php.
|
| CVE-2008-0398 |
Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly
earlier versions, allows remote attackers to inject arbitrary web
script or HTML via the comment form.
|
| CVE-2008-0381 |
Unspecified vulnerability in Mahara before 0.9.1 has unknown impact
and remote attack vectors, probably related to cross-site scripting
(XSS) in uploaded files.
|
| CVE-2008-0370 |
Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel
before 11.17 build 19417 allows remote attackers to inject arbitrary
web script or HTML via the rurl parameter. NOTE: some of these details
are obtained from third party information.
|
| CVE-2008-0362 |
Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy
3.0 and earlier allows remote attackers to inject arbitrary web script
or HTML via the album parameter.
|
| CVE-2008-0359 |
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b
allow remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to (1) admin.php or (2) index.php in photo/.
|
| CVE-2008-0354 |
Cross-site scripting (XSS) vulnerability in the chat client in IBM
Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to
inject arbitrary web script or HTML via a crafted message, which
triggers code execution after a mouseover event initiated by the
victim.
|
| CVE-2008-0335 |
Cross-site scripting (XSS) vulnerability in BugTracker.NET before
2.7.2 allows remote attackers to inject arbitrary web script or HTML
via an arbitrary custom text field.
|
| CVE-2008-0334 |
Cross-site scripting (XSS) vulnerability in
pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary
web script or HTML via the L_PREF_NAME[855] parameter.
|
| CVE-2008-0292 |
Cross-site scripting (XSS) vulnerability in photo_album.pl in Dansie
Photo Album 1.0 allows remote attackers to inject arbitrary web script
or HTML via the search parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-0284 |
Cross-site scripting (XSS) vulnerability in Simple Machines Forum
(SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary
web script or HTML via (1) Itemid or (2) topic arguments.
|
| CVE-2008-0276 |
Cross-site scripting (XSS) vulnerability in the Devel module before
5.x-0.1 for Drupal allows remote attackers to inject arbitrary web
script or HTML via a site variable, related to lack of escaping of the
variable table.
|
| CVE-2008-0274 |
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when
certain .htaccess protections are disabled, allows remote attackers to
inject arbitrary web script or HTML via crafted links involving theme
.tpl.php files.
|
| CVE-2008-0273 |
Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before
5.6, when Internet Explorer 6 is used, allows remote attackers to
conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte
sequences, which are not processed as UTF-8 by Drupal's HTML
filtering, but are processed as UTF-8 by Internet Explorer,
effectively removing characters from the document and defeating the
HTML protection mechanism.
|
| CVE-2008-0268 |
Cross-site scripting (XSS) vulnerability in view.php in eTicket
1.5.5.2 allows remote attackers to inject arbitrary web script or HTML
via the s parameter.
|
| CVE-2008-0265 |
Multiple cross-site scripting (XSS) vulnerabilities in the Search
function in the web management interface in F5 BIG-IP 9.4.3 allow
remote attackers to inject arbitrary web script or HTML via the
SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp,
(3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in
tmui/Control/jspmap/tmui/system/log/; and (6) list.jsp in certain
directories.
|
| CVE-2008-0258 |
Cross-site scripting (XSS) vulnerability in index.php in PHP Running
Management (phpRunMan) before 1.0.3 allows remote attackers to inject
arbitrary web script or HTML via the message parameter.
|
| CVE-2008-0257 |
Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search
Engine 2.7 allows remote attackers to inject arbitrary web script or
HTML via the keywords parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-0241 |
Open redirect vulnerability in /idm/user/login.jsp in Sun Java System
Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote
attackers to redirect users to arbitrary web sites and conduct
phishing attacks via a URL in the nextPage parameter.
|
| CVE-2008-0240 |
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1
through SP3, 7.0, and 7.1 allows remote attackers to inject frames
from arbitrary web sites and conduct phishing attacks via the helpUrl
parameter, aka "frame injection."
|
| CVE-2008-0239 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System
Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote
attackers to inject arbitrary HTML or web script via the (1) cntry or
lang parameters to /idm/login.jsp, (2) resultsForm parameter to
/idm/account/findForSelect.jsp, or (3) activeControl parameter to
/idm/user/main.jsp.
|
| CVE-2008-0218 |
Cross-site scripting (XSS) vulnerability in admin/index.html in Merak
IceWarp Mail Server allows remote attackers to inject arbitrary web
script or HTML via the message parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2008-0208 |
Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums
2000 3.4.05 and earlier allows remote attackers to inject arbitrary
web script or HTML via the target parameter.
|
| CVE-2008-0207 |
Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6)
size, (7) search_days, or (8) show_page parameter to the default URI.
|
| CVE-2008-0206 |
Multiple cross-site scripting (XSS) vulnerabilities in
captcha\captcha.php in the Captcha! 2.5d and earlier plugin for
WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3)
captcha_ttfrange, or (4) captcha_secret parameter.
|
| CVE-2008-0204 |
Multiple cross-site scripting (XSS) vulnerabilities in
math-comment-spam-protection.php in the Math Comment Spam Protection
2.1 and earlier plugin for WordPress allow remote attackers to inject
arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2)
mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.
|
| CVE-2008-0203 |
Multiple cross-site scripting (XSS) vulnerabilities in
cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for
WordPress allow remote attackers to inject arbitrary web script or
HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR,
(5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10)
charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace,
(15) charsizemin, (16) charsizemax, (17) charanglemax, (18)
noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax,
(22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to
wp-admin/options-general.php.
|
| CVE-2008-0201 |
Cross-site scripting (XSS) vulnerability in index.php in
ExpressionEngine 1.2.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the URL parameter.
|
| CVE-2008-0200 |
Multiple cross-site scripting (XSS) vulnerabilities in
account/index.html in RotaBanner Local 3 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1) user or
(2) drop parameter.
|
| CVE-2008-0197 |
Multiple cross-site scripting (XSS) vulnerabilities in
wp-contact-form/options-contactform.php in the WP-ContactForm 1.5
alpha and earlier plugin for WordPress allow remote attackers to
inject arbitrary web script or HTML via the (1) wpcf_email, (2)
wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5)
wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to
wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element.
|
| CVE-2008-0193 |
Cross-site scripting (XSS) vulnerability in wp-db-backup.php in
WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows
remote attackers to inject arbitrary web script or HTML via the backup
parameter in a wp-db-backup.php action to wp-admin/edit.php.
|
| CVE-2008-0192 |
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9
and earlier allow remote attackers to inject arbitrary web script or
HTML via the popuptitle parameter to (1) wp-admin/post.php or (2)
wp-admin/page-new.php.
|
| CVE-2008-0190 |
Multiple cross-site scripting (XSS) vulnerabilities in
templates/example_template.php in AwesomeTemplateEngine allow remote
attackers to inject arbitrary web script or HTML via the (1)
data[title], (2) data[message], (3) data[table][1][item], (4)
data[table][1][url], or (5) data[poweredby] parameter.
|
| CVE-2008-0186 |
Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7
and possibly earlier allows remote attackers to inject arbitrary web
script or HTML via the page parameter, possibly related to
CVE-2008-0144.
|
| CVE-2008-0185 |
SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly
earlier versions allows remote attackers to execute arbitrary SQL
commands via the pid parameter in a profile page (possibly
profile.php).
|
| CVE-2008-0181 |
Cross-site scripting (XSS) vulnerability in the Admin portlet in
Liferay Portal 4.3.6 allows remote authenticated users to inject
arbitrary web script or HTML via the Shutdown message.
|
| CVE-2008-0180 |
Cross-site scripting (XSS) vulnerability in
themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows
remote authenticated users to inject arbitrary web script or HTML via
the Greeting field in a User Profile.
|
| CVE-2008-0179 |
Cross-site scripting (XSS) vulnerability in
service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows
remote attackers to inject arbitrary web script or HTML via the
User-Agent HTTP header, which is used when composing Forgot Password
e-mail messages in HTML format.
|
| CVE-2008-0178 |
Cross-site scripting (XSS) vulnerability in the Enterprise Admin
Session Monitoring component in Liferay Portal 4.3.6 allows remote
authenticated users to inject arbitrary web script or HTML via the
User-Agent HTTP header.
|
| CVE-2008-0155 |
Cross-site scripting (XSS) vulnerability in index.php in EvilBoard
0.1a (Alpha) allows remote attackers to inject arbitrary web script or
HTML via the c parameter.
|
| CVE-2008-0146 |
Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL
allows remote attackers to inject arbitrary web script or HTML via the
PATH_INFO to the top-level URI.
|
| CVE-2008-0134 |
Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz
Forums 2000 3.4.06 and earlier allows remote attackers to inject
arbitrary web script or HTML via the MAIL parameter.
|
| CVE-2008-0131 |
Cross-site scripting (XSS) vulnerability in login_form.asp in Instant
Softwares Dating Site allows remote attackers to inject arbitrary web
script or HTML via the msg parameter, a different product than
CVE-2006-6022. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2008-0125 |
Cross-site scripting (XSS) vulnerability in phpstats.php in Michael
Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary
web script or HTML via the baseDir parameter.
|
| CVE-2008-0124 |
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before
1.3-beta1 allows remote authenticated users to inject arbitrary web
script or HTML via (1) the "Real name" field in Personal Settings,
which is presented to readers of articles; or (2) a file upload, as
demonstrated by a .htm, .html, or .js file.
|
| CVE-2008-0123 |
Cross-site scripting (XSS) vulnerability in install.php for Moodle
1.8.3, and possibly other versions before 1.8.4, allows remote
attackers to inject arbitrary web script or HTML via the dbname
parameter. NOTE: this issue only exists until the installation is
complete.
|
| CVE-2008-0093 |
Multiple cross-site scripting (XSS) vulnerabilities in newticket.php
in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to
inject arbitrary web script or HTML via the (1) Name and (2) Subject
parameters.
|
| CVE-2008-0092 |
Cross-site scripting (XSS) vulnerability in index.php in the search
module in Appalachian State University phpWebSite 1.4.0 allows remote
attackers to inject arbitrary web script or HTML via the search
parameter.
|
| CVE-2008-0005 |
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before
2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset,
which allows remote attackers to conduct cross-site scripting (XSS)
attacks using UTF-7 encoding.
|
| CVE-2007-6751 |
Cross-site scripting (XSS) vulnerability in the MailForm plugin before
1.20 for Movable Type allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2007-6730 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the web
management interface in the ZyXEL P-330W router allow remote attackers
to hijack the authentication of administrators for requests that (1)
enable remote router management via goform/formRmtMgt or (2) modify
the administrator password via goform/formPasswordSetup.
|
| CVE-2007-6729 |
Cross-site scripting (XSS) vulnerability in the web management
interface in the ZyXEL P-330W router allows remote attackers to inject
arbitrary web script or HTML via the pingstr parameter and other
unspecified vectors.
|
| CVE-2007-6728 |
Cross-site scripting (XSS) vulnerability in XMB 1.5 allows remote
attackers to inject arbitrary web script or HTML via the MSN field
during user registration.
|
| CVE-2007-6726 |
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and
0.4.2, as used in Apache Struts and other products, allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors involving (1) xip_client.html and (2) xip_server.html in
src/io/.
|
| CVE-2007-6707 |
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco
Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier
firmware allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors, a different issue than CVE-2007-3574.
|
| CVE-2007-6704 |
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass
4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon
sequences are enabled, allow remote attackers to inject arbitrary web
script or HTML via the query string to (1) my.activation.php3 and (2)
my.logon.php3.
|
| CVE-2007-6700 |
Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web
interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers
to inject arbitrary web script or HTML via the cmd parameter.
|
| CVE-2007-6696 |
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar
1.1.6 allow remote attackers to inject arbitrary web script or HTML
via (1) an event description, (2) the query string to pref.php, and
(3) the adv parameter to search.php. NOTE: vector 1 requires user
authentication.
|
| CVE-2007-6695 |
Cross-site scripting (XSS) vulnerability in index.php in Drake CMS
0.4.9 allows remote attackers to inject arbitrary web script or HTML
via the option parameter.
|
| CVE-2007-6687 |
Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery
before 2.2.4 allow remote attackers to inject arbitrary web script or
HTML via crafted filenames to the (1) Core or (2) add-item modules; or
via (3) HTTP PROPPATCH in the WebDAV module.
|
| CVE-2007-6677 |
Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam
Image 0.2.4 and earlier plugin for WordPress allows remote attackers
to inject arbitrary web script or HTML via the comment field in the
comment form.
|
| CVE-2007-6674 |
Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare
Database allows remote attackers to inject arbitrary web script or
HTML via the Arayalim parameter.
|
| CVE-2007-6673 |
Cross-site scripting (XSS) vulnerability in Makale Scripti allows
remote attackers to inject arbitrary web script or HTML via the ara
parameter to the default URI under Ara/ in a search action.
|
| CVE-2007-6669 |
Cross-site scripting (XSS) vulnerability in search.php in PHCDownload
1.1.0 allows remote attackers to inject arbitrary web script or HTML
via the string parameter.
|
| CVE-2007-6659 |
Multiple cross-site scripting (XSS) vulnerabilities in 2z project
0.9.6.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) contentshort or (2) contentfull parameter in an addnews
action to the default URI; (3) the content parameter in a pm write
action to 2z/admin.php; (4) the referer parameter to
templates/default/usermenu.tpl, accessed through index.php; or the (5)
newavatar or (6) newphoto parameter in a profile action to the default
URI under 2z/.
|
| CVE-2007-6646 |
Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1,
and possibly other versions before 1.1.0, allow remote attackers to
inject arbitrary web script or HTML via (1) the return parameter to
user/remindPassword, (2) the q parameter to the category script, (3)
the return parameter to the order script, or (4) the email parameter
to user/remindComplete.
|
| CVE-2007-6643 |
Cross-site scripting (XSS) vulnerability in the com_poll component in
Joomla! before 1.5 RC4 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2007-6641 |
Cross-site scripting (XSS) vulnerability in dir.php in milliscripts
Redirection allows remote attackers to inject arbitrary web script or
HTML via the cat parameter in a browse action.
|
| CVE-2007-6637 |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash
Player allow remote attackers to inject arbitrary web script or HTML
via a crafted SWF file, related to "pre-generated SWF files" and Adobe
Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction:
vector is already covered by CVE-2007-6244.1.
|
| CVE-2007-6633 |
Multiple cross-site scripting (XSS) vulnerabilities in
FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to
inject arbitrary web script or HTML via (1) the cat_name parameter to
faq.php; and unspecified parameters to the (2) add categories, (3)
edit categories, (4) delete categories, (5) add faq, (6) edit faq, and
(7) delete faq Admin scripts.
|
| CVE-2007-6617 |
Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA
Enterprise Edition before 3.12.1 allows remote attackers to inject
arbitrary web script or HTML, which is not properly handled when
generating error messages, as demonstrated by input originally sent in
the URI to secure/CreateIssue. NOTE: some of these details are
obtained from third party information.
|
| CVE-2007-6616 |
Cross-site scripting (XSS) vulnerability in simpleforum.cgi in
SimpleForum 4.6.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the searchkey parameter in a search
action. NOTE: some of these details are obtained from third party
information.
|
| CVE-2007-6611 |
Cross-site scripting (XSS) vulnerability in view.php in Mantis before
1.1.0 allows remote attackers to inject arbitrary web script or HTML
via a filename, related to bug_report.php.
|
| CVE-2007-6608 |
Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio
0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) LAST and (2) FIRST parameters to
admin/staff_del_confirm.php, (3) the name parameter to
admin/theme_del_confirm.php, or (4) the themeName parameter to
admin/theme_preview.php.
|
| CVE-2007-6597 |
Multiple cross-site scripting (XSS) vulnerabilities in IPortalX before
Build 033 allow remote attackers to inject arbitrary web script or
HTML via the (1) KW and (2) SF parameters to forum/login_user.asp, and
(3) the Date parameter to blogs.asp.
|
| CVE-2007-6589 |
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and
SeaMonkey before 1.1.7 does not update the origin domain when
retrieving the inner URL parameter yields an HTTP redirect, which
allows remote attackers to conduct cross-site scripting (XSS) attacks
via a jar: URI, a different vulnerability than CVE-2007-5947.
|
| CVE-2007-6588 |
Cross-site scripting (XSS) vulnerability in PHCDownload 1.10 allows
remote attackers to inject arbitrary web script or HTML via the
username field in an unspecified component. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-6574 |
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the origin parameter to work/work.php in a
display_upload_form action, or the forum parameter to (2)
forum/viewforum.php or (3) forum/viewthread.php.
|
| CVE-2007-6572 |
Cross-site scripting (XSS) vulnerability in Sun Java System Web Server
6.1 before SP8 and 7.0 before Update 1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, aka BugID
6566204.
|
| CVE-2007-6571 |
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy
Server 3.6 before SP11 on Windows allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, aka BugID
6611356.
|
| CVE-2007-6570 |
Cross-site scripting (XSS) vulnerability in the View URL Database
functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and
3.x before 3.6 SP11 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, aka BugID 6566309.
|
| CVE-2007-6569 |
Cross-site scripting (XSS) vulnerability in the View Error Log
functionality in Sun Java System Web Proxy Server 4.x before 4.0.6
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, aka BugID 6566246.
|
| CVE-2007-6564 |
Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS
1.0.4.2 allows remote attackers to inject arbitrary web script or HTML
via the com_option parameter.
|
| CVE-2007-6560 |
Multiple cross-site scripting (XSS) vulnerabilities in Logaholic
before 2.0 RC8 allow remote attackers to inject arbitrary web script
or HTML via (1) the newconfname parameter to profiles.php or (2) the
conf parameter to index.php.
|
| CVE-2007-6545 |
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before
1.6.1 allow remote attackers to inject arbitrary web script or HTML
via (1) the subject parameter to modules/news/submit.php; (2) the
PATH_INFO to modules/news/index.php, possibly related to the
XoopsPageNav class; or (3) an avatar image to edituser.php.
|
| CVE-2007-6541 |
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0
allow remote attackers to inject arbitrary web script or HTML via (1)
the topic parameter in a viewtopic action, or the (2) newsyear or (3)
newsmonth parameter in a newsarchive action to the default URI in
patch/.
|
| CVE-2007-6540 |
SQL injection vulnerability in neuron news 1.0 allows remote attackers
to execute arbitrary SQL commands via the q parameter to the default
URI in patch/.
|
| CVE-2007-6526 |
Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in
TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web
script or HTML via the area_name parameter.
|
| CVE-2007-6489 |
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series
One CMS 1.4.3 allow remote attackers to inject arbitrary web script or
HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a
guestbook action to index.php, and unspecified other vectors.
|
| CVE-2007-6486 |
Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka
the shoutbox) in LineShout 1.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) username (nickname) or (2)
message parameter. NOTE: some of these details are obtained from third
party information.
|
| CVE-2007-6477 |
Cross-site scripting (XSS) vulnerability in the on-line help feature
in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2007-6474 |
Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4
allow remote attackers to inject arbitrary web script or HTML via the
newdir parameter to index_3x.php, and unspecified other vectors.
|
| CVE-2007-6465 |
Multiple cross-site scripting (XSS) vulnerabilities in ganglia-web in
Ganglia before 3.0.6 allow remote attackers to inject arbitrary web
script or HTML via the (1) c and (2) h parameters to (a)
web/host_gmetrics.php; the (3) G, (4) me, (5) x, (6) n, (7) v, (8) l,
(9) vl, and (10) st parameters to (b) web/graph.php; and the (11) c,
(12) G, (13) h, (14) r, (15) m, (16) s, (17) cr, (18) hc, (19) sh,
(20) p, (21) t, (22) jr, (23) js, (24) gw, (25) z, and (26) gs
parameters to (c) web/get_context.php. NOTE: some of these details
are obtained from third party information.
|
| CVE-2007-6463 |
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel
in PHP Real Estate Classifieds allow remote attackers to inject
arbitrary web script or HTML via unspecified "text areas/boxes."
|
| CVE-2007-6461 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject
arbitrary web script or HTML via (1) the query string in an index
action, related to the savesearch JavaScript function; and (2) the
details parameter in a details action, related to the History tab and
the getHistory JavaScript function.
|
| CVE-2007-6460 |
Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy
Server before 0.101 allow remote attackers to inject arbitrary web
script or HTML via the URI, which is later displayed by (1) log.php or
(2) logerror.php, a different vulnerability than CVE-2007-6459.
|
| CVE-2007-6455 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Mambo 4.6.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) Itemid parameter in a com_frontpage option and the
(2) option parameter.
|
| CVE-2007-6452 |
Unspecified vulnerability in the benchmark reporting system in Google
Web Toolkit (GWT) before 1.4.61 has unknown impact and attack vectors,
possibly related to cross-site scripting (XSS).
|
| CVE-2007-6423 |
** DISPUTED **
Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server
2.2.x before 2.2.7-dev, when running on Windows, allows remote
attackers to trigger memory corruption via a long URL. NOTE: the
vendor could not reproduce this issue.
|
| CVE-2007-6422 |
The balancer_handler function in mod_proxy_balancer in the Apache HTTP
Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is
used, allows remote authenticated users to cause a denial of service
(child process crash) via an invalid bb variable.
|
| CVE-2007-6421 |
Cross-site scripting (XSS) vulnerability in balancer-manager in
mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6
allows remote attackers to inject arbitrary web script or HTML via the
(1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
|
| CVE-2007-6420 |
Cross-site request forgery (CSRF) vulnerability in the
balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x
allows remote attackers to gain privileges via unspecified vectors.
|
| CVE-2007-6412 |
Direct static code injection vulnerability in wiki/index.php in
Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote
attackers to inject arbitrary PHP code via an editcomments action.
|
| CVE-2007-6407 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli
Provisioning Manager Express allow remote attackers to inject
arbitrary web script or HTML via the (1) "assess modification," (2)
user-id, and other unspecified fields to the /tpmx URI; or (3)
involving unspecified vectors related to "error processing."
|
| CVE-2007-6406 |
Multiple cross-site scripting (XSS) vulnerabilities in CA (formerly
Computer Associates) eTrust Threat Management Console allow remote
attackers to inject arbitrary web script or HTML via the IP Address
field and other unspecified fields.
|
| CVE-2007-6390 |
Cross-site request forgery (CSRF) vulnerability in the mycalendar
plugin before 0.13 for Serendipity allows remote attackers to perform
actions as blog administrators, which can be leveraged to conduct
cross-site scripting (XSS) attacks on the blog page.
|
| CVE-2007-6388 |
Cross-site scripting (XSS) vulnerability in mod_status in the Apache
HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2
through 1.3.39, when the server-status page is enabled, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2007-6375 |
Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier
allow remote attackers to execute arbitrary SQL commands via the (1)
sort_mode parameter to wiki/list_pages.php and the (2) highlight
parameter to search/index.php. NOTE: the researcher also reported
injection via JavaScript code in the Search box, but this is probably
a forced SQL error or other separate primary issue.
|
| CVE-2007-6374 |
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0
and earlier allow remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to (1) users/register.php or (2)
search/index.php, or an editcomments action in (3) wiki/index.php or
(4) forums/index.php. NOTE: the error parameter to users/login.php is
covered by CVE-2006-3103.
|
| CVE-2007-6367 |
Multiple cross-site scripting (XSS) vulnerabilities in the guestbook
in SineCMS 2.3.4 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) username (user) or (2)
comment (commento) field, different vectors than CVE-2007-2357.
|
| CVE-2007-6365 |
Cross-site scripting (XSS) vulnerability in modules/ecal/display.php
in the Event Calendar in bcoos 1.0.10 allows remote attackers to
inject arbitrary web script or HTML via the month parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information. NOTE: the day and year vectors
are covered by CVE-2007-6274.
|
| CVE-2007-6364 |
Cross-site scripting (XSS) vulnerability in modificarPerfil.php in
JLMForo System allows remote authenticated users to inject arbitrary
web script or HTML via a signature.
|
| CVE-2007-6346 |
Cross-site scripting (XSS) vulnerability in Rainboard before 2.10
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-6343 |
Cross-site scripting (XSS) vulnerability in HP OpenView Network Node
Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-6321 |
Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2,
2007-12-09, and earlier versions, when using Internet Explorer, allows
remote attackers to inject arbitrary web script or HTML via style
sheets containing expression commands.
|
| CVE-2007-6316 |
Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server
before 3.8 allows remote attackers to inject arbitrary web script or
HTML via the URI path in an HTTP GET request, which is activated by
administrators viewing log files via the Trace page.
|
| CVE-2007-6312 |
Cross-site scripting (XSS) vulnerability in the logon page in Web
Reporting Tools portal in Websense Enterprise and Web Security Suite
6.3 allows remote attackers to inject arbitrary web script or HTML via
the username field.
|
| CVE-2007-6310 |
Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme
RC4 10.9.2007 allow remote attackers to inject arbitrary web script or
HTML via the handler parameter to (1) index.php and possibly (2)
admin/index.php, and (3) the topic parameter to modules/feed/feed.php
(aka modules/feed.php).
|
| CVE-2007-6309 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
webSPELL 4.1.2 allow remote attackers to inject arbitrary web script
or HTML via (1) the galleryID parameter in a usergallery upload
action; or the (2) upID, (3) tag, (4) month, (5) userID, or (6) year
parameter in a calendar announce action.
|
| CVE-2007-6308 |
Cross-site scripting (XSS) vulnerability in HttpLogger 0.8.1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-6307 |
Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php
in wwwstats 3.21 allow remote attackers to inject arbitrary web script
or HTML via (1) the link parameter or (2) the User-Agent HTTP header.
|
| CVE-2007-6306 |
Multiple cross-site scripting (XSS) vulnerabilities in the image map
feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary
web script or HTML via the (1) chart name or (2) chart tool tip text;
or the (3) href, (4) shape, or (5) coords attribute of a chart area.
|
| CVE-2007-6301 |
Cross-site scripting (XSS) vulnerability in compose.php in
OpenNewsletter 2.5 and earlier allows remote attackers to inject
arbitrary web script or HTML via the type parameter.
|
| CVE-2007-6298 |
Cross-site scripting (XSS) vulnerability in the Shoutbox module for
Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users
to inject arbitrary web script or HTML via Shoutbox block messages.
|
| CVE-2007-6297 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPMyChat
0.14.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) LIMIT parameter to chat/deluser.php3, the (2) Link
parameter to chat/edituser.php3, or the (3) LastCheck or (4) B
parameter to chat/users_popupL.php3. NOTE: the FontName vectors for
start_page.css.php3 and style.css.php3 are already covered by
CVE-2005-1619. The medium vectors for start_page.css.php3
(start_page.css.php) and style.css.php3 (style.css.php), and the From
vector for users_popupL.php3 (users_popupL.php), are already covered
by CVE-2005-3991.
|
| CVE-2007-6296 |
PHP remote file inclusion vulnerability in users_popupL.php3 in
phpMyChat 0.14.5 allows remote attackers to execute arbitrary PHP code
via a URL in the From parameter.
|
| CVE-2007-6295 |
Cross-site scripting (XSS) vulnerability in the WebRunMenuFrame page
in the online meeting center template in IBM Lotus Sametime before 8.0
allows remote attackers to inject arbitrary web script or HTML via the
URI.
|
| CVE-2007-6287 |
Cross-site scripting (XSS) vulnerability in the login page in Lxlabs
HyperVM 2.0 allows remote attackers to inject arbitrary web script or
HTML via the frm_emessage parameter, a different vector than
CVE-2006-6649. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2007-6274 |
Multiple cross-site scripting (XSS) vulnerabilities in
modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) day or (2) year parameter.
|
| CVE-2007-6270 |
Multiple cross-site scripting (XSS) vulnerabilities in Absolute News
Manager.NET 5.1 allow remote attackers to inject arbitrary web script
or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2)
template parameter to pages/default.aspx.
|
| CVE-2007-6244 |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash
Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote
attackers to inject arbitrary web script or HTML via (1) a SWF file
that uses the asfunction: protocol or (2) the navigateToURL function
when used with the Flash Player ActiveX Control in Internet Explorer.
|
| CVE-2007-6243 |
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up
to 7.0.70.0 does not sufficiently restrict the interpretation and
usage of cross-domain policy files, which makes it easier for remote
attackers to conduct cross-domain and cross-site scripting (XSS)
attacks.
|
| CVE-2007-6232 |
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin
0.1.0 allows remote attackers to inject arbitrary web script or HTML
via the error parameter in an error page action.
|
| CVE-2007-6219 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool
Security Manager 1.3.0 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2007-6205 |
Cross-site scripting (XSS) vulnerability in the remote RSS sidebar
plugin (serendipity_plugin_remoterss) in S9Y Serendipity before 1.2.1
allows remote attackers to inject arbitrary web script or HTML via a
link in an RSS feed.
|
| CVE-2007-6203 |
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method
specifier header from an HTTP request when it is reflected back in a
"413 Request Entity Too Large" error message, which might allow
cross-site scripting (XSS) style attacks using web client components
that can send arbitrary headers in requests, as demonstrated via an
HTTP request containing an invalid Content-length value, a similar
issue to CVE-2006-3918.
|
| CVE-2007-6196 |
Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail
before 5.2 allows remote attackers to inject arbitrary web script or
HTML via the func parameter.
|
| CVE-2007-6173 |
Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay
Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary
web script or HTML via the emailAddress parameter in a Send New
Password action, a different vector than CVE-2007-6055. NOTE: some of
these details are obtained from third party information.
|
| CVE-2007-6162 |
Cross-site scripting (XSS) vulnerability in index.php in FMDeluxe
2.1.0 allows remote attackers to inject arbitrary web script or HTML
via the id parameter in a category action.
|
| CVE-2007-6160 |
Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x
and earlier allows remote attackers to inject arbitrary web script or
HTML via the aarstal parameter in a yeardetail action.
|
| CVE-2007-6157 |
Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery
0.1.3 allows remote attackers to inject arbitrary web script or HTML
via the album parameter.
|
| CVE-2007-6156 |
Multiple cross-site scripting (XSS) vulnerabilities in
base_qry_main.php in Base Analysis and Security Engine (BASE) before
1.3.9 allow remote attackers to inject arbitrary web script or HTML
via the (1) sig[0] and (2) sig[1] parameters.
|
| CVE-2007-6142 |
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just
another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject
arbitrary web script or HTML via the (1) show parameter to index.php
and the (2) print parameter to print.php. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-6141 |
Cross-site scripting (XSS) vulnerability in vBTube.php in vBTube 1.1
Beta allows remote attackers to inject arbitrary web script or HTML
via the search parameter.
|
| CVE-2007-6136 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
M2Scripts MySpace Scripts Poll Creator allow remote attackers to
inject arbitrary web script or HTML via the (1) title, (2) intro, and
(3) question parameters, and (4) unspecified answer parameters, in a
create_new action. NOTE: some of these details are obtained from third
party information.
|
| CVE-2007-6135 |
Cross-site scripting (XSS) vulnerability in phpslideshow.php in
PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to
inject arbitrary web script or HTML via the directory parameter.
NOTE: this issue was originally reported for toonchapter8.php, but
this is probably a site-specific name, since the PHPSlideShow
distribution does not contain that file.
|
| CVE-2007-6126 |
Multiple cross-site scripting (XSS) vulnerabilities in project alumni
1.0.9 and earlier allow remote attackers to inject arbitrary web
script or HTML via the year parameter to (1) xml/index.php; or (2) the
year parameter to view.page.inc.php, which is reachable through a view
action to the top-level index.php.
|
| CVE-2007-6124 |
Cross-site scripting (XSS) vulnerability in signin.php in Softbiz
Freelancers Script 1 allows remote attackers to inject arbitrary web
script or HTML via the errmsg parameter.
|
| CVE-2007-6110 |
Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6
allows remote attackers to inject arbitrary web script or HTML via the
sort parameter.
|
| CVE-2007-6104 |
Cross-site scripting (XSS) vulnerability in the Instant Web Publishing
feature in FileMaker Pro 7 and 8, Server 7 and 8, and Developer 7
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-6102 |
Cross-site scripting (XSS) vulnerability in Feed to JavaScript
(Feed2JS) 1.91 allows remote attackers to inject arbitrary web script
or HTML via a URL in a feed.
|
| CVE-2007-6100 |
Cross-site scripting (XSS) vulnerability in
libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when
logins are authenticated with the cookie auth_type, allows remote
attackers to inject arbitrary web script or HTML via the convcharset
parameter to index.php, a different vulnerability than CVE-2005-0992.
|
| CVE-2007-6090 |
Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan
1.7.5 allows remote attackers to inject arbitrary web script or HTML
via the file parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-6085 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
VigileCMS 1.4 allow remote attackers to inject arbitrary web script or
HTML via the message field in the (1) vedipm or (2) live_chat module.
|
| CVE-2007-6055 |
Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay
Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web
script or HTML via the login parameter. NOTE: this issue reportedly
exists because of a regression that followed a fix at an unspecified
earlier date.
|
| CVE-2007-6054 |
Cross-site scripting (XSS) vulnerability in the login page in the
management interface in the Aruba 800 Mobility Controller 2.5.4.18 and
earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to
inject arbitrary web script or HTML via the PATH_INFO to the /screens
URI, related to the url variable.
|
| CVE-2007-6037 |
Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in
Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject
arbitrary web script or HTML via the standalone parameter and other
unspecified parameters.
|
| CVE-2007-6003 |
Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the
Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers
to inject arbitrary web script or HTML via the url parameter. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2007-6002 |
Cross-site scripting (XSS) vulnerability in Fenriru (1) Sleipnir
2.5.17 R2 and earlier and (2) Grani 3.0 and earlier allows remote
attackers to inject arbitrary web script or HTML via the Search field
in a search for additions to the Favorites section.
|
| CVE-2007-6001 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Bandersnatch 0.4 allow remote attackers to inject arbitrary web script
or HTML via the (1) func or (2) date parameter, or the jid parameter
in a (3) log or (4) user action, a different vulnerability than
CVE-2007-3910.
|
| CVE-2007-5993 |
Cross-site scripting (XSS) vulnerability in Visionary Technology in
Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote
attackers to inject arbitrary web script or HTML via the searchtype
parameter.
|
| CVE-2007-5991 |
SQL injection vulnerability in index.php in ExoPHPdesk allows remote
attackers to execute arbitrary SQL commands via the user parameter in
a profile fn action.
|
| CVE-2007-5990 |
Cross-site scripting (XSS) vulnerability in ExoPHPdesk allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors in a user profile, possibly the (1) name and (2) website
parameters to register.php.
|
| CVE-2007-5985 |
Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker
before 1.4.5 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors to (1) account.php, (2) moresmiles.php,
or (3) recover.php; or (4) the "to" parameter to usercp.php.
|
| CVE-2007-5983 |
Cross-site scripting (XSS) vulnerability in index.php in Justin
Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to
inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).
|
| CVE-2007-5982 |
Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4,
2.0.5, and possibly other versions allow remote attackers to inject
arbitrary web script or HTML via the (1) room parameter to
sources/frame.php, the (2) theme_c parameter to help/index.php, or the
(3) INSTALL_X7CHATVERSION parameter to upgradev1.php.
|
| CVE-2007-5980 |
Cross-site scripting (XSS) vulnerability in home/rss.php in eggblog
before 3.1.1 allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO (PHP_SELF).
|
| CVE-2007-5979 |
Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5
Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows
remote attackers to inject arbitrary web script or HTML via the
backurl parameter.
|
| CVE-2007-5977 |
Cross-site scripting (XSS) vulnerability in db_create.php in
phpMyAdmin before 2.11.2.1 allows remote authenticated users with
CREATE DATABASE privileges to inject arbitrary web script or HTML via
a hex-encoded IMG element in the db parameter in a POST request, a
different vulnerability than CVE-2006-6942.
|
| CVE-2007-5961 |
Cross-site scripting (XSS) vulnerability in the Red Hat Network
channel search feature, as used in RHN and Red Hat Network Satellite
before 5.0.2, allows remote attackers to inject arbitrary web script
or HTML via unknown vectors.
|
| CVE-2007-5955 |
Cross-site scripting (XSS) vulnerability in updir.php in UPDIR.NET
before 2.04 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2007-5954 |
Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo
System allows remote attackers to inject arbitrary web script or HTML
via the clave parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-5952 |
Cross-site scripting (XSS) vulnerability in admin/index.php in Helios
Calendar 1.2.1 Beta allows remote attackers to inject arbitrary web
script or HTML via the username parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-5950 |
Cross-site scripting (XSS) vulnerability in NetCommons before 1.0.11,
and 1.1.x before 1.1.2, allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, a different vulnerability
than CVE-2006-4165.
|
| CVE-2007-5949 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk
6.2 allows remote authenticated users to inject arbitrary web script
or HTML via the Description parameter in a Maximo change action.
|
| CVE-2007-5948 |
Multiple cross-site scripting (XSS) vulnerabilities in main.php in
SF-Shoutbox 1.2.1 through 1.4 allow remote attackers to inject
arbitrary web script or HTML via the (1) nick (aka Name) and (2) shout
(aka Shout) parameters.
|
| CVE-2007-5947 |
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and
SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME
type, and considers HTML documents within a jar archive to have the
same origin as the inner URL, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via a jar: URI.
|
| CVE-2007-5944 |
Cross-site scripting (XSS) vulnerability in Servlet Engine / Web
Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through
5.1.1.16 allows remote attackers to inject arbitrary web script or
HTML via the Expect HTTP header. NOTE: this might be the same issue
as CVE-2006-3918, but there are insufficient details to be sure.
|
| CVE-2007-5932 |
Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content
Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web
script or HTML via unspecified form fields related to the (1) search
function, (2) advanced search function, and possibly other components.
|
| CVE-2007-5930 |
Cross-site scripting (XSS) vulnerability in the web interface in
Cerberus FTP Server before 2.46 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-5924 |
Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task
in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-5923 |
Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in
CA (formerly Computer Associates) eTrust SiteMinder Agent allows
remote attackers to inject arbitrary web script or HTML via the
SMAUTHREASON parameter, a different vector than CVE-2005-2204.
|
| CVE-2007-5891 |
Multiple cross-site scripting (XSS) vulnerabilities in jsp/Login.do in
ManageEngine OpManager MSP Edition and OpManager 7.0 allow remote
attackers to inject arbitrary web script or HTML via the (1)
requestid, (2) fileid, (3) woMode, and (2) woID parameters. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2007-5888 |
Cross-site scripting (XSS) vulnerability in displayecard.php in
Coppermine Photo Gallery (CPG) before 1.4.14 allows remote attackers
to inject arbitrary web script or HTML via the data parameter.
|
| CVE-2007-5858 |
WebKit in Safari in Apple Mac OS X 10.4.11 and 10.5.1, iPhone 1.0
through 1.1.2, and iPod touch 1.1 through 1.1.2 allows remote
attackers to "navigate the subframes of any other page," which can be
leveraged to conduct cross-site scripting (XSS) attacks and obtain
sensitive information.
|
| CVE-2007-5854 |
Launch Services in Apple Mac OS X 10.4.11 and 10.5.1 does not treat
HTML files as unsafe content, which allows attackers to conduct
cross-site scripting (XSS) attacks or obtain sensitive information via
a crafted HTML file.
|
| CVE-2007-5834 |
Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows
remote attackers to inject arbitrary web script or HTML via a SCRIPT
element in a news post.
|
| CVE-2007-5833 |
Multiple cross-site scripting (XSS) vulnerabilities in BosDev
BosMarket Business Directory System allow remote authenticated users
to inject arbitrary web script or HTML via (1) user info (account
details) or (2) a post.
|
| CVE-2007-5817 |
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote
attackers to perform certain privileged actions via a (1) del, (2)
delbackup, (3) res, or (4) ren action. NOTE: this issue can be
leveraged to conduct cross-site scripting (XSS) and possibly other
attacks.
|
| CVE-2007-5809 |
Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00
through 03-10, as used by certain Cosminexus products, allows remote
attackers to inject arbitrary web script or HTML via unspecified HTTP
requests that trigger creation of a server-status page.
|
| CVE-2007-5806 |
Cross-site scripting (XSS) vulnerability in
Services/Utilities/classes/class.ilUtil.php in ILIAS 3.8.3 and earlier
allows remote attackers to inject arbitrary web script or HTML via
attributes inside a domain-name string in the (1) mailing or (2) forum
component, as demonstrated using the style and onmouseover HTML
attributes.
|
| CVE-2007-5803 |
Multiple cross-site scripting (XSS) vulnerabilities in CGI programs in
Nagios before 2.12 might allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors, a different issue than
CVE-2007-5624 and CVE-2008-1360.
|
| CVE-2007-5798 |
Multiple cross-site scripting (XSS) vulnerabilities in
uddigui/navigateTree.do in the UDDI user console in IBM WebSphere
Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow
remote attackers to inject arbitrary web script or HTML via the (1)
keyField, (2) nameField, (3) valueField, and (4) frameReturn
parameters.
|
| CVE-2007-5796 |
Cross-site scripting (XSS) vulnerability in the management console in
Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows
remote attackers to inject arbitrary web script or HTML by modifying
the URL that is used for loading Certificate Revocation Lists.
|
| CVE-2007-5778 |
Mobile Spy (1) stores login credentials in cleartext under the
RetinaxStudios registry key, and (2) sends login credentials and log
data over a cleartext HTTP connection, which allows attackers to
obtain sensitive information by reading the registry or sniffing the
network.
|
| CVE-2007-5736 |
Unrestricted file upload vulnerability in upload.php in SeeBlick 1.0
Beta allows remote attackers to upload arbitrary files via unspecified
vectors. NOTE: these files are stored with .html extensions, so the
scope of the attack might be limited to resource consumption and
possibly XSS.
|
| CVE-2007-5728 |
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1,
and possibly 4.1.2, allows remote attackers to inject arbitrary web
script or HTML via certain input available in PHP_SELF in (1)
redirect.php, possibly related to (2) login.php, different vectors
than CVE-2007-2865.
|
| CVE-2007-5727 |
Incomplete blacklist vulnerability in the stripScripts function in
common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other
versions, allows remote attackers to conduct cross-site scripting
(XSS) attacks and inject arbitrary web script or HTML via XSS
sequences without SCRIPT tags in the description parameter to (1)
tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover
event in a b tag.
|
| CVE-2007-5725 |
Multiple cross-site scripting (XSS) vulnerabilities in Smart-Shop
allow remote attackers to inject arbitrary web script or HTML via (1)
the email parameter to index.php; or the command parameter to
index.php in (2) the default action for the home page, (3) a
currencies action, or (4) a basket action.
|
| CVE-2007-5724 |
Multiple cross-site scripting (XSS) vulnerabilities in Omnistar Live
allow remote attackers to inject arbitrary web script or HTML via (1)
the category_id parameter to users/kb.php, and possibly (3) the Email
Box field in profile.php.
|
| CVE-2007-5710 |
Cross-site scripting (XSS) vulnerability in
wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers
to inject arbitrary web script or HTML via the posts_columns array
parameter.
|
| CVE-2007-5703 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON
Registration Authority Web Interface 1.0 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-5702 |
Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions
(aka the login box) in the Novell OpenSUSE SWAMP Workflow
Administration and Management Platform 1.x allows remote attackers to
inject arbitrary web script or HTML via the username parameter. NOTE:
some of these details are obtained from third party information.
|
| CVE-2007-5698 |
Cross-site scripting (XSS) vulnerability in default.asp in CREApark
GOLD KOY PORTALI allows remote attackers to inject arbitrary web
script or HTML via the aranan parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-5692 |
Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8
allow remote attackers to inject arbitrary web script or HTML via (1)
the lang parameter to integrator.php; (2) the token parameter in a New
Password action, (3) the nid_acl parameter in a Folder Properties
action, or (4) the uid parameter in a Modify User action to
command.php; or (5) the target parameter to index.php, different
vectors than CVE-2006-3320.
|
| CVE-2007-5683 |
Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki
1.9.8.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via (1) the username parameter to the password reminder
page (tiki-remind_password.php), (2) IMG tags in wiki pages, and (3)
the local_php parameter to db/tiki-db.php.
|
| CVE-2007-5677 |
Cross-site scripting (XSS) vulnerability in shoutbox/blocco.php in
Hackish BETA 1.1 allows remote attackers to inject arbitrary web
script or HTML via the go_shout parameter.
|
| CVE-2007-5673 |
Cross-site scripting (XSS) vulnerability in cgi-bin/webif.exe in ifnet
WebIf allows remote attackers to inject arbitrary web script or HTML
via the cmd parameter.
|
| CVE-2007-5649 |
Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative
Digital Resources SocketMail 2.2.1 allows remote attackers to inject
arbitrary web script or HTML via the lost_id parameter.
|
| CVE-2007-5648 |
Multiple cross-site scripting (XSS) vulnerabilities in rnote.php in
rNote 0.9.7.5 allow remote attackers to inject arbitrary web script or
HTML via the (1) d or the (2) u parameter.
|
| CVE-2007-5647 |
Multiple cross-site scripting (XSS) vulnerabilities in SocketKB 1.1.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) art_id or (2) node parameter in an article action to the default
URI.
|
| CVE-2007-5629 |
Cross-site scripting (XSS) vulnerability in admin/logon.asp in
ShoppingTree CandyPress Store 4.1 allows remote attackers to inject
arbitrary web script or HTML via the msg parameter, a different vector
than CVE-2007-2804. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-5625 |
Cross-site scripting (XSS) vulnerability in filename.asp in ASP Site
Search SearchSimon Lite 1.0 allows remote attackers to inject
arbitrary web script or HTML via the QUERY parameter.
|
| CVE-2007-5624 |
Cross-site scripting (XSS) vulnerability in Nagios 2.x before 2.10
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors to unspecified CGI scripts.
|
| CVE-2007-5621 |
Multiple cross-site scripting (XSS) vulnerabilities in the Token
module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used
by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node
Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote
authenticated users with a post comments privilege to inject arbitrary
web script or HTML via unspecified vectors related to (1) comments,
(2) vocabulary names, (3) term names, and (4) usernames.
|
| CVE-2007-5613 |
Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay
Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web
script or HTML via unspecified parameters and cookies.
|
| CVE-2007-5598 |
Cross-site scripting (XSS) vulnerability in Weblinks for Drupal 4.7.x
before 4.7.x-1.0 and 5.x before 5.x-1.8 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-5596 |
The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3
places the .html extension on a whitelist, which allows remote
attackers to conduct cross-site scripting (XSS) attacks by uploading
.html files.
|
| CVE-2007-5589 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
before 2.11.1.2 allow remote attackers to inject arbitrary web script
or HTML via certain input available in (1) PHP_SELF in (a)
server_status.php, and (b) grab_globals.lib.php, (c)
display_change_password.lib.php, and (d) common.lib.php in libraries/;
and certain input available in PHP_SELF and (2) PATH_INFO in
libraries/common.inc.php. NOTE: there might also be other vectors
related to (3) REQUEST_URI.
|
| CVE-2007-5588 |
Cross-site scripting (XSS) vulnerability in mnoGoSearch before 3.2.43
allows remote attackers to inject arbitrary web script or HTML via the
t parameter in search.cgi, as reachable from search.htm-dist.
|
| CVE-2007-5582 |
Cross-site scripting (XSS) vulnerability in the login page in Cisco
CiscoWorks Server (CS), possibly 2.6 and earlier, when using
CiscoWorks Common Services 3.0.x and 3.1, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-5581 |
Multiple cross-site scripting (XSS) vulnerabilities in
mpweb/scripts/mpx.dll in Cisco Unified MeetingPlace 5.4 and earlier
and 6.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) FirstName and (2) LastName parameters.
|
| CVE-2007-5577 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web
script or HTML via the (1) Title or (2) Section Name form fields in
the Section Manager component, or (3) multiple unspecified fields in
New Menu Item.
|
| CVE-2007-5564 |
Multiple cross-site scripting (XSS) vulnerabilities in NSSboard
(formerly Simple PHP Forum) 6.1 allow remote attackers to inject
arbitrary web script or HTML via (1) HTML tags when BBcode is
disabled; or the (2) user, (3) email, or (4) Real Name fields in a
profile.
|
| CVE-2007-5562 |
Cross-site scripting (XSS) vulnerability in cgi-bin/welcome (aka the
login page) in Netgear SSL312 PROSAFE SSL VPN-Concentrator 25 allows
remote attackers to inject arbitrary web script or HTML via the err
parameter in the context of an error page.
|
| CVE-2007-5547 |
Cross-site scripting (XSS) vulnerability in Cisco IOS allows remote
attackers to inject arbitrary web script or HTML, and execute IOS
commands, via unspecified vectors, aka PSIRT-2022590358. NOTE: as of
20071016, the only disclosure is a vague pre-advisory with no
actionable information. However, since it is from a well-known
researcher, it is being assigned a CVE identifier for tracking
purposes.
|
| CVE-2007-5496 |
Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5
allows local users to inject arbitrary web script or HTML via a
crafted (1) file or (2) process name, which triggers an Access Vector
Cache (AVC) log entry in a log file used during composition of HTML
documents for sealert.
|
| CVE-2007-5480 |
Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge
InnovaShop allow remote attackers to inject arbitrary web script or
HTML via the (1) msg parameter to msg.jsp, and the (2) contentid
parameter to tc/contents/home001.jsp.
|
| CVE-2007-5479 |
Cross-site scripting (XSS) vulnerability in Search.asp in Xcomputer
allows remote attackers to inject arbitrary web script or HTML via the
EXPS parameter.
|
| CVE-2007-5478 |
Cross-site scripting (XSS) vulnerability in projects in Nabh
Stringbeans Portal (sbportal) 3.2 allows remote attackers to inject
arbitrary web script or HTML via the project_name parameter.
|
| CVE-2007-5477 |
Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod
0.48 Half-Life Dedicated Server plugin allows remote attackers to
inject arbitrary web script or HTML via the redir parameter.
|
| CVE-2007-5472 |
Cross-site scripting (XSS) vulnerability in the Server component in CA
Host-Based Intrusion Prevention System (HIPS) before 8.0.0.93 allows
remote attackers to inject arbitrary web script or HTML via requests
that are written to logs for later display in the log viewer.
|
| CVE-2007-5459 |
Cross-site scripting (XSS) vulnerability in the sidebar HTML page in
the MouseoverDictionary before 0.6.2 extension for Mozilla Firefox
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-5455 |
Cross-site scripting (XSS) vulnerability in wxis.exe in WWWISIS 7.1
and earlier allows remote attackers to inject arbitrary web script or
HTML via a call to the iah/iah.xis IsisScript code, possibly involving
the lang or exprSearch parameter.
|
| CVE-2007-5443 |
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple
1.1.3.1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to (1) the anchor tag and (2)
listtags.
|
| CVE-2007-5434 |
Cross-site scripting (XSS) vulnerability in PRO-search 0.17.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the q parameter to the default URI.
|
| CVE-2007-5433 |
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in
Site-Up 2.64 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) search or (2) search mask field.
|
| CVE-2007-5429 |
Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01
allows remote attackers to inject arbitrary web script or HTML via the
archive parameter.
|
| CVE-2007-5428 |
Cross-site scripting (XSS) vulnerability in UMI CMS allows remote
attackers to inject arbitrary web script or HTML via the search_string
parameter to the default URI in search_do/.
|
| CVE-2007-5427 |
Cross-site scripting (XSS) vulnerability in the com_search component
in Joomla! 1.0.13 and earlier allows remote attackers to inject
arbitrary web script or HTML via the searchword parameter. NOTE: this
might be related to CVE-2007-4189.1.
|
| CVE-2007-5426 |
Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX
2.5.4 allow remote attackers to inject arbitrary web script or HTML
via the page parameter to the default URI for some directories, as
demonstrated by (1) ActiveKB/ and (2) default/categories/ActiveKB/.
|
| CVE-2007-5415 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when
UTF-7 document content is rendered directly in UTF-7, allows remote
attackers to inject arbitrary web script or HTML via a gopher URI that
uses '/' (slash) characters to delimit a literal string within an XSS
sequence, a related issue to CVE-2007-5414.
|
| CVE-2007-5414 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before
2.0, when UTF-7 document content is rendered directly in UTF-7, allows
remote attackers to inject arbitrary web script or HTML via a gopher
URI that uses single quote characters to delimit a literal string
within an XSS sequence, a related issue to CVE-2007-5415.
|
| CVE-2007-5411 |
Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP
Phone with firmware 5.1.8 allows remote attackers to inject arbitrary
web script or HTML via the From header in a SIP message.
|
| CVE-2007-5403 |
Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox
3.7.1 allow remote authenticated users to inject arbitrary web script
or HTML via the (1) Forename, (2) Surname, (3) Telephone, and (4) Fax
fields to writeenduserenduser.asp; the (5) Filter field to
statsrequestypereport.asp; and the (6) sys_request_id parameter to
requestattach.asp; and allow remote authenticated users to inject
arbitrary web script or HTML via the (7) Asset, (8) Location, and (9)
Problem fields to editrequestenduser.asp; the (10) Asset, (11) Asset
Location, (12) Problem Desc, and (13) Solution Desc fields to
editrequestuser.asp; and the (14) End User and (15) Description fields
to usersearchrequests.asp. NOTE: vectors 5 and 6 do not require
authentication to exploit.
|
| CVE-2007-5386 |
Cross-site scripting (XSS) vulnerability in scripts/setup.php in
phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode
requests, allows remote attackers to inject arbitrary web script or
HTML via the query string.
|
| CVE-2007-5385 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub
6.2.6.B and earlier, allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2007-5370 |
Multiple cross-site scripting (XSS) vulnerabilities in
cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow
remote attackers to inject arbitrary web script or HTML via the (1)
group or (2) utag parameter.
|
| CVE-2007-5312 |
Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07
allows remote attackers to inject arbitrary web script or HTML via the
(1) color parameter to pjirc/css.php and the (2) cat parameter to
browse.php.
|
| CVE-2007-5304 |
Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta
0.6 allow remote attackers to inject arbitrary web script or HTML via
the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the
(2) elseifvotetxtresultatduvote parameter to
utilisateurs/votesresultats.php, and the (3)
elseifforumtxtmenugeneraleduforum parameter to
moduleajouter/depot/adminforum.php.
|
| CVE-2007-5303 |
Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS
Rus 2.1 allows remote attackers to inject arbitrary web script or HTML
via the page_id parameter.
|
| CVE-2007-5302 |
Multiple cross-site scripting (XSS) vulnerabilities in HP System
Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and
SMH before 2.1.10 for Linux and Windows, allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-5297 |
Cross-site scripting (XSS) vulnerability in index.php in Minki 1.30
allows remote attackers to inject arbitrary web script or HTML via the
page parameter.
|
| CVE-2007-5296 |
Multiple cross-site scripting (XSS) vulnerabilities in dblisttest.asp
in dbList 8.1 allow remote attackers to inject arbitrary web script or
HTML via the (1) db, (2) pagesize, (3) sort, (4) strKeyWords, and (5)
table parameters. NOTE: some of these details are obtained from third
party information.
|
| CVE-2007-5295 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
(a) Wikepage Opus 13 2007.2 and (b) TipiWiki 2 allow remote attackers
to inject arbitrary web script or HTML via the (1) PageContent and (2)
PageName parameters.
|
| CVE-2007-5293 |
Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta
(aka Phoenix) allow remote attackers to inject arbitrary web script or
HTML via the (1) err_msg parameter to error.php and the (2) content
parameter to templates/simple/ia.php.
|
| CVE-2007-5292 |
Cross-site scripting (XSS) vulnerability in photos.cfm in Directory
Image Gallery 1.1 allows remote attackers to inject arbitrary web
script or HTML via the backwardDirectory parameter.
|
| CVE-2007-5291 |
Cross-site scripting (XSS) vulnerability in Edit.asp in DB Manager 2.0
allows remote attackers to inject arbitrary web script or HTML via the
id parameter.
|
| CVE-2007-5290 |
Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail
Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before
3.4.64, WebMail Lite ASP before 4.0.11, and WebMail Lite PHP before
4.0.22; allow remote attackers to inject arbitrary web script or HTML
via the (1) mode parameter to login.php and the (2) mode2 parameter to
default.asp in an advanced_login mode.
|
| CVE-2007-5280 |
Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in
AppFuse before 2.0 Final allow remote attackers to inject arbitrary
web script or HTML via unspecified input that is recorded in (1)
success or (2) error messages.
|
| CVE-2007-5270 |
Unspecified vulnerability in the Boost module before 4.7.x-1.0, and
5.x before 5.x-1.0, for Drupal allows remote attackers to create or
overwrite arbitrary files, and conduct cross-site scripting attacks
(XSS) via unspecified vectors.
|
| CVE-2007-5255 |
Cross-site scripting (XSS) vulnerability in Google Mini Search
Appliance 3.4.14 allows remote attackers to inject arbitrary web
script or HTML via the ie parameter to the /search URI.
|
| CVE-2007-5251 |
Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16
allow remote attackers to inject arbitrary web script or HTML via (1)
the showOption parameter to domain.asp, or the (2) Folder or (3)
StartPath parameter to FileManager.asp.
|
| CVE-2007-5235 |
Cross-site scripting (XSS) vulnerability in index.php in Uebimiau
2.7.2 through 2.7.10 allows remote attackers to inject arbitrary web
script or HTML via the f_email parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-5228 |
Cross-site scripting (XSS) vulnerability in the subscription
functionality in the Project issue tracking module before 4.7.x-1.5,
4.7.x-2.x before 4.7.x-2.5, and 5.x-1.x before 5.x-1.1 for Drupal
allows remote authenticated users with project create or edit
permissions to inject arbitrary web script or HTML via unspecified
vectors involving a (1) individual or (2) overview form.
|
| CVE-2007-5227 |
Multiple cross-site scripting (XSS) vulnerabilities in
messaging/course/composeMessage.jsp in BlackBoard Learning System
6.3.1.593 and earlier in BlackBoard Academic Suite allow remote
attackers to inject arbitrary web script or HTML via the (1) subject_t
and (2) body_text parameters. NOTE: vector 2 requires bypassing a
client-side security mechanism that attempts to block XSS sequences.
|
| CVE-2007-5218 |
Cross-site scripting (XSS) vulnerability in index.php in Don Barnes
DRBGuestbook 1.1.13 allows remote attackers to inject arbitrary web
script or HTML via the action parameter.
|
| CVE-2007-5214 |
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100
Network Camera 2.02 with firmware 2.43 and earlier allow remote
attackers to inject arbitrary web script or HTML via (1) the PATH_INFO
to the default URI associated with a directory, as demonstrated by (a)
the root directory and (b) the view/ directory; (2) parameters
associated with saved settings, as demonstrated by (c) the
conf_Network_HostName parameter on the Network page and (d) the
conf_Layout_OwnTitle parameter to ServerManager.srv; and (3) the query
string to ServerManager.srv, which is displayed on the logs page.
NOTE: an attacker can leverage a CSRF vulnerability to modify saved
settings.
|
| CVE-2007-5212 |
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100
Network Camera 2.02 with firmware before 2.43 allow remote attackers
to inject arbitrary web script or HTML via (1) parameters associated
with saved settings, as demonstrated by the conf_SMTP_MailServer1
parameter to ServerManager.srv; or (2) the subpage parameter to
wizard/first/wizard_main_first.shtml. NOTE: an attacker can leverage a
CSRF vulnerability to modify saved settings.
|
| CVE-2007-5211 |
Multiple cross-site scripting (XSS) vulnerabilities in Arbor Networks
Peakflow SP 3.5.1 before patch 14, and 3.6.1 before patch 5, when
scope accounts are enabled, allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors involving GET or POST
requests. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2007-5190 |
Multiple cross-site scripting (XSS) vulnerabilities in Alcatel
OmniVista 4760 R4.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) the action parameter to
php-bin/Webclient.php or (2) the Langue parameter to the default URI.
|
| CVE-2007-5183 |
Cross-site scripting (XSS) vulnerability in Mailbox.mws in
OdysseySuite, possibly 4.0.729, allows remote attackers to inject
arbitrary web script or HTML via the idkey parameter.
|
| CVE-2007-5182 |
Cross-site scripting (XSS) vulnerability in mail.asp in Netkamp Emlak
Scripti allows remote attackers to inject arbitrary web script or HTML
via the (1) Email parameter, and possibly the (2) Ad, (3) Soyad, (4)
Konu, and (5) Mesaj parameters to iletisim.asp.
|
| CVE-2007-5179 |
Multiple cross-site scripting (XSS) vulnerabilities in iletisim.asp in
Y&K Iletisim Formu allow remote attackers to inject arbitrary web
script or HTML via the (1) ad, (2) sehir, (3) yas, (4) cins, (5) tel,
(6) mail, and (7) mesaj parameters. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-5176 |
Multiple cross-site scripting (XSS) vulnerabilities in GroupLink
eHelpDesk 6.2.2 allow remote attackers to inject arbitrary web script
or HTML via the (1) NA_DISPLAYNAME parameter in
helpdesk/user/rf_create.jsp and the (2) username and (3) LDAPError
parameters in index2.jsp. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-5161 |
Cross-zone scripting vulnerability in the internal browser in
i-Systems Feedreader 3.10 allows remote attackers to inject arbitrary
web script or HTML via an item in a feed, as demonstrated by a
WordPress blog update. NOTE: this was originally reported as XSS.
|
| CVE-2007-5142 |
Cross-site scripting (XSS) vulnerability in buscar.asp in Solidweb
Novus 1.0 allows remote attackers to inject arbitrary web script or
HTML via the p parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-5136 |
Cross-site scripting (XSS) vulnerability in DFD Cart 1.1.4 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-5127 |
Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02
allow remote attackers to inject arbitrary web script or HTML via (1)
the l_username parameter to the default URI under admin/ or (2) the
l_emoticonlist parameter to admin/emoticonlist.php.
|
| CVE-2007-5121 |
Cross-site scripting (XSS) vulnerability in JSPWiki 2.5.139-beta
allows remote attackers to inject arbitrary web script or HTML via the
redirect parameter to wiki-3/Login.jsp and unspecified other
components.
|
| CVE-2007-5120 |
Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103
and 2.5.139-beta allow remote attackers to inject arbitrary web script
or HTML via the (1) group and (2) members parameters in (a)
NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4)
edittime, (5) author, and (6) link parameters in (c) Comment.jsp; the
(7) loginname, (8) wikiname, (9) fullname, and (10) email parameters
in (d) UserPreferences.jsp and (e) Login.jsp; the (11) r1 and (12) r2
parameters in (f) Diff.jsp; and the (13) changenote parameter in (g)
PageInfo.jsp.
|
| CVE-2007-5112 |
Cross-site scripting (XSS) vulnerability in session.cgi (aka the login
page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to
inject arbitrary web script or HTML via the query string, a different
vulnerability than CVE-2007-4713. NOTE: this can be leveraged to
capture login credentials in some browsers that support remembered
(auto-completed) passwords.
|
| CVE-2007-5106 |
Cross-site scripting (XSS) vulnerability in wp-register.php in
WordPress 2.0 allows remote attackers to inject arbitrary web script
or HTML via the user_login parameter.
|
| CVE-2007-5105 |
Cross-site scripting (XSS) vulnerability in wp-register.php in
WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary
web script or HTML via the user_email parameter.
|
| CVE-2007-5091 |
Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare
1.4.001 allow remote attackers to inject arbitrary web script or HTML
via the cat_data[color] parameter to (1)
preferences/inc/class.uicategories.inc.php and (2)
admin/inc/class.uicategories.inc.php.
|
| CVE-2007-5088 |
Cross-site scripting (XSS) vulnerability in search/cust_bill_event.cgi
in Freeside 1.7.2 allows remote attackers to inject arbitrary web
script or HTML via the failed parameter.
|
| CVE-2007-5078 |
Multiple cross-site scripting (XSS) vulnerabilities in eGov Manager
allow remote attackers to inject arbitrary web script or HTML via
unspecified "user-supplied input" to (1) center.exe or (2) Index.exe.
|
| CVE-2007-5072 |
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog
(SPHPBlog) before 0.5.1, when register_globals is enabled, allow
remote attackers to inject arbitrary web script or HTML via certain
user_colors array parameters to certain user_style.php files under
themes/, as demonstrated by the user_colors[bg_color] parameter.
|
| CVE-2007-5059 |
Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL allow
remote attackers to inject arbitrary web script or HTML via several
vectors, as demonstrated by the (1) uname and (2) pass parameters in a
login form, and (3) an unspecified "url value," leading to storage of
XSS sequences in the database and display of these sequences in the
alert section of the admin panel.
|
| CVE-2007-5058 |
Cross-site scripting (XSS) vulnerability in the Web administration
interface in Barracuda Spam Firewall before firmware 3.5.10.016 allows
remote attackers to inject arbitrary web script or HTML via the
username field in a login attempt, which is not properly handled when
the Monitor Web Syslog screen is open.
|
| CVE-2007-5052 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Vigile CMS 1.8 allow remote attackers to inject arbitrary web script
or HTML via a request to the wiki module with (1) the title parameter
or (2) a "title=" sequence in the PATH_INFO, or a request to the
download module with (3) the cat parameter or (4) a "cat=" sequence in
the PATH_INFO.
|
| CVE-2007-5051 |
Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView
4.1.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) box_width, (2) PEDIGREE_GENERATIONS, and (3) rootid
parameters in ancestry.php, and the (4) newpid parameter in
timeline.php. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2007-5046 |
Cross-site scripting (XSS) vulnerability in the Webmail interface for
IceWarp Merak Mail Server before 9.0.0 allows remote attackers to
inject arbitrary JavaScript via a javascript: URI in an attribute of
an element in an email message body, as demonstrated by the onload
attribute in a BODY element.
|
| CVE-2007-5033 |
Cross-site scripting (XSS) vulnerability in profile.php in phpBB XS 2
allows remote attackers to inject arbitrary web script or HTML via the
selfdes parameter in a profile_info editprofile action.
|
| CVE-2007-5027 |
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in
the web management panel for the WBR3404TX broadband router with
firmware R1.94p0vTIG allow remote attackers to inject arbitrary web
script or HTML via the (1) DD or (2) DU parameter.
|
| CVE-2007-5013 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Phormer 3.31 allow remote attackers to inject arbitrary web script or
HTML via the (1) u, (2) p, (3) c, and (4) s parameters, and other
unspecified vectors. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-5012 |
Cross-site scripting (XSS) vulnerability in picture.php in
PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote
attackers to inject arbitrary web script or HTML via the author
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2007-5010 |
Cross-site scripting (XSS) vulnerability in WebBatch allows remote
attackers to inject arbitrary web script or HTML via the URL to
webbatch.exe.
|
| CVE-2007-5000 |
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in
the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61
and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0
through 2.2.6 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2007-4981 |
Cross-site scripting (XSS) vulnerability in the save function in
Obedit 3.03 allows user-assisted remote attackers to inject arbitrary
web script or HTML via unknown vectors, as demonstrated by a SCRIPT
element in an unspecified context when saving a document. NOTE:
because the details of the attack are uncertain, it is unclear whether
this crosses privilege boundaries.
|
| CVE-2007-4977 |
Cross-site scripting (XSS) vulnerability in mode.php in Coppermine
Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to
inject arbitrary web script or HTML via the referer parameter.
|
| CVE-2007-4975 |
Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1
allows remote attackers to inject arbitrary web script or HTML via
the chapter parameter.
|
| CVE-2007-4959 |
Cross-site scripting (XSS) vulnerability in
catalog_products_with_images.php in osCMax 2.0.0-RC3-0-1 allows remote
attackers to inject arbitrary web script or HTML via the URI. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2007-4958 |
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery
(TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or
HTML via the URI for (1) index.php, (2) i_frames/i_login.php, and (3)
i_frames/i_top_tags.php. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-4945 |
Multiple cross-site scripting (XSS) vulnerabilities in LetterGrade
allow remote attackers to inject arbitrary web script or HTML via (1)
a student's email address, (2) the year parameter to
genbrws/Student/cal_month.php3, and other unspecified vectors related
to the calendar. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2007-4929 |
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W
camera allow remote attackers to inject arbitrary web script or HTML
via the camNo parameter to incl/image_incl.shtml, and other
unspecified vectors.
|
| CVE-2007-4917 |
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats
0.1.9.2 allows remote attackers to inject arbitrary web script or HTML
via the ip parameter in an online action, a different vector than
CVE-2007-4334.
|
| CVE-2007-4912 |
Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php
in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows
remote attackers to inject arbitrary web script or HTML into user
profile fields via unspecified vectors related to character sets other
than iso-8859-1 or utf-8.
|
| CVE-2007-4900 |
Cross-site scripting (XSS) vulnerability in the logon page in RSA
EnVision 3.3.6 Build 0115 allows remote attackers to inject arbitrary
web script or HTML via the username field.
|
| CVE-2007-4899 |
Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum
5.10.20 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) id parameter to forum_forum.php, or the
search_string parameter to forum_text_search_action.php in a (2)
titles or (3) bodies search.
|
| CVE-2007-4896 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1)
lang[adminseite], (2) lang[ueberschrift], or (3) einst[metachar]
parameter, different vectors than CVE-2007-4711.
|
| CVE-2007-4893 |
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress
multi-user (MU) before 1.2.5a does not properly verify the
unfiltered_html privilege, which allows remote attackers to conduct
cross-site scripting (XSS) attacks via modified data to (1) post.php
or (2) page.php with a no_filter field.
|
| CVE-2007-4883 |
Cross-site scripting (XSS) vulnerability in the BotQuery extension in
MediaWiki 1.7.x and earlier before SVN 20070910 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, a similar issue to CVE-2007-4828.
|
| CVE-2007-4882 |
Multiple cross-site scripting (XSS) vulnerabilities in TechExcel
CustomerWise (formerly TechExcel CRM) allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-4874 |
Multiple cross-site scripting (XSS) vulnerabilities in SimpNews
2.41.03 allow remote attackers to inject arbitrary web script or HTML
via the (1) l_username parameter to admin/layout2b.php, and the (2)
backurl parameter to comment.php.
|
| CVE-2007-4862 |
Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON
5.4 allows remote attackers to inject arbitrary web script or HTML via
the config[news_url] parameter.
|
| CVE-2007-4836 |
Cross-site scripting (XSS) vulnerability in index.php in phpMyQuote
0.20 allows remote attackers to inject arbitrary web script or HTML
via the id parameter in an edit action.
|
| CVE-2007-4835 |
SQL injection vulnerability in index.php in phpMyQuote 0.20 allows
remote attackers to execute arbitrary SQL commands via the id
parameter in an edit action.
|
| CVE-2007-4831 |
Multiple cross-site scripting (XSS) vulnerabilities in
account_settings.php in TorrentTrader 1.07 allow remote attackers to
inject arbitrary web script or HTML via the (1) avatar and (2) title
parameters.
|
| CVE-2007-4830 |
Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in
DirectAdmin 1.30.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the user parameter.
|
| CVE-2007-4828 |
Cross-site scripting (XSS) vulnerability in the API pretty-printing
mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0
through 1.10.1, and the 1.11 development versions before 1.11.0 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-4819 |
Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-4813 |
Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01
Beta 7 allows remote attackers to inject arbitrary web script or HTML
via the name field. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-4811 |
Multiple cross-site scripting (XSS) vulnerabilities in Netjuke 1.0-rc2
allow remote attackers to inject arbitrary web script or HTML via (1)
the val parameter to alphabet.php in an alpha.albums action, or the
PATH_INFO to (2) random.php or (3) admin/hidden.php.
|
| CVE-2007-4810 |
Multiple SQL injection vulnerabilities in Netjuke 1.0-rc2 allow remote
attackers to execute arbitrary SQL commands via (1) the ge_id
parameter in a list.artists action to explore.php or (2) the id
parameter in a show.tracks action to xml.php.
|
| CVE-2007-4779 |
Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2
(aka Endeleo) allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors, probably related to the archive
section.
|
| CVE-2007-4760 |
The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus
7 and 7.5 can generate HTML documents that contain cross-site
scripting (XSS) vulnerabilities, which allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors. NOTE:
this is probably the same issue as CVE-2007-3503.
|
| CVE-2007-4745 |
Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook
3.42 and earlier component (com_akobook) for Mambo allow remote
attackers to inject arbitrary web script or HTML via Javascript events
in the (1) gbmail and (2) gbpage parameters in the sign function.
|
| CVE-2007-4742 |
Claroline before 1.8.6 allows remote authenticated administrators to
obtain sensitive information via an invalid value in the sort
parameter to admin/adminusers.php, which reveals the path in an error
message in some circumstances, as demonstrated by a parameter value
containing an XSS sequence.
|
| CVE-2007-4741 |
Cross-site scripting (XSS) vulnerability in admin/adminusers.php in
Claroline before 1.8.6 allows remote authenticated administrators to
inject arbitrary web script or HTML via the sort parameter. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2007-4717 |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline
before 1.8.6 allow remote authenticated administrators to inject
arbitrary web script or HTML via the (1) dir parameter in
admin/adminusers.php, the (2) action parameter in
admin/advancedUserSearch.php, and the (3) view parameter in
admin/campusProblem.php.
|
| CVE-2007-4713 |
Multiple cross-site scripting (XSS) vulnerabilities in urchin.cgi in
Urchin 5.6.00r2 allow remote attackers to inject arbitrary web script
or HTML via the (1) dtc, (2) vid, (3) n, (4) dt, (5) ed, and (6) bd
parameters.
|
| CVE-2007-4711 |
Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch
1.00 allow remote attackers to inject arbitrary web script or HTML via
the (1) homepage, (2) mail, and (3) name parameters in a show action
to (a) form.php; the (4) language and (5) anzeigebreite parameters to
(b) admin/header.php; and the (6) msg parameter to (c) install.php,
different vectors than CVE-2006-0706.
|
| CVE-2007-4698 |
Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4
through 10.4.10, allows remote attackers to conduct cross-site
scripting (XSS) attacks by causing JavaScript events to be associated
with the wrong frame.
|
| CVE-2007-4634 |
Multiple SQL injection vulnerabilities in Cisco CallManager and
Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before
4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote
attackers to execute arbitrary SQL commands via the lang variable to
the (1) user or (2) admin logon page, aka CSCsi64265.
|
| CVE-2007-4633 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco
CallManager and Unified Communications Manager (CUCM) before
3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before
4.3(1)sr1 allow remote attackers to inject arbitrary web script or
HTML via the lang variable to the (1) user or (2) admin logon page,
aka CSCsi10728.
|
| CVE-2007-4630 |
Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute
Poll Manager XE 4.1 allows remote attackers to inject arbitrary web
script or HTML via the msg parameter.
|
| CVE-2007-4624 |
Cross-site scripting (XSS) vulnerability in pframe.php in AbleDesign
Dynamic Picture Frame 1.00 allows remote attackers to inject arbitrary
web script or HTML via the img_url parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2007-4595 |
Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.12 allows
remote attackers to inject arbitrary web script or HTML in certain
circumstances involving (1) lack of charset specification within a
META element or (2) a META element that specifies an unrecognized
charset, which trigger automatic character set recognition by the web
browser, as demonstrated by improper handling of UTF-7 data.
|
| CVE-2007-4592 |
Multiple cross-site scripting (XSS) vulnerabilities in the web
interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A,
7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject
arbitrary web script or HTML via the (1) contextid, (2) username, (3)
userNameVal, and (4) schema parameters to the login component.
|
| CVE-2007-4589 |
Multiple cross-site scripting (XSS) vulnerabilities in InterWorx
Hosting Control Panel (InterWorx-CP) Webmaster Level (SiteWorx) 3.0.2
(1) allow remote attackers to inject arbitrary web script or HTML via
the PATH_INFO to index.php; and allow remote authenticated users to
inject arbitrary web script or HTML via the PATH_INFO to (2)
siteworx.php, (3) users.php, (4) ftp.php, (5) mysql.php, (6)
domains.php, (7) htaccess.php, (8) scriptworx.php, (9) stats.php, (10)
backup.php, (11) restore.php, and (12) httpd.php; and unspecified
vectors to (13) cron.php and (14) prefs.php.
|
| CVE-2007-4588 |
Multiple cross-site scripting (XSS) vulnerabilities in InterWorx
Hosting Control Panel (InterWorx-CP) Server Admin Level (NodeWorx)
3.0.2 (1) allow remote attackers to inject arbitrary web script or
HTML via the PATH_INFO to index.php; and allow remote authenticated
users to inject arbitrary web script or HTML via the PATH_INFO to (2)
nodeworx.php, (3) users.php, (4) lang.php, (5) themes.php, (6)
setup.php, (7) siteworx.php, (8) packages.php, (9) backup.php, (10)
import.php, (11) scriptworx.php, (12) resellers.php, (13)
reseller-packages.php, (14) http.php, (15) mail.php, (16) ftp.php,
(17) mysql.php, (18) sshd.php, (19) nfs.php, (20) cron.php, (21)
ip.php, (22) firewall.php, (23) updates.php, (24) rrd.php, or (25)
cluster.php.
|
| CVE-2007-4587 |
Cross-site scripting (XSS) vulnerability in Easy Software Cafeteria
escafeWeb (aka Tuigwaa) 1.0 through 1.0.4 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, possibly
related to the setting of option.nopage.create in tuigwaa.properties.
|
| CVE-2007-4557 |
Cross-site scripting (XSS) vulnerability in the webacc servlet in
Novell GroupWise 6.5 WebAccess allows remote attackers to inject
arbitrary web script or HTML via the User.Id parameter, as
demonstrated by a URL within a url field in a STYLE element, possibly
due to an incomplete fix for CVE-2004-2103.2.
|
| CVE-2007-4555 |
Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows
remote attackers to inject arbitrary web script or HTML via arguments
to a valid command, which is not properly handled when it is displayed
by the view log option in the administration interface. NOTE: this
can be leveraged to create a new admin account.
|
| CVE-2007-4554 |
Cross-site scripting (XSS) vulnerability in tiki-remind_password.php
in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to
inject arbitrary web script or HTML via the username parameter. NOTE:
this issue might be related to CVE-2006-2635.7.
|
| CVE-2007-4544 |
Cross-site scripting (XSS) vulnerability in wp-newblog.php in
WordPress multi-user (MU) 1.0 and earlier allows remote attackers to
inject arbitrary web script or HTML via the weblog_id parameter
(Username field).
|
| CVE-2007-4543 |
Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla
2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1
allows remote attackers to inject arbitrary web script or HTML via the
buildid field in the "guided form."
|
| CVE-2007-4542 |
Multiple cross-site scripting (XSS) vulnerabilities in MapServer
before 4.10.3 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors involving the (1) processLine function in
maptemplate.c and the (2) writeError function in mapserv.c in the
mapserv CGI program.
|
| CVE-2007-4541 |
Multiple cross-site scripting (XSS) vulnerabilities in Olate Download
(od) 3.4.2 allow remote attackers to inject arbitrary web script or
HTML via (1) the PHP_SELF variable in modules/core/uim.php and (2)
[url] tags in a comment in modules/core/fldm.php.
|
| CVE-2007-4530 |
Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak
Server 2.0.20.1 allow remote attackers to inject arbitrary web script
or HTML via (1) the error_text parameter to error_box.html or (2) the
ok_title parameter to ok_box.html.
|
| CVE-2007-4523 |
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website
Manager 0.8.9 and earlier allow remote authenticated users to inject
arbitrary web script or HTML via one or more of the following vectors:
the (1) id parameter to (a) pages/delete_page.php, (b)
navigation/delete_menu.php, and (c) navigation/delete_item.php in
admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters
in (d) admin/navigation/do_new_item.php; the (5) new_menuname
parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name,
and url parameters to (f) admin/pages/do_new_page.php, probably
involving the Title or textarea field as reachable through
admin/pages/new_page.php. NOTE: the original disclosure does not
precisely state which vectors are associated with SQL injection versus
XSS.
|
| CVE-2007-4522 |
Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9
and earlier allow remote authenticated users to execute arbitrary SQL
commands via one or more of the following vectors: the (1) id
parameter to (a) pages/delete_page.php, (b)
navigation/delete_menu.php, and (c) navigation/delete_item.php in
admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters
in (d) admin/navigation/do_new_item.php; the (5) new_menuname
parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name,
and url parameters to (f) admin/pages/do_new_page.php. NOTE: some
vectors might be reachable through the url and name parameters to (g)
admin/navigation/new_nav_item.php. NOTE: the original disclosure does
not precisely state which vectors are associated with SQL injection
versus XSS.
|
| CVE-2007-4512 |
Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for
Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers
to inject arbitrary web script or HTML via an archive with a file that
matches a virus signature and has a crafted filename that is not
properly handled by the print function in SavMain.exe.
|
| CVE-2007-4488 |
Multiple cross-site scripting (XSS) vulnerabilities in the Siemens
Gigaset SE361 WLAN router with firmware 1.00.0 allow remote attackers
to inject arbitrary web script or HTML via the portion of the URI
immediately following the filename for (1) a GIF filename, which
triggers display of the GIF file in text format and an unspecified
denial of service (crash); or (2) the login.tri filename, which
triggers a continuous loop of the browser attempting to visit the
login page.
|
| CVE-2007-4487 |
Cross-site scripting (XSS) vulnerability in D22-Shoutbox for Invision
Power Board (IPB or IP.Board) allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-4483 |
Cross-site scripting (XSS) vulnerability in index.php in the WordPress
Classic 1.5 theme in WordPress before 2.1.3 allows remote attackers to
inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).
|
| CVE-2007-4482 |
Cross-site scripting (XSS) vulnerability in index.php in the Pool
1.0.7 theme for WordPress allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO (PHP_SELF).
|
| CVE-2007-4481 |
Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix
0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress allows remote
attackers to inject arbitrary web script or HTML via the PATH_INFO
(PHP_SELF).
|
| CVE-2007-4480 |
Cross-site scripting (XSS) vulnerability in index.php in the Sirius
1.0 theme for WordPress allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO (PHP_SELF).
|
| CVE-2007-4479 |
Cross-site scripting (XSS) vulnerability in search.html in Search
Engine Builder allows remote attackers to inject arbitrary web script
or HTML via the searWords parameter.
|
| CVE-2007-4478 |
Cross-site scripting (XSS) vulnerability in Microsoft Internet
Explorer 6.0 and 7 allows user-assisted remote attackers to inject
arbitrary web script or HTML in the local zone via a URI, when the
document at the associated URL is saved to a local file, which then
contains the URI string along with the document's original content.
|
| CVE-2007-4465 |
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the
Apache HTTP Server before 2.2.6, when the charset on a
server-generated page is not defined, allows remote attackers to
inject arbitrary web script or HTML via the P parameter using the
UTF-7 charset. NOTE: it could be argued that this issue is due to a
design limitation of browsers that attempt to perform automatic
content type detection.
|
| CVE-2007-4453 |
** DISPUTED **
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.8
allow remote attackers to inject arbitrary web code or HTML via the
(1) s parameter to index.php, and the (2) q parameter to (a) faq.php,
(b) member.php, (c) memberlist.php, (d) calendar.php, (e) search.php,
(f) forumdisplay.php, (g) showgroups.php, (h) online.php, and (i)
sendmessage.php. NOTE: these issues have been disputed by the vendor,
stating "I can't reproduce a single one of these". The researcher is
known to be unreliable.
|
| CVE-2007-4434 |
Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the
Text File Search ASP (Classic) edition allows remote attackers to
inject arbitrary web script or HTML via the query parameter.
|
| CVE-2007-4433 |
Cross-site scripting (XSS) vulnerability in textfilesearch.aspx in the
Text File Search ASP.NET edition allows remote attackers to inject
arbitrary web script or HTML via the search field.
|
| CVE-2007-4412 |
Multiple cross-site scripting (XSS) vulnerabilities in Headstart
Solutions DeskPRO 3.0.2 allow remote authenticated users to inject
arbitrary web script or HTML via unspecified parameters to (1)
techs.php, (2) ticket_category.php, (3) ticket_priority.php, (4)
ticket_workflow.php, (5) ticket_escalate.php, (6) fields_ticket.php,
(7) ticket_rules_web.php, (8) ticket_displayfields.php, (9)
ticket_rules_mail.php, (10) fields_user.php, (11) fields_faq.php, and
(12) user_help.php, in (a) admincp/ and (b) possibly a directory on
the "User side."
|
| CVE-2007-4365 |
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
set_lang cookie to an unspecified component. NOTE: this may overlap
CVE-2007-1965.
|
| CVE-2007-4363 |
Multiple cross-site scripting (XSS) vulnerabilities in the
nodereference module in Drupal Content Construction Kit (CCK) before
4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject
arbitrary web script or HTML via nodereference fields, when using (1)
the plain formatter or (2) the autocomplete text field widget without
Views.module.
|
| CVE-2007-4350 |
Cross-site scripting (XSS) vulnerability in the management interface
in HP SiteScope 9.0 build 911 allows remote attackers to inject
arbitrary web script or HTML via an SNMP trap message.
|
| CVE-2007-4348 |
Cross-site scripting (XSS) vulnerability in the CAD service in IBM
Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows
allows remote attackers to inject arbitrary web script or HTML via
HTTP requests to port 1581, which generate log entries in a
dsmerror.log file that is accessible through a certain web interface.
|
| CVE-2007-4334 |
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats
0.1.9.2 allows remote attackers to inject arbitrary web script or HTML
via the IP parameter.
|
| CVE-2007-4333 |
Multiple cross-site scripting (XSS) vulnerabilities in signup.php in
Article Dashboard allow remote attackers to inject arbitrary web
script or HTML via the (1) f_emailaddress, (2) f_reemailaddress, and
other unspecified parameters. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2007-4331 |
PHP remote file inclusion vulnerability in index.php in FindNix allows
remote attackers to include the contents of arbitrary URLs and conduct
cross-site scripting (XSS) attacks via a URL in the page parameter.
|
| CVE-2007-4318 |
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the
management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall
2 device allows remote authenticated administrators to inject
arbitrary web script or HTML via the sysSystemName parameter.
|
| CVE-2007-4307 |
Multiple cross-site scripting (XSS) vulnerabilities in Storesprite 7
and earlier allow remote attackers to inject arbitrary web script or
HTML via the next parameter to (1) addaddress.php, (2)
editshipdetails.php, (3) register.php, or (4) login.php in secure/.
|
| CVE-2007-4306 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
2.10.3 allow remote attackers to inject arbitrary web script or HTML
via the (1) unlim_num_rows, (2) sql_query, or (3) pos parameter to (a)
tbl_export.php; the (4) session_max_rows or (5) pos parameter to (b)
sql.php; the (6) username parameter to (c) server_privileges.php; or
the (7) sql_query parameter to (d) main.php. NOTE: vector 5 might be
a regression or incomplete fix for CVE-2006-6942.7.
|
| CVE-2007-4301 |
Multiple cross-site scripting (XSS) vulnerabilities in the management
interface in WebCart 2.20 through 2.25 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-4297 |
Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp
in Dersimiz Haber Ekleme Modulu allow remote attackers to inject
arbitrary web script or HTML via the (1) yazan, (2) mail, and (3)
yorum parameters. NOTE: some of these details are obtained from third
party information.
|
| CVE-2007-4284 |
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified
MeetingPlace Web Conferencing (MP) 5.3.235.0 and earlier allow remote
attackers to inject arbitrary HTML and web script via the (1) Success
Template (STPL) and (2) Failure Template (FTPL) parameters, which are
not properly handled in an error message.
|
| CVE-2007-4281 |
Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source
3.4 and 3.4.1 allows remote attackers to inject arbitrary web script
or HTML via the login field on the login page, and other unspecified
vectors.
|
| CVE-2007-4265 |
Multiple cross-site scripting (XSS) vulnerabilities in VisionProject
3.1 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) projectIssueId parameter in EditProjectIssue.do,
the (2) projectId parameter in ProjectSelected.do, the (3) folderId
parameter in ProjectDocuments.do and the (4) sortField parameter in
ProjectIssues.do.
|
| CVE-2007-4264 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) path and (2) download parameters.
|
| CVE-2007-4245 |
Cross-site scripting (XSS) vulnerability in Search.php in DiMeMa
CONTENTdm (CDM) allows remote attackers to inject arbitrary web script
or HTML via a search, probably related to the CISOBOX1 parameter to
results.php in CDM 4.2.
|
| CVE-2007-4239 |
Cross-site scripting (XSS) vulnerability in user/forgotPassStep2.jsp
in the admin interface in C-SAM oneWallet 210_07062007;1.0 allows
remote attackers to inject arbitrary web script or HTML via the
loginID parameter.
|
| CVE-2007-4212 |
Multiple cross-site scripting (XSS) vulnerabilities in the Search
Module in PHP-Nuke allow remote attackers to inject arbitrary web
script or HTML via a trailing "<" instead of a ">" in (1) the onerror
attribute of an IMG element, (2) the onload attribute of an IFRAME
element, or (3) redirect users to other sites via the META tag.
|
| CVE-2007-4193 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
index.php in IDE Group DVD Rental System (DRS) 5.1 before 20070801
allow remote attackers to perform certain actions as arbitrary users,
as demonstrated by (1) modifying data or (2) canceling a subscription.
NOTE: it is not clear whether IDE Group updates all DRS installations
in its role as an application service provider. If so, then this issue
should not be included in CVE.
|
| CVE-2007-4192 |
Multiple cross-site scripting (XSS) vulnerabilities in IDE Group DVD
Rental System (DRS) 5.1 before 20070801 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors. NOTE: it
is not clear whether IDE Group updates all DRS installations in its
role as an application service provider. If so, then this issue should
not be included in CVE.
|
| CVE-2007-4190 |
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow)
allows remote attackers to inject arbitrary HTTP headers and probably
conduct HTTP response splitting attacks via CRLF sequences in the url
parameter. NOTE: this can be leveraged for cross-site scripting (XSS)
attacks. NOTE: some of these details are obtained from third party
information.
|
| CVE-2007-4189 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors in the (1) com_search, (2)
com_content, and (3) mod_login components. NOTE: some of these details
are obtained from third party information.
|
| CVE-2007-4178 |
Cross-site scripting (XSS) vulnerability in index.php in WebDirector
2.2 and earlier allows remote attackers to inject arbitrary web script
or HTML via the deslocal parameter.
|
| CVE-2007-4177 |
Multiple cross-site scripting (XSS) vulnerabilities in Interact before
2.4 allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: this might overlap CVE-2007-3328.
|
| CVE-2007-4175 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
OpenRat CMS 0.8-beta1 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) subaction and (2) action
parameters.
|
| CVE-2007-4172 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Webmail
(OWM) 2.52 20060831 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) searchtype, (2) longpage, and
(3) page parameters to (a) openwebmail-main.pl; the (4) prefs_caller,
(5) userfirsttime, (6) page, (7) sort, (8) folder, and (9) message_id
parameters to (b) openwebmail-prefs.pl; the (10) compose_caller, (11)
msgdatetype, (12) keyword, (13) searchtype, (14) folder, (15) page,
and (16) sort parameters to (c) openwebmail-send.pl; the (17) folder,
(18) page, and (19) sort parameters to (d) openwebmail-folder.pl; the
(20) searchtype, (21) page, (22) filesort, (23) singlepage, (24)
showhidden, (25) showthumbnail, and (26) message_id parameters to (e)
openwebmail-webdisk.pl; the (27) folder parameter to (f)
openwebmail-advsearch.pl; and the (28) abookcollapse, (29)
abooksearchtype, (30) abooksort, (31) abooklongpage, (32) abookpage,
(33) message_id, (34) searchtype, (35) msgdatetype, (36) sort, (37)
page, (38) rootxowmuid, and (39) listviewmode parameters to (g)
openwebmail-abook.pl, different vectors than CVE-2005-2863,
CVE-2006-2190, CVE-2006-3229, and CVE-2006-3233.
|
| CVE-2007-4166 |
Cross-site scripting (XSS) vulnerability in index.php in the Unnamed
theme 1.217, and Special Edition (SE) 1.02, before 20070804 for
WordPress allows remote attackers to inject arbitrary web script or
HTML via the s parameter, possibly a related issue to CVE-2007-2757,
CVE-2007-4014, and CVE-2007-4165. NOTE: some of these details are
obtained from third party information.
|
| CVE-2007-4165 |
Cross-site scripting (XSS) vulnerability in index.php in the Blue
Memories theme 1.5 for WordPress allows remote attackers to inject
arbitrary web script or HTML via the s parameter, possibly a related
issue to CVE-2007-2757 and CVE-2007-4014. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-4153 |
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1
allow remote authenticated administrators to inject arbitrary web
script or HTML via (1) the Options Database Table in the Admin Panel,
accessed through options.php; or (2) the opml_url parameter to
link-import.php. NOTE: this might not cross privilege boundaries in
some configurations, since the Administrator role has the
unfiltered_html capability.
|
| CVE-2007-4146 |
Cross-site scripting (XSS) vulnerability in webevent.cgi in WebEvent
2.61 through 4.03 allows remote attackers to inject arbitrary web
script or HTML via the cmd parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-4144 |
Cross-site scripting (XSS) vulnerability in
sample-forms/simple-contact-form-with-preview/simple-contact-form-with-preview.html
in MitriDAT eMail Form Processor Pro allows remote attackers to inject
arbitrary web script or HTML via the base_path parameter, possibly
related to (1) formprocessorpro.php in the PHP version of the product,
and (2) formprocessorpro.pl in the Perl version of the product.
|
| CVE-2007-4142 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server
7.5.1 before 20070731 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors involving a crafted Sametime
meeting.
|
| CVE-2007-4141 |
OpenRat CMS 0.8-beta1 and earlier allows remote attackers to obtain
sensitive information via a request containing an XSS sequence in the
action parameter to index.php, which reveals the path in an error
message.
|
| CVE-2007-4139 |
Cross-site scripting (XSS) vulnerability in the Temporary Uploads
editing functionality (wp-admin/includes/upload.php) in WordPress
2.2.1, allows remote attackers to inject arbitrary web script or HTML
via the style parameter to wp-admin/upload.php.
|
| CVE-2007-4115 |
Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms)
0.2 allow remote attackers to inject arbitrary web script or HTML via
the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3)
titletext-ed.php.
|
| CVE-2007-4112 |
Multiple SQL injection vulnerabilities in Advanced Webhost Billing
System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow
remote attackers to execute arbitrary SQL commands via unspecified
vectors. NOTE: this can be leveraged for XSS attacks that "bypass
AWBS's anti-XSS input validation."
|
| CVE-2007-4104 |
Multiple cross-site scripting (XSS) vulnerabilities in the
WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors, one of
which involves an rss2 feed with an invalid or missing blog with an
XSS sequence in the query string.
|
| CVE-2007-4102 |
Cross-site scripting (XSS) vulnerability in search.php for sBlog 0.7.3
Beta allows remote attackers to inject arbitrary HTML and web script
via a leading '"/></> sequence in the search string.
|
| CVE-2007-4090 |
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard
0.1.2 allow remote attackers to inject arbitrary web script or HTML
via (1) the URI to inc/lib/screen.php or (2) the title parameter to
post.php. NOTE: vector 2 might overlap CVE-2006-6283. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2007-4088 |
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard
0.1.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) id, (2) f, (3) quote, and (4) act parameters to cp.php;
the (5) u parameter to user.php; the (6) f parameter to post.php; the
(7) s parameter to topic.php; the (8) quote, (9) t, (10) poll, and
(11) p parameters to post.php; the (12) Message Title field of a
private message (PM) in mode 6 of cp.php; the (13) title field of a
private message (PM) in mode 7 of cp.php; and (14) allow user-assisted
remote attackers to inject arbitrary web script or HTML via a dosearch
action to search.php, which reflects the first lines of all posts by a
user. NOTE: the act parameter to help.php and the p parameter to
report.php are already covered by CVE-2006-4708. NOTE: vectors 12 and
13 might overlap CVE-2006-6283.1. NOTE: vector 14 might overlap
CVE-2006-4708.b.
|
| CVE-2007-4087 |
AlstraSoft Video Share Enterprise allows remote attackers to obtain
sensitive information (the full path) via (1) a ' (quote) character in
the category parameter to view_video.php, or (2) an XSS sequence in
the UID parameter to (a) uprofile.php, (b) channel_detail.php, (c)
uvideos.php, (d) groups_home.php, or (e) ufriends.php.
|
| CVE-2007-4083 |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft
AskMe Pro allow remote attackers to inject arbitrary web script or
HTML via (1) the cat_id parameter to search.php or the (2) typ
parameter to register.php.
|
| CVE-2007-4082 |
Cross-site scripting (XSS) vulnerability in contact_author.php
AlstraSoft Article Manager Pro allows remote attackers to inject
arbitrary web script or HTML via the userid parameter.
|
| CVE-2007-4081 |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft
Affiliate Network Pro allow remote attackers to inject arbitrary web
script or HTML via vectors in (a) merchants/index.php, including the
(1) id or (2) msg parameter in a programedit action; the (3) pgmid
parameter in an uploadProducts action; the (4) d, (5) m, or (6) y
parameter in a daily action; the (7) err parameter in a ProgramReport
action; the (8) i, (9) txtto, (10) txtfrom, or (11) programs parameter
in a LinkReport action; or the (12) msg parameter in an add_money
action; and one vector in (b) merchants/temp.php using (13) the rowid
parameter. NOTE: vector 7 might overlap CVE-2005-3795.1.
|
| CVE-2007-4080 |
Cross-site scripting (XSS) vulnerability in index.php AlstraSoft
E-Friends allows remote attackers to inject arbitrary web script or
HTML via the p_id parameter in a people_card action. NOTE: this might
overlap CVE-2006-2564.
|
| CVE-2007-4079 |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS
Text Messaging Enterprise allow remote attackers to inject arbitrary
web script or HTML via the (1) domain or (2) q parameter to (a)
admin/membersearch.php, or (3) the userid parameter to (b)
admin/edituser.php.
|
| CVE-2007-4078 |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Text
Ads Enterprise allow remote attackers to inject arbitrary web script
or HTML via the (1) r parameter to (a) forgot_uid.php, the (2) query
or (3) sk parameter to (b) search_results.php, or (4) the pageId
parameter to (c) website_page.php.
|
| CVE-2007-4077 |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft
Video Share Enterprise allow remote attackers to inject arbitrary web
script or HTML via the (1) msg, (2) page, (3) viewkey, or (4) viewtype
parameter to (a) view_video.php; the (5) next parameter to (b)
signup.php; the (6) search_id parameter to (c) search_result.php; the
(7) category or (8) page parameter to (d) video.php; the (9) receiver
parameter to (e) compose.php; the (10) catgy parameter to (f)
groups.php; the (11) channelname parameter to (g)
siteadmin/channels.php; or the (12) uname parameter to (h)
siteadmin/muser.php.
|
| CVE-2007-4075 |
Cross-site scripting (XSS) vulnerability in index.asp in Alisveris
Sitesi Scripti allows remote attackers to inject arbitrary web script
or HTML via the q parameter in a search mod action. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2007-4071 |
Multiple cross-site scripting (XSS) vulnerabilities in
uploader/index.php in Webbler CMS before 3.1.6 allow remote attackers
to inject arbitrary web script or HTML via the (1) page or (2) login
parameter.
|
| CVE-2007-4064 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x
before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to
inject arbitrary web script or HTML via "some server variables,"
including PHP_SELF; and (2) allow remote authenticated administrators
to inject arbitrary web script or HTML via custom content type names.
|
| CVE-2007-4052 |
Cross-site scripting (XSS) vulnerability in utilities/login.asp in
nukedit 4.9.7 and earlier allows remote attackers to inject arbitrary
web script or HTML via the email parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-4048 |
Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo
2.5.4-dev and earlier allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO.
|
| CVE-2007-4024 |
Cross-site scripting (XSS) vulnerability in W1L3D4_aramasonuc.asp in
W1L3D4 Philboard 0.3 allows remote attackers to inject arbitrary web
script or HTML via the searchterms parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-4023 |
Cross-site scripting (XSS) vulnerability in the login CGI program in
Aruba Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and
earlier FIPS versions, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2007-4022 |
Cross-site scripting (XSS) vulnerability in
frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote
attackers to inject arbitrary web script or HTML via the resname
parameter.
|
| CVE-2007-4021 |
Multiple cross-site scripting (XSS) vulnerabilities in login.php in
Brain Book Software Secure 1.0.20070629 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1) user and
(2) pwd parameters.
|
| CVE-2007-4020 |
Multiple cross-site scripting (XSS) vulnerabilities in login.php in
AdMan 1.0.20051202 FF 3 patch and earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) user and (2) pwd
parameters.
|
| CVE-2007-4014 |
Cross-site scripting (XSS) vulnerability in a certain index.php
installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and
(3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote
attackers to inject arbitrary web script or HTML via the s parameter,
possibly a related issue to CVE-2007-2757. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-3991 |
Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp
cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3)
Ehliyet, (4) Askerlik, and (5) GSM parameters; and possibly other
unspecified vectors.
|
| CVE-2007-3989 |
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in
Dora Emlak 1.0, when the goster parameter is set to iletisim, allow
remote attackers to inject arbitrary web script or HTML via the (1)
Adiniz and (2) Soyadiniz parameters; and possibly other unspecified
vectors. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2007-3977 |
Cross-site scripting (XSS) vulnerability in bwired allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2007-3975 |
Cross-site scripting (XSS) vulnerability in index.php in Elite Forum
1.0.0.0 allows remote attackers to inject arbitrary web script or HTML
via the title parameter in a ptopic action, a different vulnerability
than CVE-2005-3412.
|
| CVE-2007-3974 |
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which
allows remote attackers to create arbitrary accounts via modified mot
and droit parameters.
|
| CVE-2007-3973 |
Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow
remote attackers to inject arbitrary web script or HTML via the (1) id
parameter to (a) index.php, or the (2) search parameter or (3) theme
cookie to (b) recherche.php.
|
| CVE-2007-3963 |
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7,
and possibly other 1.0.x versions, allow remote attackers to inject
arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1)
upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in
install/, a different vulnerability than CVE-2005-4193.
|
| CVE-2007-3941 |
Cross-site scripting (XSS) vulnerability in profile.php in Jasmine CMS
1.0_1 allows remote authenticated users to inject arbitrary web script
or HTML via the profile_email parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-3940 |
Cross-site scripting (XSS) vulnerability in default.asp in QuickerSite
1.7.2 allows remote attackers to inject arbitrary web script or HTML
via the svalue parameter in a search action. NOTE: some of these
details are obtained from third party information.
|
| CVE-2007-3930 |
Interpretation conflict between Microsoft Internet Explorer and
DocuWiki before 2007-06-26b allows remote attackers to inject
arbitrary JavaScript and conduct cross-site scripting (XSS) attacks
when spellchecking UTF-8 encoded messages via the spell_utf8test
function in lib/exe/spellcheck.php, which triggers HTML document
identification and script execution by Internet Explorer even though
the Content-Type header is text/plain.
|
| CVE-2007-3918 |
Cross-site scripting (XSS) vulnerability in account/verify.php in
GForge 4.6b2 allows remote attackers to inject arbitrary web script or
HTML via the confirm_hash parameter.
|
| CVE-2007-3910 |
Cross-site scripting (XSS) vulnerability in Bandersnatch 0.4 allows
remote attackers to inject arbitrary JavaScript via a Jabber resource
name and possibly other data items, which are stored in conversation
logs.
|
| CVE-2007-3888 |
Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple
Blog 0.5 and earlier allow remote attackers to inject arbitrary web
script or HTML via (1) the search action, possibly related to the term
parameter to index.php; or (2) an anonymous blog entry, possibly
involving the (a) posted_by, (b) subject, and (c) content parameters
to index.php; as demonstrated by the onmouseover attribute of certain
elements. NOTE: some of these details are obtained from third party
information.
|
| CVE-2007-3887 |
Multiple cross-site scripting (XSS) vulnerabilities in mesaj_formu.asp
in ASP Ziyaretci Defteri 1.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) Isim, (2) Mesajiniz, and (3)
E-posta fields. NOTE: these probably correspond to the isim, mesaj,
and posta parameters to save.php.
|
| CVE-2007-3886 |
Cross-site scripting (XSS) vulnerability in default.asp in Element CMS
allows remote attackers to inject arbitrary web script or HTML via the
s parameter in a search pID action.
|
| CVE-2007-3885 |
Cross-site scripting (XSS) vulnerability in philboard_search.asp in
husrevforum 1.0.1 allows remote attackers to inject arbitrary web
script or HTML via the searchterms parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-3844 |
Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and
SeaMonkey 1.1.3 allows remote attackers to conduct cross-site
scripting (XSS) attacks with chrome privileges via an addon that
inserts a (1) javascript: or (2) data: link into an about:blank
document loaded by chrome via (a) the window.open function or (b) a
content.location assignment, aka "Cross Context Scripting." NOTE: this
issue is caused by a CVE-2007-3089 regression.
|
| CVE-2007-3842 |
Cross-site scripting (XSS) vulnerability in the 8e6 R3000 Enterprise
Filter before 2.0.05 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors. NOTE: this may be the same as
CVE-2007-2970.
|
| CVE-2007-3839 |
Cross-site scripting (XSS) vulnerability in takeprofedit.php in
TBDev.NET DR 010306 and earlier allows remote attackers to inject
arbitrary web script or HTML via a javascript: URI in the avatar
parameter. NOTE: this may be related to the tracker program in the
Janitor package. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2007-3838 |
Cross-site scripting (XSS) vulnerability in takeprofedit.php in
TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote
attackers to inject arbitrary web script or HTML via the SRC attribute
of a SCRIPT element in the avatar parameter. NOTE: this may be related
to the tracker program in the Janitor package. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-3835 |
Cross-site scripting (XSS) vulnerability in Ex Libris MetaLib 3.13 and
4 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to a resource id that can be discovered
through a search.
|
| CVE-2007-3834 |
Multiple cross-site scripting (XSS) vulnerabilities in Ex Libris ALEPH
allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to a URL that can be discovered through a
keyword search. NOTE: this may be related to the MetaLib XSS issue,
CVE-2007-3835.
|
| CVE-2007-3830 |
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia
Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to
inject arbitrary web script or HTML via the reminder parameter.
|
| CVE-2007-3822 |
Multiple cross-site scripting (XSS) vulnerabilities in Webcit before
7.11 allow remote attackers to inject arbitrary web script or HTML via
(1) the who parameter to showuser; and other vectors involving (2)
calendar mode, (3) bulletin board mode, (4) room names, and (5)
uploaded file names.
|
| CVE-2007-3821 |
Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11
allows remote attackers to modify configurations and perform other
actions as arbitrary users via unspecified vectors.
|
| CVE-2007-3818 |
Cross-site scripting (XSS) vulnerability in the LoginToboggan module
5.x-1.x-dev before 20070712 for Drupal allows remote authenticated
users with "administer blocks" permission to inject arbitrary
JavaScript and gain privileges via "the message displayed above the
default user login block."
|
| CVE-2007-3817 |
Cross-site scripting (XSS) vulnerability in the LoginToboggan module
4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal,
when configured to display a "Log out" link, allows remote attackers
to inject arbitrary web script or HTML via a crafted username. NOTE:
Drupal sanitizes the username by removing certain characters, so this
might not be a vulnerability on default installations.
|
| CVE-2007-3807 |
Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum
before 7.3 allow remote attackers to inject arbitrary web script or
HTML via the user name field in the login procedure, and other
unspecified vectors.
|
| CVE-2007-3784 |
Cross-site scripting (XSS) vulnerability in the Belkin G Plus Router
F5D7231-4 with firmware 4.05.03 allows remote attackers to inject
arbitrary web script or HTML via a hostname of a DHCP client.
|
| CVE-2007-3769 |
Cross-site scripting (XSS) vulnerability in the mirrored server
management interface in SurgeFTP 2.3a1 allows user-assisted, remote
FTP servers to inject arbitrary web script or HTML via a malformed
response without a status code, which is reflected to the user in the
resulting error message. NOTE: this can be leveraged for root access
via a sequence of steps involving web script that creates a new FTP
user account.
|
| CVE-2007-3761 |
Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone
1.1.1 allows remote attackers to inject arbitrary web script or HTML
by causing Javascript events to be applied to a frame in another
domain.
|
| CVE-2007-3760 |
Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone
1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X
10.4 through 10.4.10, allows remote attackers to inject arbitrary web
script or HTML via frame tags.
|
| CVE-2007-3758 |
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on
Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers
to set Javascript window properties for web pages that are in a
different domain, which can be leveraged to conduct cross-site
scripting (XSS) attacks.
|
| CVE-2007-3736 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before
2.0.0.5 allows remote attackers to inject arbitrary web script "into
another site's context" via a "timing issue" involving the (1)
addEventListener or (2) setTimeout function, probably by setting
events that activate after the context has changed.
|
| CVE-2007-3712 |
Multiple cross-site scripting (XSS) vulnerabilities in HiddenChest "is
ve Bayi Basvuru Formu" (Yb ve Bayi Babvuru Formu) allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2007-3708 |
Cross-site scripting (XSS) vulnerability in CodeIgniter 1.5.3 before
20070626 allows remote attackers to inject arbitrary web script or
HTML via (1) String.fromCharCode and (2) malformed nested tag
manipulations in an unspecified component, related to insufficient
sanitization by the xss_clean function.
|
| CVE-2007-3694 |
Cross-site scripting (XSS) vulnerability in login.php in Miro Project
Broadcast Machine 0.9.9.9 allows remote attackers to inject arbitrary
web script or HTML via the username parameter.
|
| CVE-2007-3693 |
Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built
on Helma, allows remote attackers to inject arbitrary web script or
HTML via the q parameter to the search function.
|
| CVE-2007-3685 |
Cross-site scripting (XSS) vulnerability in rpc.php in Unobtrusive
Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject
arbitrary web script or HTML via the q parameter.
|
| CVE-2007-3672 |
Cross-site scripting (XSS) vulnerability in ecrire/tools.php in
DotClear 1.2.6 allows remote attackers to inject arbitrary web script
or HTML via unspecified form fields on the blogroll page.
|
| CVE-2007-3653 |
Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script
(aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary
web script or HTML via the (1) key or (2) desc parameter to index.php,
or (3) the name parameter to page.php.
|
| CVE-2007-3640 |
Adobe Integrated Runtime (AIR, aka Apollo) allows context-dependent
attackers to modify arbitrary files within an executing .air file
(compiled AIR application) and perform cross-site scripting (XSS)
attacks, as demonstrated by an application that modifies an HTML file
inside itself via JavaScript that uses an APPEND open operation and
the writeUTFBytes function. NOTE: this may be an intended consequence
of the AIR permission model; if so, then perhaps this issue should not
be included in CVE.
|
| CVE-2007-3623 |
Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand
Device Manager, Tiered Storage Manager, Replication Monitor, and
GlobalLink Availability Manager before 20070528 allows remote
attackers to inject arbitrary web script or HTML via the Expect HTTP
header.
|
| CVE-2007-3613 |
Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP
Internet Graphics Service (IGS) allows remote attackers to inject
arbitrary web script or HTML via the PARAMS parameter.
|
| CVE-2007-3596 |
inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric
characters in the sess_id parameter, which has unknown impact and
remote attack vectors, probably cross-site scripting (XSS).
|
| CVE-2007-3594 |
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet
ManageEngine OpManager 6 and 7 allow remote attackers to inject
arbitrary web script or HTML via the (1) name parameter in (a) ping.do
and (b) traceRoute.do in map/; the (2) reportName, (3) displayName,
and (4) selectedNode parameters to (c) reports/ReportViewAction.do;
the (5) operation parameter to (d) admin/ServiceConfiguration.do; and
the (6) selectedNode and (7) selectedTab parameters to (e)
admin/DeviceAssociation.do. NOTE: the searchTerm parameter in
Search.do is already covered by CVE-2006-2343.
|
| CVE-2007-3593 |
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine
NetFlow Analyzer 5 allow remote attackers to inject arbitrary web
script or HTML via the (1) alpha parameter in (a)
netflow/jspui/applicationList.jsp, the (2) task parameter in (b)
netflow/jspui/appConfig.jsp, the (3) view parameter in (c)
netflow/jspui/index.jsp, and the (4) rtype parameter in (d)
netflow/jspui/selectDevice.jsp and (e) netflow/jspui/customReport.jsp.
NOTE: it was later reported that vector 3 also affects 7.5 build 7500.
|
| CVE-2007-3590 |
Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB
2.24.0 allows remote attackers to inject arbitrary web script or HTML
via the user parameter.
|
| CVE-2007-3576 |
** DISPUTED **
Microsoft Internet Explorer 6 executes web script from URIs of
arbitrary scheme names ending with the "script" character sequence,
using the (1) vbscript: handler for scheme names with 7 through 9
characters, and the (2) javascript: handler for scheme names with 10
or more characters, which might allow remote attackers to bypass
certain XSS protection schemes. NOTE: other researchers dispute the
significance of this issue, stating "this only works when typed in the
address bar."
|
| CVE-2007-3574 |
Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on
the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06
firmware allow remote attackers to inject arbitrary web script or HTML
via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4)
snmp_setcomm parameter.
|
| CVE-2007-3569 |
Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library
Management System allow remote attackers to inject arbitrary web
script or HTML via the (1) updateform and (2) displayform parameter to
(a) gateway/gateway.exe; the (3) TERMS, (4) database, (5) srchad, (6)
SuggestedSearch, and (7) searchform parameters to the (b) "Basic
Search page"; and (8) username parameter when (c) logging on.
|
| CVE-2007-3561 |
Cross-site scripting (XSS) vulnerability in ara.asp in Efendy Blog 1.0
allows remote attackers to inject arbitrary web script or HTML via the
ara parameter. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2007-3559 |
Cross-site scripting (XSS) vulnerability in
infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and
6.01.9, when guest posts are enabled, allows remote authenticated
users to inject arbitrary web script or HTML via the URI, related to
the FUSION_QUERY constant.
|
| CVE-2007-3556 |
Liesbeth base CMS stores sensitive information under the web root with
insufficient access control, which allows remote attackers to download
an include file containing account credentials via a direct request
for config.inc.
|
| CVE-2007-3555 |
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1
allows remote attackers to inject arbitrary web script or HTML via a
style expression in the search parameter, a different vulnerability
than CVE-2004-1424.
|
| CVE-2007-3553 |
Cross-site scripting (XSS) vulnerability in Rapid Install Web Server
in Oracle Application Server 11i allows remote attackers to inject
arbitrary web script or HTML via a URL to the "Secondary Login Page",
as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2007-3546 |
Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus
Vulnerability Scanner before 3.0.6 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-3542 |
Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml
0.3.1 allows remote attackers to inject arbitrary web script or HTML
via the msg parameter.
|
| CVE-2007-3541 |
Cross-site scripting (XSS) vulnerability in Kurinton sHTTPd 20070408
and earlier allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2007-3540 |
Multiple cross-site scripting (XSS) vulnerabilities in search.asp in
rwAuction Pro 5.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) search, (2) show, (3) searchtype, (4)
catid, and (5) searchtxt parameters, a different version and vectors
than CVE-2005-4060.
|
| CVE-2007-3517 |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3
allow remote attackers to inject arbitrary web script or HTML via the
PATH_INFO (PHP_SELF) to (1) index.php, (2)
demo/claroline170/index.php, and possibly other scripts.
|
| CVE-2007-3516 |
Multiple cross-site scripting (XSS) vulnerabilities in kayit.asp in
Gorki Online Santrac Sitesi allow remote attackers to inject arbitrary
web script or HTML via the (1) kullanici, (2) posta, or (3) takim_adi
parameter to uyeler.asp. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-3503 |
The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML
documentation pages that contain cross-site scripting (XSS)
vulnerabilities, which allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2007-3501 |
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in
DirectAdmin 1.30.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the domain parameter, a different
vector than CVE-2007-1508.
|
| CVE-2007-3498 |
Cross-site scripting (XSS) vulnerability in smoketests/configForm.php
in HTML Purifier before 2.0.1 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors related to
"unescaped print_r output."
|
| CVE-2007-3496 |
Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java
(BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7
through SP11, aka SAP Java Technology Services 640 before SP20 and SAP
Web Dynpro Runtime Core Components 700 before SP12, allows remote
attackers to inject arbitrary web script or HTML via the User-Agent
HTTP header.
|
| CVE-2007-3495 |
Multiple cross-site scripting (XSS) vulnerabilities in the SAP
Internet Communication Framework (BC-MID-ICF) in the SAP Basis
component 700 before SP12, and 640 before SP20, allow remote attackers
to inject arbitrary web script or HTML via certain parameters
associated with the default login error page.
|
| CVE-2007-3486 |
Cross-site scripting (XSS) vulnerability in AltaVista search engine
allows remote attackers to inject arbitrary web script or HTML via the
text parameter to the default URI.
|
| CVE-2007-3485 |
Multiple cross-site scripting (XSS) vulnerabilities in Yandex.Server
allow remote attackers to inject arbitrary web script or HTML via the
(1) query or (2) within parameter to the default URI.
|
| CVE-2007-3484 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in search.php in Google
Custom Search Engine allows remote attackers to inject arbitrary web
script or HTML via the q parameter. NOTE: this issue is disputed by
the Google Security Team, who states that "Google does not provide the
'search.php' script referenced. When a user creates a custom search
engine, we provide them with a block of javascript to include on their
site. Some users write additional code around this block of
javascript to further customize their website."
|
| CVE-2007-3448 |
Cross-site scripting (XSS) vulnerability in index.php in BugMall
Shopping Cart 2.5 and earlier allows remote attackers to inject
arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and
other versions might also be affected.
|
| CVE-2007-3426 |
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA
1.4.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via the lang parameter.
|
| CVE-2007-3417 |
Multiple cross-site scripting (XSS) vulnerabilities in
cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow
remote attackers to inject arbitrary web script or HTML via a search
string, which is not sanitized when an HREF attribute is printed by
the (1) process_search or (2) show_recent_searches function.
|
| CVE-2007-3414 |
Multiple cross-site scripting (XSS) vulnerabilities in access2asp 4.5
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) od and (2) search parameters to (a) suppliersList.asp
and (b) contactsList.asp.
|
| CVE-2007-3413 |
Multiple cross-site scripting (XSS) vulnerabilities in bosDataGrid
2.50 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) GridSearch, (2) gsearch, or (3) ParentID parameter
to an unspecified component.
|
| CVE-2007-3412 |
Cross-site scripting (XSS) vulnerability in edit_image.asp in
ClickGallery Server 5.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the from parameter.
|
| CVE-2007-3405 |
Multiple cross-site scripting (XSS) vulnerabilities in defter_yaz.asp
in Lebisoft zdefter 4.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) ad and (2) konu parameters. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2007-3396 |
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF)
web server 3.1.0 allows remote attackers to inject arbitrary web
script or HTML via the opsubmenu parameter.
|
| CVE-2007-3386 |
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet
for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote
attackers to inject arbitrary HTML and web script via crafted
requests, as demonstrated using the aliases parameter to an html/add
action.
|
| CVE-2007-3384 |
Multiple cross-site scripting (XSS) vulnerabilities in
examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) Name or (2) Value field, related to error messages.
|
| CVE-2007-3383 |
Cross-site scripting (XSS) vulnerability in SendMailServlet in the
examples web application (examples/jsp/mail/sendmail.jsp) in Apache
Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote
attackers to inject arbitrary web script or HTML via the From field
and possibly other fields, related to generation of error messages.
|
| CVE-2007-3366 |
Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper
(scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378,
allows remote attackers to inject arbitrary web script or HTML via the
URI. NOTE: the provenance of this information is unknown; the details
are obtained solely from third party information.
|
| CVE-2007-3364 |
Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi
sample page in MyServer 0.8.9 allows remote attackers to inject
arbitrary web script or HTML via the body content.
|
| CVE-2007-3355 |
Multiple cross-site scripting (XSS) vulnerabilities in NetClassifieds
Premium Edition allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2007-3352 |
Cross-site scripting (XSS) vulnerability in the preview form in
Stephen Ostermiller Contact Form before 2.00.02 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors that contain an apostrophe.
|
| CVE-2007-3344 |
Multiple cross-site scripting (XSS) vulnerabilities in netjukebox
4.01b allow remote attackers to inject arbitrary web script or HTML
via the (1) album_id, (2) order, (3) sort, (4) filter, and (5)
genre_id parameters to (a) index.php; and the (6) url parameter to (b)
ridirect.php. NOTE: the attack also reveals the installation path.
|
| CVE-2007-3343 |
Cross-site scripting (XSS) vulnerability in RaidenHTTPD before 2.0.14
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-3342 |
Multiple cross-site scripting (XSS) vulnerabilities in Movable Type
(MT) before 3.34 allow remote attackers to inject arbitrary web script
or HTML via comments that have (1) a malformed SGML numeric character
reference with a '\0' (0x00) character in a javascript: URI or (2) an
attribute in an element that lacks the '>' character at the end of the
start tag, a different vulnerability than CVE-2007-0231.
|
| CVE-2007-3339 |
Multiple cross-site scripting (XSS) vulnerabilities in
forum/include/error/autherror.cfm in FuseTalk Basic, Standard,
Enterprise, and ColdFusion allow remote attackers to inject arbitrary
web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP
parameters to (a) forum/include/error/autherror.cfm, and the (3)
FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm
and (c) blog/include/common/comfinish.cfm.
|
| CVE-2007-3331 |
Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO
4.0 allows remote attackers to change the admin password via (1) a
certain HTML form that is posted automatically by JavaScript or (2) a
news post.
|
| CVE-2007-3330 |
Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0
allows remote attackers to inject arbitrary web script or HTML via a
news post, which is stored in news/ without sanitization.
|
| CVE-2007-3328 |
Multiple cross-site scripting (XSS) vulnerabilities in Interact 2.4
beta 1 allow remote attackers to inject arbitrary web script or HTML
via the (1) module_key parameter to (a) kb/kb.php, (b)
quiz/runquiz.php, (c) quiz/quiz.php, (d) forum/forum.php, (e)
forum/byname.php, and (f) journal/journalview.php in modules/, and
unspecified other scripts; the (2) tag_key parameter to
modules/journal/journalview.php; the (3) user_group_key parameter to
(g) users/secureaccounts.php; and (4) the request_uri parameter to (h)
login.php.
|
| CVE-2007-3326 |
Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow
remote attackers to redirect visitors to arbitrary local files via a
.. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the
Hyperlink information URl field for post Topic in showthread.php,
enabling cross-site scripting (XSS) and other attacks, a different
vulnerability than CVE-2005-3025.2.
|
| CVE-2007-3324 |
Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart
7.07 allow remote attackers to inject arbitrary web script or HTML via
the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp
or (2) comersus_message.asp, different vectors than CVE-2004-0681.
|
| CVE-2007-3323 |
SQL injection vulnerability in comersus_optReviewReadExec.asp in
Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary
SQL commands via the idProduct parameter. NOTE: this might be the same
as CVE-2005-2190.2.
|
| CVE-2007-3310 |
Cross-site scripting (XSS) vulnerability in arama.asp in TDizin allows
remote attackers to inject arbitrary web script or HTML via the ara
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2007-3299 |
Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when
AllSearchStr (aka the All Search Terms report) is enabled, allows
remote attackers to inject arbitrary web script or HTML via a search
string.
|
| CVE-2007-3291 |
Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier
allows remote attackers to inject arbitrary web script or HTML via an
article name, possibly involving the titulo parameter in article.php.
|
| CVE-2007-3288 |
Cross-site scripting (XSS) vulnerability in the skeltoac stats
(Automattic Stats) 1.0 plugin for WordPress allows remote attackers to
inject arbitrary web script or HTML via the HTTP Referer field.
|
| CVE-2007-3281 |
Cross-site scripting (XSS) vulnerability in index.php in Php Hosting
Biller 1.0 allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO.
|
| CVE-2007-3276 |
Cross-site scripting (XSS) vulnerability in index.php in Site@School
(S@S) 2.4.10 allows remote attackers to inject arbitrary web script or
HTML via the q parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-3269 |
Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6
before 20070611 allow remote attackers to inject arbitrary web script
or HTML via (1) the URI in a GET request or (2) the Title field of a
visitor comment, and (3) allow remote authenticated users to inject
arbitrary web script or HTML via a message to another user. NOTE:
vector (2) might overlap CVE-2006-3571.1.
|
| CVE-2007-3267 |
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum
1.01b and earlier allows remote attackers to inject arbitrary web
script or HTML via the fromaction parameter in a log action, a
different vector than CVE-2007-3235.
|
| CVE-2007-3265 |
Cross-site scripting (XSS) vulnerability in the Samples component in
IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-3261 |
Cross-site scripting (XSS) vulnerability in widgets/widget_search.php
in dKret before 2.6 allows remote attackers to inject arbitrary web
script or HTML via the PATH_INFO (PHP_SELF).
|
| CVE-2007-3254 |
Multiple cross-site scripting (XSS) vulnerabilities in Xythos
Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before
6.0.46.1, allow remote authenticated users to inject arbitrary web
script or HTML via (1) a saved Workflow name; (2) a Workflow name,
related to deletion of a Workflow template; (3) the Content-Type HTTP
header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also
affect the same version numbers of Xythos Digital Locker (XDL). Some
or all vectors might also affect Xythos WebFile Server.
|
| CVE-2007-3249 |
Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php
in the Letterman Subscriber (mod_letterman) before 1.2.5 module for
Joomla! allows remote attackers to inject arbitrary web script or HTML
via the Itemid parameter.
|
| CVE-2007-3243 |
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress
0.8.1 allows remote attackers to inject arbitrary web script or HTML
via the re parameter. NOTE: exploitation may require forcing the
client to send a certain Referer header.
|
| CVE-2007-3241 |
Cross-site scripting (XSS) vulnerability in blogroll.php in the
cordobo-green-park theme for WordPress allows remote attackers to
inject arbitrary web script or HTML via the PHP_SELF portion of a URI.
|
| CVE-2007-3240 |
Cross-site scripting (XSS) vulnerability in 404.php in the
Vistered-Little theme for WordPress allows remote attackers to inject
arbitrary web script or HTML via the URI (REQUEST_URI) that accesses
index.php. NOTE: this can be leveraged for PHP code execution in an
administrative session.
|
| CVE-2007-3239 |
Cross-site scripting (XSS) vulnerability in searchform.php in the
AndyBlue theme before 20070607 for WordPress allows remote attackers
to inject arbitrary web script or HTML via the PHP_SELF portion of a
URI to index.php. NOTE: this can be leveraged for PHP code execution
in an administrative session.
|
| CVE-2007-3238 |
Cross-site scripting (XSS) vulnerability in functions.php in the
default theme in WordPress 2.2 allows remote authenticated
administrators to inject arbitrary web script or HTML via the
PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different
vulnerability than CVE-2007-1622. NOTE: this might not cross privilege
boundaries in some configurations, since the Administrator role has
the unfiltered_html capability.
|
| CVE-2007-3235 |
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum
1.0 allows remote attackers to inject arbitrary web script or HTML via
the topic parameter. NOTE: this might be resultant from SQL injection.
|
| CVE-2007-3227 |
Cross-site scripting (XSS) vulnerability in the to_json
(ActiveRecord::Base#to_json) function in Ruby on Rails before edge
9606 allows remote attackers to inject arbitrary web script via the
input values.
|
| CVE-2007-3226 |
Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2006-2851 and
CVE-2006-3240.
|
| CVE-2007-3218 |
Cross-site scripting (XSS) vulnerability in request.php in PHP Live!
3.2.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via the pagex parameter.
|
| CVE-2007-3213 |
Multiple cross-site scripting (XSS) vulnerabilities in comments.cgi in
Sporum Forum 3.0.9 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) view and (2) mode parameters.
|
| CVE-2007-3212 |
Multiple cross-site scripting (XSS) vulnerabilities in links.php in
Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir
parameters, different vectors than CVE-2005-4460.
|
| CVE-2007-3211 |
Cross-site scripting (XSS) vulnerability in 404.php in Domain
Technologie Control (DTC) before 0.25.9 allows remote attackers to
inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI).
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2007-3202 |
Cross-site scripting (XSS) vulnerability in the rich text editor in
Webwiz allows remote attackers to inject arbitrary web script or HTML
via URL-encoded HTML composed of a frameset in which a frame has a SRC
attribute pointing to a JavaScript document.
|
| CVE-2007-3198 |
Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP
Blog (Maran Blog), possibly only versions before 20070610, allows
remote attackers to inject arbitrary web script or HTML via the id
parameter.
|
| CVE-2007-3195 |
Cross-site scripting (XSS) vulnerability in index.php in ERFAN WIKI
1.00 allows remote attackers to inject arbitrary web script or HTML
via the title parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-3189 |
Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun
Network Management System (JFFNMS) 0.8.3 allows remote attackers to
inject arbitrary web script or HTML via the user parameter.
|
| CVE-2007-3182 |
Multiple cross-site scripting (XSS) vulnerabilities in Calendarix
0.7.20070307, when register_globals is enabled, allow remote attackers
to inject arbitrary web script or HTML via the (1) year and (2) month
parameters to calendar.php, and the (3) leftfooter parameter to
cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is
already covered by CVE-2006-1835.
|
| CVE-2007-3174 |
Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online
Banking allows remote attackers to inject arbitrary web script or HTML
via the adtype parameter, a different vector than CVE-2006-1980.
|
| CVE-2007-3170 |
Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau
Webmail allow remote attackers to inject arbitrary web script or HTML
via (1) the PATH_INFO to redirect.php or (2) the selected_theme
parameter to demo/pop3/error.php.
|
| CVE-2007-3156 |
Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi
in Webmin before 1.350 and Usermin before 1.280 allow remote attackers
to inject arbitrary web script or HTML via the (1) cid, (2) message,
or (3) question parameter. NOTE: some of these details are obtained
from third party information.
|
| CVE-2007-3137 |
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in
WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) sbl, (2) sbr, or (3) search parameter.
NOTE: the original disclosure claims the pageid parameter in index.php
is affected, but this is incorrect.
|
| CVE-2007-3135 |
Cross-site scripting (XSS) vulnerability in atomPhotoBlog.php in Atom
Photoblog 1.0.9 and earlier allows remote attackers to inject
arbitrary web script or HTML via the tag parameter.
|
| CVE-2007-3134 |
Multiple cross-site scripting (XSS) vulnerabilities in
atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1) Your
Name, (2) Your Homepage, and (3) Your Comment fields, when using
"Approve Comments."
|
| CVE-2007-3131 |
Cross-site scripting (XSS) vulnerability in add_comment.php in Light
Blog 4.1 before 20070606 allows remote attackers to inject arbitrary
web script or HTML via the id parameter.
|
| CVE-2007-3129 |
Cross-site scripting (XSS) vulnerability in login.php in Utopia News
Pro 1.4.0 allows remote attackers to inject arbitrary web script or
HTML via the password parameter.
|
| CVE-2007-3120 |
Cross-site scripting (XSS) vulnerability in public/code/cp_dpage.php
in All In One Control Panel (AIOCP) before 1.3.017 allows remote
attackers to inject arbitrary web script or HTML via the aiocp_dp
parameter. NOTE: some of these details are obtained from third party
information.
|
| CVE-2007-3117 |
Cross-site scripting (XSS) vulnerability in the SEO module in ADPLAN 3
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to HTTP headers.
|
| CVE-2007-3110 |
Cross-site scripting (XSS) vulnerability in the Andy Frank Beatnik 1.0
extension for Firefox allows remote attackers to inject arbitrary web
script or HTML via an RSS feed. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-3101 |
Multiple cross-site scripting (XSS) vulnerabilities in certain JSF
applications in Apache MyFaces Tomahawk before 1.1.6 allow remote
attackers to inject arbitrary web script via the autoscroll parameter,
which is injected into Javascript that is sent to the client.
|
| CVE-2007-3078 |
Multiple cross-site scripting (XSS) vulnerabilities in Aigaion before
1.3.3 allow remote attackers to inject arbitrary web script or HTML
via the title parameter (Authors and Publication titles) to (1)
authoractions.php or (2) publicationactions.php.
|
| CVE-2007-3070 |
Cross-site scripting (XSS) vulnerability in index.php in BDigital Web
Solutions WebStudio allows remote attackers to inject arbitrary web
script or HTML via the pageid parameter.
|
| CVE-2007-3067 |
Cross-site scripting (XSS) vulnerability in the Attunement and Key
Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, possibly
involving the (1) keyshow, (2) sortkey, and (3) show parameters to
index.php.
|
| CVE-2007-3064 |
Cross-site scripting (XSS) vulnerability in diary.php in My Databook
allows remote attackers to inject arbitrary web script or HTML via the
year parameter.
|
| CVE-2007-3063 |
SQL injection vulnerability in diary.php in My Databook allows remote
attackers to execute arbitrary SQL commands via the delete parameter.
|
| CVE-2007-3062 |
Cross-site scripting (XSS) vulnerability in HP System Management
Homepage (SMH) before 2.1.2 running on Linux and Windows allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2007-3060 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) sid parameter to (a) chat.php, (2) LANG[DEFAULT_BRANDING] and (3)
PHPLIVE_VERSION parameters to (b) help.php, the (4) admin[name]
parameter to (c) admin/header.php, and the (5) BASE_URL parameter to
(d) super/info.php, and in some cases, the LANG[DEFAULT_BRANDING],
PHPLIVE_VERSION, and (6) nav_line parameters to setup/footer.php,
different vectors than CVE-2006-6769.
|
| CVE-2007-3056 |
Cross-site scripting (XSS) vulnerability in filedetails.php in WebSVN
2.0rc4, and possibly earlier, allows remote attackers to inject
arbitrary web script or HTML via the path parameter.
|
| CVE-2007-3055 |
Cross-site scripting (XSS) vulnerability in index.php in Codelib
Linker 2.0.4 and earlier allows remote attackers to inject arbitrary
web script or HTML via the cat parameter.
|
| CVE-2007-3054 |
Cross-site scripting (XSS) vulnerability in search.php in Codelib
Linker 2.0.4 and earlier allows remote attackers to inject arbitrary
web script or HTML via the kword parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-3049 |
Cross-site scripting (XSS) vulnerability in index.php in Buttercup web
file manager (BWFM) May 2007 allows remote attackers to inject
arbitrary web script or HTML via the title parameter.
|
| CVE-2007-3043 |
Cross-site scripting (XSS) vulnerability in Collaboration - File
Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi
Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration
Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus
Collaboration Portal up to 06-30-/D, and uCosminexus Collaboration
Portal - Forum/File Sharing up to 06-30-/C on Windows allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2007-3042 |
Cross-site scripting (XSS) vulnerability in Meneame before 2 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-3033 |
Cross-site scripting (XSS) vulnerability in Windows Vista Feed
Headlines Gadget (aka Sidebar RSS Feeds Gadget) in Windows Vista
allows user-assisted remote attackers to execute arbitrary code via an
RSS feed with crafted HTML attributes, which are not properly removed
and are rendered in the local zone.
|
| CVE-2007-3014 |
Multiple cross-site scripting (XSS) vulnerabilities in activeWeb
contentserver before 5.6.2964 allow remote attackers to inject
arbitrary web script or HTML via the msg parameter to (1)
errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a
MIME type (mimetype).
|
| CVE-2007-3001 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife
(PHPJK) allow remote attackers to inject arbitrary web script or HTML
via (1) the sUName parameter to UserArea/Authenticate.php, (2) the
sAccountUnq parameter to UserArea/NewAccounts/index.php, or the (3)
iCategoryUnq, (4) iDBLoc, (5) iTtlNumItems, (6) iNumPerPage, or (7)
sSort parameter to G_Display.php, different vectors than
CVE-2005-4239.
|
| CVE-2007-2993 |
Multiple cross-site scripting (XSS) vulnerabilities in OmegaMw7.asp in
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote
attackers to inject arbitrary web script or HTML via (1) user-created
text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and
other unspecified standard fields.
|
| CVE-2007-2992 |
Multiple SQL injection vulnerabilities in OmegaMw7.asp in OMEGA (aka
Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to
execute arbitrary SQL commands via (1) user-created text fields; the
(2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified
standard fields.
|
| CVE-2007-2991 |
Cross-site scripting (XSS) vulnerability in includes/send.inc.php in
Evenzia CMS allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO.
|
| CVE-2007-2976 |
Centrinity FirstClass 8.3 and earlier, and Server and Internet
Services 8.0 and earlier, do not properly handle a URL with a null
("%00") character, which allows remote attackers to conduct cross-site
scripting (XSS) attacks. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-2970 |
Multiple cross-site scripting (XSS) vulnerabilities in cgi/block.cgi
in 8e6 R3000 Internet Filter allow remote attackers to inject
arbitrary web script or HTML via the (1) URL, (2) CAT, and (3) USER
parameters. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2007-2968 |
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce
1.1.0 and earlier allows remote attackers to inject arbitrary web
script or HTML via the name parameter (Full Name field).
|
| CVE-2007-2963 |
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power
Board (IPB or IP.Board) 2.2.2, and possibly earlier, allows remote
attackers to inject arbitrary web script or HTML via (1)
module_bbcodeloader.php, (2) module_div.php, (3) module_email.php, (4)
module_image.php, (5) module_link.php, or (6) the editorid parameter
to module_table.php in jscripts/folder_rte_files/. NOTE: some details
were obtained from third party sources.
|
| CVE-2007-2962 |
Cross-site scripting (XSS) vulnerability in search.php in Particle
Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary
web script or HTML via the order parameter.
|
| CVE-2007-2932 |
Cross-site scripting (XSS) vulnerability in index.php in BoastMachine
allows remote attackers to inject arbitrary web script or HTML via the
blog parameter in a content search action.
|
| CVE-2007-2916 |
Cross-site scripting (XSS) vulnerability in showown.php in GMTT Music
Distro 1.2 allows remote attackers to inject arbitrary web script or
HTML via the st parameter.
|
| CVE-2007-2915 |
Cross-site scripting (XSS) vulnerability in RM EasyMail Plus allows
remote attackers to inject arbitrary web script or HTML via the title
field in an email.
|
| CVE-2007-2914 |
Multiple cross-site scripting (XSS) vulnerabilities in PsychoStats
3.0.6b allow remote attackers to inject arbitrary web script or HTML
via the PATH_INFO to (1) awards.php, (2) login.php, (3) register.php,
(4) weapons.php, and possibly other unspecified files.
|
| CVE-2007-2913 |
Cross-site scripting (XSS) vulnerability in index.php in ClonusWiki .5
allows remote attackers to inject arbitrary web script or HTML via the
query parameter.
|
| CVE-2007-2910 |
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before
3.6.7 PL1 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, related to the vb_367_xss_fix_plugin.xml
update, a related issue to CVE-2007-2909.
|
| CVE-2007-2909 |
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft
vBulletin 3.6.x before 3.6.7 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to the
vb_calendar366_xss_fix_plugin.xml update.
|
| CVE-2007-2908 |
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft
vBulletin before 3.6.6 allows remote attackers to inject arbitrary web
script or HTML via the title field in a single add action.
|
| CVE-2007-2907 |
Unspecified vulnerability in SSL-Explorer before 0.2.13 allows remote
authenticated users to enter redirect URLs containing (1) JavaScript
or (2) HTTP headers via an unspecified vector, possibly the forwardTo
parameter to redirect.do. NOTE: the impact might be cross-site
scripting (XSS) or HTTP request smuggling.
|
| CVE-2007-2904 |
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging
Server 6.0 through 6.3, when Internet Explorer is used, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, possibly a related issue to CVE-2006-5653.
|
| CVE-2007-2901 |
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0
and earlier allow remote attackers to inject arbitrary web script or
HTML via the img parameter to
main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and
other unspecified vectors.
|
| CVE-2007-2892 |
Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7
allows remote attackers to inject arbitrary web script or HTML via the
id parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2007-2887 |
Cross-site scripting (XSS) vulnerability in index.php in Web Icerik
Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary
web script or HTML via the No parameter in the Sayfa page.
|
| CVE-2007-2880 |
Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4
allow remote attackers to inject arbitrary web script or HTML via the
(1) Room_name parameter to room/info_book.asp or the (2) curYear
parameter to room/week.asp.
|
| CVE-2007-2879 |
Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk
Portal System 3G allows remote attackers to inject arbitrary web
script or HTML via the month parameter.
|
| CVE-2007-2870 |
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and
SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the
same-origin policy and conduct cross-site scripting (XSS) and other
attacks by using the addEventListener method to add an event listener
for a site, which is executed in the context of that site.
|
| CVE-2007-2865 |
Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin
4.1.1 allows remote attackers to inject arbitrary web script or HTML
via the server parameter.
|
| CVE-2007-2847 |
Multiple cross-site scripting (XSS) vulnerabilities in hlstats.php in
HLstats 1.35, and possibly earlier, allow remote attackers to inject
arbitrary web script or HTML via the (1) authusername or (2)
authpassword parameter, different vectors than CVE-2007-0840 and
CVE-2007-2812.
|
| CVE-2007-2832 |
Cross-site scripting (XSS) vulnerability in the web application
firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5,
4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers
to inject arbitrary web script or HTML via the pattern parameter to
CCMAdmin/serverlist.asp (aka the search-form) and possibly other
unspecified vectors.
|
| CVE-2007-2825 |
Multiple cross-site scripting (XSS) vulnerabilities in ReadMsg.php in
@Mail 5.02 and earlier allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors involving (1) links and (2)
images.
|
| CVE-2007-2819 |
Cross-site scripting (XSS) vulnerability in reportItem.do in Track+
3.3.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via the projId parameter.
|
| CVE-2007-2818 |
Cross-site scripting (XSS) vulnerability in cand_login.asp in
CactuSoft Parodia 6.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via the strJobIDs parameter.
|
| CVE-2007-2812 |
Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats
1.35, and possibly earlier, allows remote attackers to inject
arbitrary web script or HTML via (1) the PATH_INFO or (2) the action
parameter.
|
| CVE-2007-2811 |
Cross-site scripting (XSS) vulnerability in OSK Advance-Flow 4.41 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2007-2808 |
Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb
4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web
script or HTML via the database parameter.
|
| CVE-2007-2806 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
GaliX 2.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) galix_cat_detail, (2) galix_gal_detail, and (3)
galix_cat_detail_sort parameters.
|
| CVE-2007-2805 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote
attackers to inject arbitrary web script or HTML via the (1) ticketID,
(2) view, and (3) fuse parameters.
|
| CVE-2007-2804 |
Multiple cross-site scripting (XSS) vulnerabilities in
scripts/prodList.asp in CandyPress Store 3.5.2.14 and earlier allow
remote attackers to inject arbitrary web script or HTML via the (1)
brand and (2) Msg parameters.
|
| CVE-2007-2802 |
Cross-site scripting (XSS) vulnerability in cp/ps/Main/login/Login in
RM EasyMail Plus allows remote attackers to inject arbitrary web
script or HTML via the d parameter.
|
| CVE-2007-2801 |
Multiple cross-site scripting (XSS) vulnerabilities in open.php in
eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow
remote attackers to inject arbitrary web script or HTML via the (1)
err and (2) warn parameters. NOTE: the vendor disputes the
significance of the issue, stating that "eTicket is not designed to
work with register_globals On."
|
| CVE-2007-2790 |
Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP
Shopping Cart 6.50, and possibly earlier, allows remote attackers to
inject arbitrary web script or HTML via the type parameter.
|
| CVE-2007-2781 |
Cross-site scripting (XSS) vulnerability in
include/sessionRegister.php in WikyBlog before 1.4.13 allows remote
attackers to inject arbitrary web script or HTML, probably via vectors
related to a certain data2 array element.
|
| CVE-2007-2757 |
Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2
allow remote attackers to inject arbitrary web script or HTML via the
s parameter to (1) wp-content/themes/redoable/searchloop.php or (2)
wp-content/themes/redoable/header.php.
|
| CVE-2007-2745 |
Cross-site scripting (XSS) vulnerability in printcal.pl in vDesk
Webmail 4.03 allows remote attackers to inject arbitrary web script or
HTML via the type parameter.
|
| CVE-2007-2740 |
Unspecified vulnerability in xajax before 0.2.5 has unknown impact and
attack vectors, not related to XSS.
|
| CVE-2007-2739 |
Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-2732 |
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS
allow remote attackers to inject arbitrary web script or HTML via the
(1) path parameter to view/search/; or the (2) companyname, (3)
country, (4) email, (5) firstname, (6) middlename, (7) required, (8)
surname, or (9) title parameter to view/supplynews/.
|
| CVE-2007-2724 |
Cross-site scripting (XSS) vulnerability in all_photos.html in fotolog
allows remote attackers to inject arbitrary web script or HTML via the
user parameter.
|
| CVE-2007-2718 |
Cross-site scripting (XSS) vulnerability in the WebMail system in
Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft
Internet Explorer, allows remote attackers to inject arbitrary web
script or HTML via crafted STYLE tags.
|
| CVE-2007-2716 |
Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c
and earlier allow remote attackers to inject arbitrary web script or
HTML via the show parameter to (1) listmembers.php and (2) stats.php.
NOTE: some of these details are obtained from third party information.
|
| CVE-2007-2702 |
Cross-site scripting (XSS) vulnerability in the GroupSpace application
in BEA WebLogic Portal 9.2 GA allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors related to
the rich text editor.
|
| CVE-2007-2694 |
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic
Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1
through SP5, 9.0 GA, and 9.1 GA allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-2686 |
Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS
2.1 allows remote attackers to inject arbitrary web script or HTML via
the login parameter in a sendpwd task.
|
| CVE-2007-2680 |
Cross-site scripting (XSS) vulnerability in the management interface
in Canon Network Camera Server VB100 and VB101 with firmware 3.0 R69
and earlier, and VB150 with firmware 1.1 R39 and earlier, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-2676 |
PHP remote file inclusion vulnerability in skins/header.php in Open
Translation Engine (OTE) 0.7.8 allows remote attackers to execute
arbitrary PHP code via a URL in the ote_home parameter.
|
| CVE-2007-2670 |
PHPChain 1.0 and earlier allows remote attackers to obtain the
installation path via invalid values of the catid parameter to (1)
settings.php or (2) cat.php, as demonstrated by XSS manipulations.
|
| CVE-2007-2669 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPChain 1.0
and earlier allow remote attackers to inject arbitrary web script or
HTML via the catid parameter to (1) settings.php or (2) cat.php. NOTE:
certain parameter values also trigger path disclosure.
|
| CVE-2007-2632 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User
Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject
arbitrary web script or HTML via (1) the edit_plugin parameter to
configure_plugin.tpl.php, or (2) certain array parameters to
web/phpinfo.php, as demonstrated by 1[] or a[].
|
| CVE-2007-2627 |
Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress,
when custom 404 pages that call get_sidebar are used, allows remote
attackers to inject arbitrary web script or HTML via the query string
(PHP_SELF), a different vulnerability than CVE-2007-1622.
|
| CVE-2007-2625 |
Cross-site scripting (XSS) vulnerability in
shared/code/cp_authorization.php in All In One Control Panel (AIOCP)
before 1.3.016 allows remote attackers to inject arbitrary web script
or HTML via unspecified parameters. NOTE: some of these details are
obtained from third party information.
|
| CVE-2007-2624 |
Dynamic variable evaluation vulnerability in
shared/config/cp_config.php in All In One Control Panel (AIOCP) before
1.3.016 allows remote attackers to conduct cross-site scripting (XSS)
and possibly other attacks via the SERVER superglobal array. NOTE:
some of these details are obtained from third party information.
|
| CVE-2007-2610 |
Cross-site scripting (XSS) vulnerability in OpenLD before 1.1.9, and
1.1-modified before 1.1-modified3, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors in the Search
feature, possibly the term parameter.
|
| CVE-2007-2600 |
Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS
(aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) catFile parameter to
(a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c)
openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or
the (3) search parameter to search.php.
|
| CVE-2007-2592 |
Multiple cross-site scripting (XSS) vulnerabilities in Nokia
Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly
involving Novell Groupwise Mobile Server and Nokia Intellisync
Wireless Email Express, allow remote attackers to inject arbitrary web
script or HTML via the (1) username parameter to de/pda/dev_logon.asp
and (2) multiple unspecified vectors in (a)
usrmgr/registerAccount.asp, (b) de/create_account.asp, and other
files.
|
| CVE-2007-2581 |
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft
Windows SharePoint Services 3.0 for Windows Server 2003 and Office
SharePoint Server 2007 allow remote attackers to inject arbitrary web
script or HTML via the PATH_INFO (query string) in "every main page,"
as demonstrated by default.aspx.
|
| CVE-2007-2579 |
Multiple cross-site scripting (XSS) vulnerabilities in ACP3 4.0 beta 3
allow remote attackers to inject arbitrary web script or HTML via (1)
the form[mail] parameter to contact/contact/index.php; the (2)
form[mods][] or (3) form[search_term] parameter to
search/list/action_search/index.php; (4) the id parameter to
modules/dl/download.php; (5) the form[cat] parameter to
news/list/index.php; the (6) form[cat], (7) form[name], or (8)
form[message] parameter to certain
news/details/id_*/action_create/index.php files; or (9) the form[mail]
parameter to newsletter/create/index.php.
|
| CVE-2007-2562 |
Cross-site scripting (XSS) vulnerability in index.php in Kayako
eSupport 3.00.90 allows remote attackers to inject arbitrary web
script or HTML via the _m parameter.
|
| CVE-2007-2555 |
Unspecified vulnerability in Default.aspx in Podium CMS allows remote
attackers to have an unknown impact, possibly session fixation, via a
META HTTP-EQUIV Set-cookie expression in the id parameter, related to
"cookie manipulation." NOTE: this issue might be cross-site scripting
(XSS).
|
| CVE-2007-2551 |
Cross-site scripting (XSS) vulnerability in usersettings.php in
WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to
inject arbitrary web script or HTML via the name parameter.
|
| CVE-2007-2547 |
Cross-site scripting (XSS) vulnerability in index.php in
TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to
inject arbitrary web script or HTML via the l parameter.
|
| CVE-2007-2532 |
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen
Duong Obie Website Mini Web Shop 2 allow remote attackers to inject
arbitrary web script or HTML via the PATH_INFO (query string) to (1)
sendmail.php or (2) order_form.php, different vectors than
CVE-2006-6734.
|
| CVE-2007-2524 |
Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket
Request System (OTRS) 2.0.x allows remote attackers to inject
arbitrary web script or HTML via the Subaction parameter in an
AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this
identifier for an ipsec-tools issue, but the proper identifier for the
ipsec-tools issue is CVE-2007-1841.
|
| CVE-2007-2499 |
Multiple cross-site scripting (XSS) vulnerabilities in DVDdb 0.6 and
earlier allow remote attackers to inject arbitrary web script or HTML
via (1) the movieid parameter to loan.php or (2) the s parameter to
listmovies.php.
|
| CVE-2007-2472 |
Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard
3.4.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via the form parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-2470 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
FileRun 1.0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) page, (2) module, or (3) section parameter.
|
| CVE-2007-2450 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager
and (2) Host Manager web applications in Apache Tomcat 4.0.0 through
4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through
5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to
inject arbitrary web script or HTML via a parameter name to
manager/html/upload, and other unspecified vectors.
|
| CVE-2007-2449 |
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP
files in the examples web application in Apache Tomcat 4.0.0 through
4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through
5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject
arbitrary web script or HTML via the portion of the URI after the ';'
character, as demonstrated by a URI containing a "snp/snoop.jsp;"
sequence.
|
| CVE-2007-2433 |
Cross-site scripting (XSS) vulnerability in index.php in Ariadne 2.4.1
allows remote attackers to inject arbitrary web script or HTML via the
ARLogin parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-2432 |
Cross-site scripting (XSS) vulnerability in utilities/search.asp in
nukedit 4.9.7b allows remote attackers to inject arbitrary web script
or HTML via the terms parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-2431 |
Dynamic variable evaluation vulnerability in
shared/config/tce_config.php in TCExam 4.0.011 and earlier allows
remote attackers to conduct cross-site scripting (XSS) and possibly
other attacks by modifying critical variables such as $_SERVER, as
demonstrated by injecting web script via the _SERVER[SCRIPT_NAME]
parameter.
|
| CVE-2007-2423 |
Cross-site scripting (XSS) vulnerability in index.php in MoinMoin
1.5.7 allows remote attackers to inject arbitrary web script or HTML
via the do parameter in an AttachFile action, a different
vulnerability than CVE-2007-0857. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-2410 |
WebCore on Apple Mac OS X 10.3.9 and 10.4.10 retains properties of
certain global objects when a new URL is visited in the same window,
which allows remote attackers to conduct cross-site scripting (XSS)
attacks.
|
| CVE-2007-2404 |
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and
10.4.10 before 20070731 allows remote attackers to inject arbitrary
HTTP headers and conduct HTTP response splitting attacks via CRLF
sequences in an unspecified context. NOTE: this can be leveraged for
cross-site scripting (XSS) attacks.
|
| CVE-2007-2401 |
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9,
10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to
inject arbitrary HTTP headers via LF characters in an XMLHttpRequest
request, which are not filtered when serializing headers via the
setRequestHeader function. NOTE: this issue can be leveraged for
cross-site scripting (XSS) attacks.
|
| CVE-2007-2400 |
Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X,
Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote
attackers to bypass the JavaScript security model and modify pages
outside of the security domain and conduct cross-site scripting (XSS)
attacks via vectors related to page updating and HTTP redirects.
|
| CVE-2007-2391 |
Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1
for Windows allows remote attackers to inject arbitrary web script or
HTML via a web page that includes a windows.setTimeout function that
is activated after the user has moved from the current page.
|
| CVE-2007-2357 |
Cross-site scripting (XSS) vulnerability in mods/Core/result.php in
SineCms 2.3.4 allows remote attackers to inject arbitrary web script
or HTML via the stringa parameter.
|
| CVE-2007-2349 |
Cross-site scripting (XSS) vulnerability in Invision Power Board
(IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary
web script or HTML by uploading crafted images or PDF files.
|
| CVE-2007-2337 |
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS
0.96.6 Alpha and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) url parameter to (a) magpie_debug.php
and (b) magpie_simple.php in external/magpierss/scripts/, the (2)
rss_url parameter to (c) magpie_slashbox.php in
external/magpierss/scripts/, and the (3) body parameter to the (d)
weblogmodule (aka Weblog Comments) module.
|
| CVE-2007-2335 |
Cross-site scripting (XSS) vulnerability in the RSS feed reader
functionality in Lunascape 4.1.3 build2 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2007-2310 |
Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php
in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web
script or HTML via the img_url parameter.
|
| CVE-2007-2309 |
Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0
allows remote attackers to inject arbitrary web script or HTML via the
den parameter. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2007-2308 |
Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0
allows remote attackers to inject arbitrary web script or HTML via the
rok parameter.
|
| CVE-2007-2306 |
Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War
(VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when
register_globals is enabled, allow remote attackers to inject
arbitrary web script or HTML via the (1) memberlist parameter to
extra/login.php and the (2) title parameter to extra/today.php.
|
| CVE-2007-2300 |
Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto
Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier
allow remote attackers to inject arbitrary web script or HTML via the
m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php.
|
| CVE-2007-2265 |
Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows
remote attackers to inject arbitrary web script or HTML via the City
field in a sign action in index.php.
|
| CVE-2007-2256 |
Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95
allows remote attackers to inject arbitrary web script or HTML via the
user parameter.
|
| CVE-2007-2248 |
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in
Phorum before 5.1.22 allow remote attackers to inject arbitrary web
script or HTML via the (1) group_id parameter in the groups module or
(2) the smiley_id parameter in the smileys modsettings module.
|
| CVE-2007-2245 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
before 2.10.1.0 allow remote attackers to inject arbitrary web script
or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2)
certain input to the PMA_sanitize function.
|
| CVE-2007-2236 |
footer.php in PunBB 1.2.14 and earlier allows remote attackers to
include local files in include/user/ via a cross-site scripting (XSS)
attack, or via the pun_include tag, as demonstrated by use of
admin_options.php to execute PHP code from an uploaded avatar file.
|
| CVE-2007-2235 |
Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) Referer HTTP header to misc.php or the (2) category
name when deleting a category in admin_categories.php.
|
| CVE-2007-2206 |
Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe
Website Manager 0.8.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via a leading "<"<" in the
ripeformpost parameter.
|
| CVE-2007-2203 |
Cross-site scripting (XSS) vulnerability in Big Blue Guestbook allows
remote attackers to inject arbitrary web script or HTML via the
message field in the guestbook entry submission form.
|
| CVE-2007-2198 |
Cross-site scripting (XSS) vulnerability in LAN Management System
(LMS) before 1.6.9 allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors, probably involving the OD
parameter to contrib/formularz_przelewu_wplaty/druk.php.
|
| CVE-2007-2191 |
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x
allow remote attackers to inject arbitrary web script or HTML via the
(1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other
SIP protocol fields, which are stored in /var/log/asterisk/full and
displayed by admin/modules/logfiles/asterisk-full-log.php.
|
| CVE-2007-2159 |
Multiple cross-site scripting (XSS) vulnerabilities in the Database
Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the
4.7.x-1.* series, for Drupal allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors relating to (1)
direct display of data from the database and (2) other portions of the
user interface.
|
| CVE-2007-2153 |
Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0
allows remote attackers to inject arbitrary web script or HTML via the
username parameter.
|
| CVE-2007-2119 |
Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the
Administration Front End for Oracle Enterprise (Ultra) Search, as used
in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application
Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to
inject arbitrary HTML or web script via the EXPTYPE parameter, aka
SES01.
|
| CVE-2007-2102 |
Cross-site scripting (XSS) vulnerability in weblog.php in my little
weblog allows remote attackers to inject arbitrary web script or HTML
via the id parameter, a different vector than CVE-2006-6087.
|
| CVE-2007-2099 |
Cross-site scripting (XSS) vulnerability in htdocs/php.php in
OpenConcept Back-End CMS 0.4.7 allows remote attackers to inject
arbitrary web script or HTML via the page[] parameter.
|
| CVE-2007-2098 |
Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in
Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web
script or HTML via the (1) pic and (2) gal parameters.
|
| CVE-2007-2090 |
Cross-site scripting (XSS) vulnerability in index.php in TuMusika
Evolution 1.6 allows remote attackers to inject arbitrary web script
or HTML via the msg parameter.
|
| CVE-2007-2085 |
Cross-site scripting (XSS) vulnerability in oe2edit.cgi in oe2edit CMS
allows remote attackers to inject arbitrary web script or HTML via the
q parameter.
|
| CVE-2007-2071 |
Multiple cross-site scripting (XSS) vulnerabilities in Open-gorotto
2.0a 2006/02/08 edition, 2006/03/19 edition, and 2006/04/07 edition
before 20070416 allow remote attackers to inject arbitrary web script
or HTML via unspecified parameters to (1) pub/modules/d/_top.html; (2)
/pub/modules/a/_access.html; (3) _circletop.html or (4) _cir66.html in
pub/modules/ci/; or (5) _fri66.html, (6) _inv66.html, (7) _top.html,
(8) _friends.html, or (9) _fri33.html in pub/modules/f/.
|
| CVE-2007-2061 |
Cross-site scripting (XSS) vulnerability in check_login.asp in
AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject
arbitrary web script or HTML via the username parameter.
|
| CVE-2007-2016 |
Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in
phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web
script or HTML via the lang[] parameter.
|
| CVE-2007-2013 |
Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme
Einfacher Passworschutz allows remote attackers to inject arbitrary
web script or HTML via the msg parameter.
|
| CVE-2007-2011 |
Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1
allows remote attackers to inject arbitrary web script or HTML via the
username parameter.
|
| CVE-2007-1991 |
Cross-site scripting (XSS) vulnerability in mail/signup.asp in
CmailServer WebMail 5.4.3, and possibly earlier, allows remote
attackers to inject arbitrary web script or HTML via the Comment
parameter, a different vector than CVE-2007-1927.
|
| CVE-2007-1989 |
Multiple cross-site scripting (XSS) vulnerabilities in DotClear before
1.2.6 allow remote attackers to inject arbitrary web script or HTML
via the (1) post_id parameter to ecrire/trackback.php or the (2)
tool_url parameter to tools/thememng/index.php. NOTE: some of these
details are obtained from third party information.
|
| CVE-2007-1988 |
Cross-site scripting (XSS) vulnerability in kernel/filters.inc.php in
PHPEcho CMS 2.0 allows remote attackers to inject arbitrary web script
or HTML via the id parameter.
|
| CVE-2007-1977 |
Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS
1.4.10 allows remote attackers to inject arbitrary web script or HTML
via the acuparam parameter.
|
| CVE-2007-1969 |
Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam
Crew MyBlog remote attackers to inject arbitrary web script or HTML
via the id parameter.
|
| CVE-2007-1965 |
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS
2.0.4.3 and earlier allow remote attackers to inject arbitrary web
script or HTML via the set_lang parameter to (1) archive.php, (2)
article.php, (3) index.php, or (4) topics.php.
|
| CVE-2007-1950 |
Cross-site scripting (XSS) vulnerability in index_cms.php in
WebBlizzard CMS allows remote attackers to inject arbitrary web script
or HTML via the Suchzeile parameter.
|
| CVE-2007-1941 |
Cross-site scripting (XSS) vulnerability in the Active Content Filter
feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and
7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web
script or HTML via a multipart/related e-mail message, a different
issue than CVE-2006-4843.
|
| CVE-2007-1939 |
Cross-site scripting (XSS) vulnerability in the embedded webserver in
Daniel Naber LanguageTool before 0.8.9 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors involving
an error message, possibly the demultiplex method in HTTPServer.java.
|
| CVE-2007-1938 |
Ichitaro 2005 through 2007, and possibly related products, allows
remote attackers to have an unknown impact via unspecified vectors in
a document distributed through e-mail or a web site, possibly due to a
buffer overflow or cross-site scripting (XSS).
|
| CVE-2007-1927 |
Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer
WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary
web script or HTML via the POP3Mail parameter.
|
| CVE-2007-1926 |
Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin
before 1.293 does not properly display log files, which allows remote
authenticated users to inject arbitrary web script or HTML via (1)
http or (2) ftp requests logged in /var/log/directadmin/security.log;
(3) allows context-dependent attackers to inject arbitrary web script
or HTML into /var/log/messages via a PHP script that invokes
/usr/bin/logger; (4) allows local users to inject arbitrary web script
or HTML into /var/log/messages by invoking /usr/bin/logger at the
command line; and allows remote attackers to inject arbitrary web
script or HTML via remote requests logged in the (5)
/var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7)
/var/log/proftpd/auth.log, (8) /var/log/httpd/error_log, (9)
/var/log/httpd/access_log, (10) /var/log/directadmin/error.log, and
(11) /var/log/directadmin/security.log files.
|
| CVE-2007-1919 |
Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream
Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web
script or HTML via the page parameter.
|
| CVE-2007-1905 |
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple
Technologies QuizShock 1.6.1 and earlier allows remote attackers to
inject arbitrary web script or HTML via encoded special characters in
the forward_to parameter, as demonstrated using "<"<".
|
| CVE-2007-1903 |
Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0
allows remote attackers to inject arbitrary web script or HTML via the
part parameter.
|
| CVE-2007-1894 |
Cross-site scripting (XSS) vulnerability in
wp-includes/general-template.php in WordPress before 20070309 allows
remote attackers to inject arbitrary web script or HTML via the year
parameter in the wp_title function.
|
| CVE-2007-1873 |
Cross-site scripting (XSS) vulnerability in Mephisto 0.7.3 allows
remote attackers to inject arbitrary web script or HTML via the q
parameter to the search script.
|
| CVE-2007-1872 |
Cross-site scripting (XSS) vulnerability in toendaCMS 1.5.3 allows
remote attackers to inject arbitrary web script or HTML via the
searchword parameter in a search id.
|
| CVE-2007-1871 |
Cross-site scripting (XSS) vulnerability in chcounter 3.1.3 allows
remote attackers to inject arbitrary web script or HTML via the
login_name parameter to /stats/.
|
| CVE-2007-1848 |
Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php
in Drake CMS allows remote attackers to inject arbitrary web script or
HTML via the desc[][title] field. NOTE: Drake CMS has only a beta
version available, and the vendor has previously stated "We do not
consider security reports valid until the first official release of
Drake CMS."
|
| CVE-2007-1840 |
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not
escape HTML special characters in LDAP data, which allows remote
attackers to have an unknown impact, probably cross-site scripting
(XSS).
|
| CVE-2007-1830 |
Unspecified vulnerability in the Username Hijacking Patch 20070312 for
web-app.org WebAPP 0.9.9.6 allows remote attackers to obtain
administrative access via unknown vectors, related to "something
overlooked in the original that was still overlooked in the patch",
and possibly related to copying files to the user-lib and the "XSS and
cookies exploit."
|
| CVE-2007-1828 |
Multiple cross-site scripting (XSS) vulnerabilities in web-app.org
WebAPP before 0.9.9.6 allow remote authenticated users to inject
arbitrary web script or HTML via (1) the QUERY_STRING corresponding to
drop downs or (2) various forms.
|
| CVE-2007-1802 |
Cross-site scripting (XSS) vulnerability in MailDwarf 3.01 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-1780 |
Cross-site scripting (XSS) vulnerability in the DHT shell (owdhtshell)
in Overlay Weaver 0.5.9 to 0.5.11, when invoked with the -x option,
allows remote attackers to inject arbitrary web script or HTML via
fields in certain input forms.
|
| CVE-2007-1774 |
Multiple cross-site scripting (XSS) vulnerabilities in aBitWhizzy
allow remote attackers to inject arbitrary web script or HTML via the
d parameter to (1) whizzery/whizzypic.php or (2)
whizzery/whizzylink.php.
|
| CVE-2007-1768 |
Cross-site scripting (XSS) vulnerability in
app/helpers/application_helper.rb in Mephisto 0.7.3 and Mephisto Edge
20070325 allows remote attackers to inject arbitrary web script or
HTML via the author name field in a comment.
|
| CVE-2007-1732 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in an mt import in
wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated
administrators to inject arbitrary web script or HTML via the demo
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information. NOTE:
another researcher disputes this issue, stating that this is
legitimate functionality for administrators. However, it has been
patched by at least one vendor.
|
| CVE-2007-1723 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administration console in Secure Computing CipherTrust IronMail 6.1.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) network, (2) defRouterIp, (3) hostName, (4) domainName, (5)
ipAddress, (6) defaultRouter, (7) dns1, or (8) dns2 parameter to (a)
admin/system_IronMail.do; the (9) ipAddress parameter to (b)
admin/systemOutOfBand.do; the (10) password or (11) confirmPassword
parameter to (c) admin/systemBackup.do; the (12) Klicense parameter to
(d) admin/systemLicenseManager.do; the (13) rows[1].attrValueStr or
(14) rows[2].attrValueStr parameter to (e)
admin/systemWebAdminConfig.do; the (15) rows[0].attrValueStr,
rows[1].attrValueStr, (16) rows[2].attrValue, or (17)
rows[2].attrValueStrClone parameter to (f)
admin/ldap_ConfigureServiceProperties.do; the (18) input1 parameter to
(g) admin/mailFirewall_MailRoutingInternal.do; or the (19)
rows[2].attrValueStr, (20) rows[3].attrValueStr, (21)
rows[5].attrValueStr, or (22) rows[6].attrValueStr parameter to (h)
admin/mailIdsConfig.do.
|
| CVE-2007-1714 |
Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0
allows remote attackers to inject arbitrary web script or HTML via dir
parameter.
|
| CVE-2007-1679 |
** DISPUTED **
Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware
Webmail 1.0 allow remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors in (1) imp/search.php and (2)
ingo/rule.php. NOTE: this issue has been disputed by the vendor,
noting that the search.php issue was resolved in CVE-2006-4255, and
attackers can only use rule.php to inject XSS into their own pages.
|
| CVE-2007-1678 |
Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension
for Firefox allows remote attackers to inject arbitrary web script or
HTML via RSS feeds, which are executed by the chrome: URI handler.
|
| CVE-2007-1646 |
Multiple cross-site scripting (XSS) vulnerabilities in SubHub 2.3.0
allow remote attackers to inject arbitrary web script or HTML via (1)
the searchtext parameter to (a) /search, or the (2) message parameter
to (b) /calendar or (c) /subscribe.
|
| CVE-2007-1625 |
Cross-site scripting (XSS) vulnerability in save_entry.php in
realGuestbook 5.01 allows remote attackers to inject arbitrary web
script or HTML via the homepage parameter, as reachable through
add_entry.php. NOTE: the original report stated that the
vulnerability was in add_entry.php, which does not receive the input
data.
|
| CVE-2007-1623 |
Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook
5.01, when register_globals is enabled, allow remote attackers to
inject arbitrary web script or HTML via the (1) bg_color_1, (2)
fs_menu, (3) fc_menu, (4) ff_menu, (5) bg_color_2, (6) fs_normal, (7)
fc_normal, and (8) ff_normal parameters to welcome_admin.php; and
possibly unspecified other parameters and files. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2007-1622 |
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in
WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series,
allows remote authenticated users with theme privileges to inject
arbitrary web script or HTML via the PATH_INFO in the administration
interface, related to loose regular expression processing of PHP_SELF.
|
| CVE-2007-1611 |
Cross-site scripting (XSS) vulnerability in the RSS reader in a
certain SOURCENEXT product, probably IKANARI JIJYOU 1.0.0 and 1.0.1,
allows remote attackers to inject arbitrary web script or HTML via the
title of an article in a feed.
|
| CVE-2007-1610 |
Cross-site scripting (XSS) vulnerability in the RSS reader in Glue
Software NewsGlue before 1.3.4 allows remote attackers to inject
arbitrary web script or HTML via a feed.
|
| CVE-2007-1609 |
Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic
Monitoring Services (DMS) in Oracle Application Server (OAS) 10g
10.1.2.0.0 allows remote attackers to inject arbitrary web script or
HTML via the table parameter. NOTE: This may be related to
CVE-2002-0563.
|
| CVE-2007-1606 |
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora
(Web-Agora) allow remote attackers to inject arbitrary web script or
HTML via (1) the showuser parameter to profile.php, the (2)
search_forum or (3) search_user parameter to search.php, or (4) the
userid parameter to change_password.php.
|
| CVE-2007-1576 |
Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt
5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors
to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only
Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail
summary page; and unspecified other files.
|
| CVE-2007-1551 |
Multiple cross-site scripting (XSS) vulnerabilities in phpx 3.5.15
allow remote attackers to inject arbitrary web script or HTML via (1)
the signature in "dans profile," or (2) search.php.
|
| CVE-2007-1520 |
The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and
earlier does not ensure the SERVER superglobal is an array before
validating the HTTP_REFERER, which allows remote attackers to conduct
CSRF attacks.
|
| CVE-2007-1519 |
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke
8.0 and earlier allows remote attackers to inject arbitrary web script
or HTML via the query parameter in a search operation in the Downloads
module, a different product than CVE-2006-3948.
|
| CVE-2007-1515 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3
4.1.3, and possibly earlier, allow remote attackers to inject
arbitrary web script or HTML via (1) the email Subject header in
thread.php, (2) the edit_query parameter in search.php, or other
unspecified parameters in search.php. NOTE: some of these details are
obtained from third party information.
|
| CVE-2007-1508 |
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in
DirectAdmin allows remote attackers to inject arbitrary web script or
HTML via the RESULT parameter, a different vector than CVE-2006-5983.
|
| CVE-2007-1506 |
Cross-site scripting (XSS) vulnerability in
PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows
remote attackers to inject arbitrary web script or HTML via the (1)
p_oldurl and (2) p_newurl parameters.
|
| CVE-2007-1504 |
Cross-site scripting (XSS) vulnerability in the Servlet Service in
Fujitsu Interstage Application Server (IJServer) 8.0.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, possibly involving web.xml and HTTP 404 and 500
status codes.
|
| CVE-2007-1494 |
Cross-site scripting (XSS) vulnerability in NukeSentinel before 2.5.06
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to the "filters for https:// and http://".
|
| CVE-2007-1482 |
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows
remote attackers to inject arbitrary web script or HTML via the e_id
parameter in a viewentry cmd.
|
| CVE-2007-1479 |
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative
Guestbook 1.0 allows remote attackers to inject arbitrary web script
or HTML via an unspecified parameter.
|
| CVE-2007-1473 |
Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in
Horde Framework before 3.1.4 RC1, when the login page contains a
language selection box, allows remote attackers to inject arbitrary
web script or HTML via the new_lang parameter to login.php.
|
| CVE-2007-1468 |
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest
(CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web
script or HTML via an attachment to a defect log entry.
|
| CVE-2007-1467 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control
Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace,
Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP
Communicator, Unified Video Advantage, Unified Videoconferencing 35xx
products, Unified Videoconferencing Manager, WAN Manager, Security
Device Manager, Network Analysis Module (NAM), CiscoWorks and related
products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN
Controllers (WLC), and Wireless Control System (WCS) allow remote
attackers to inject arbitrary web script or HTML via the text field of
the search form.
|
| CVE-2007-1454 |
ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the
FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which
allows remote attackers to conduct cross-site scripting (XSS) attacks
via HTML with a '<' character followed by certain whitespace
characters, which passes one filter but is collapsed into a valid tag,
as demonstrated using %0b.
|
| CVE-2007-1443 |
Multiple cross-site scripting (XSS) vulnerabilities in register.php in
Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e
allow remote attackers to inject arbitrary web script or HTML via the
(1) r_username, (2) r_email, (3) r_password, (4) r_confirmpassword,
(5) r_homepage, (6) r_icq, (7) r_aim, (8) r_yim, (9) r_msn, (10)
r_year, (11) r_month, (12) r_day, (13) r_gender, (14) r_signature,
(15) r_usertext, (16) r_invisible, (17) r_usecookies, (18)
r_admincanemail, (19) r_emailnotify, (20) r_notificationperpm, (21)
r_receivepm, (22) r_emailonpm, (23) r_pmpopup, (24) r_showsignatures,
(25) r_showavatars, (26) r_showimages, (27) r_daysprune, (28)
r_umaxposts, (29) r_dateformat, (30) r_timeformat, (31) r_startweek,
(32) r_timezoneoffset, (33) r_usewysiwyg, (34) r_styleid, (35)
r_langid, (36) key_string, (37) key_number, (38) disablesmilies, (39)
disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and
(43) field[3] parameters. NOTE: a third-party researcher has disputed
some of these vectors, stating that only the r_dateformat and
r_timeformat parameters in Burning Board 2.3.6 are affected.
|
| CVE-2007-1433 |
Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and
possibly earlier versions, allows remote attackers to inject arbitrary
web script or HTML via the comment fields to (1)
scripts/addblog_comment.php and (2) detail.php.
|
| CVE-2007-1418 |
Cross-site scripting (XSS) vulnerability in
skins/ace/popup-notopic.php in MindTouch OpenGarden DekiWiki before
Gooseberry++ allows remote attackers to inject arbitrary web script or
HTML via the message parameter.
|
| CVE-2007-1405 |
Cross-site scripting (XSS) vulnerability in the "download wiki page as
text" feature in Trac before 0.10.3.1, when Microsoft Internet
Explorer is used, allows remote attackers to inject arbitrary web
script or HTML via unspecified parameters.
|
| CVE-2007-1395 |
Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0
through 2.9.2 allows remote attackers to conduct cross-site scripting
(XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or
(2) table parameter value followed by an uppercase </SCRIPT> end tag,
which bypasses the protection against lowercase </script>.
|
| CVE-2007-1390 |
Multiple cross-site scripting (XSS) vulnerabilities in dynaliens 2.0
and 2.1 allow remote attackers to inject arbitrary web script or HTML
via unspecified parameters to (1) recherche.php3 or (2) ajouter.php3.
|
| CVE-2007-1389 |
dynaliens 2.0 and 2.1 allows remote attackers to bypass authentication
and perform certain privileged actions via a direct request for (1)
validlien.php3 (2) supprlien.php3 (3) supprub.php3 (4) validlien.php3
(5) confsuppr.php3 (6) modiflien.php3, or (7) confmodif.php3 in
admin/.
|
| CVE-2007-1374 |
Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz
Forums 2000 3.4.06 allows remote attackers to inject arbitrary web
script or HTML via the MSN parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-1367 |
Cross-site scripting (XSS) vulnerability in the login page in Avaya
Communications Manager (CM) S87XX, S8500, and S8300 products before
3.1.3 allows remote attackers to inject arbitrary web script or HTML
via the Login field.
|
| CVE-2007-1361 |
Cross-site scripting (XSS) vulnerability in virtuemart_parser.php in
VirtueMart before 20070213 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors. NOTE: this issue is
probably different than CVE-2007-0376.
|
| CVE-2007-1358 |
Cross-site scripting (XSS) vulnerability in certain applications using
Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows
remote attackers to inject arbitrary web script or HTML via crafted
"Accept-Language headers that do not conform to RFC 2616".
|
| CVE-2007-1355 |
Multiple cross-site scripting (XSS) vulnerabilities in the
appdev/sample/web/hello.jsp example application in Tomcat 4.0.0
through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0
through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to
inject arbitrary web script or HTML via the test parameter and
unspecified vectors.
|
| CVE-2007-1342 |
Cross-site scripting (XSS) vulnerability in admincp/index.php in
Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject
arbitrary web script or HTML via the add rss url form.
|
| CVE-2007-1331 |
Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking
Solutions ePortfolio 1.0 Java allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors that bypass the
client-side protection scheme, one of which may be the q parameter to
the search program. NOTE: some of these details are obtained from
third party information.
|
| CVE-2007-1328 |
Cross-site scripting (XSS) vulnerability in formulaire.php in Bernard
JOLY BJ Webring allows remote attackers to inject arbitrary web script
or HTML via an unspecified parameter related to the add link menu.
|
| CVE-2007-1305 |
Multiple cross-site scripting (XSS) vulnerabilities in add2.php in
Sava's Guestbook 23.11.2006 allow remote attackers to inject arbitrary
web script or HTML via the (1) name, (2) country, (3) email, and (4)
website parameters.
|
| CVE-2007-1291 |
Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug
Tracking System (TygerBT) 1.1.3 allow remote attackers to inject
arbitrary web script or HTML via the PATH_INFO to (1) Login.php and
(2) Register.php.
|
| CVE-2007-1287 |
A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and
PHP 6.0 in CVS, allows remote attackers to conduct cross-site
scripting (XSS) attacks via GET, POST, or COOKIE array values, which
are not escaped in the phpinfo output, as originally fixed for
CVE-2005-3388.
|
| CVE-2007-1280 |
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and
Server 6 allows remote attackers to inject arbitrary web script or
HTML via a URL after a # (hash) in the URL path, as demonstrated using
en/frameset-7.html, and possibly other unspecified vectors involving
templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3)
wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5)
WindowManager.dll in RoboHelp Server 6.
|
| CVE-2007-1276 |
Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in
Webmin before 1.330 and Usermin before 1.260 allow remote attackers to
inject arbitrary web script or HTML via a crafted filename.
|
| CVE-2007-1262 |
Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter
in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject
arbitrary web script or HTML via the (1) data: URI in an HTML e-mail
attachment or (2) various non-ASCII character sets that are not
properly filtered when viewed with Microsoft Internet Explorer.
|
| CVE-2007-1248 |
Multiple cross-site scripting (XSS) vulnerabilities in built2go News
Manager Blog 1.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a)
news.php, and the nid parameter to (b) rating.php.
|
| CVE-2007-1244 |
Cross-site request forgery (CSRF) vulnerability in the AdminPanel in
WordPress 2.1.1 and earlier allows remote attackers to perform
privileged actions as administrators, as demonstrated using the delete
action in wp-admin/post.php. NOTE: this issue can be leveraged to
perform cross-site scripting (XSS) attacks and steal cookies via the
post parameter.
|
| CVE-2007-1241 |
Cross-site scripting (XSS) vulnerability in setup.php in Audins
Audiens 3.3 allows remote attackers to inject arbitrary web script or
HTML via the PATH_INFO. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-1240 |
Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS
3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web
script or HTML via (1) the searchkey parameter to index.php, or the
(2) sn or (3) ri parameter to modules/htmlframechat/index.php. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2007-1234 |
Multiple cross-site scripting (XSS) vulnerabilities in sitex allow
remote attackers to inject arbitrary web script or HTML via (1) the
sxYear parameter to calendar.php, (2) the search parameter to
search.php, (3) the linkid parameter to redirect.php, or (4) the page
parameter to calendar_events.php.
|
| CVE-2007-1231 |
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager
1.2.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) database name, (2) table name, (3) ViewName, (4) view, (5)
trigger, and (6) function fields in main.php and certain other files.
|
| CVE-2007-1230 |
Multiple cross-site scripting (XSS) vulnerabilities in
wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote
attackers to inject arbitrary web script or HTML via (1) the Referer
HTTP header or (2) the URI, a different vulnerability than
CVE-2007-1049.
|
| CVE-2007-1229 |
Cross-site scripting (XSS) vulnerability in the Nullsoft
ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web
script or HTML via the top-level URI on the Incoming interface (port
8001/tcp), which is not properly handled in the administrator
interface when viewing the log file.
|
| CVE-2007-1198 |
Cross-site scripting (XSS) vulnerability in TaskFreak! before 0.5.7
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, possibly a variant of CVE-2007-0982.
|
| CVE-2007-1197 |
Multiple unspecified vulnerabilities in Epiware before 4.7.5 have
unknown impact and attack vectors, possibly related to cross-site
scripting (XSS) and other unspecified issues.
|
| CVE-2007-1177 |
WebAPP before 0.9.9.5 does not properly filter certain characters in
contexts related to (1) the query string, (2) Profiles, (3) the Forum
Post icon field, (4) the Edit Profile, and (5) the Gallery, which has
unknown impact and remote attack vectors, possibly related to
cross-site scripting (XSS).
|
| CVE-2007-1176 |
Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before
0.9.9.5 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to (1) Gallery Comments pages, (2)
Feedback pages, (3) Search Results pages, and (4) the Statistics Log
viewer.
|
| CVE-2007-1175 |
Cross-site scripting (XSS) vulnerability in an admin feature in WebAPP
before 20070209 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2007-1174 |
Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before
20070214 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors, related to unspecified fields in user
Profiles. NOTE: some of these details are obtained from third party
information.
|
| CVE-2007-1161 |
Cross-site scripting (XSS) vulnerability in call_entry.php in Call
Center Software 0,93 allows remote attackers to inject arbitrary web
script or HTML via the problem_desc parameter, as demonstrated by the
ONLOAD attribute of a BODY element.
|
| CVE-2007-1159 |
Cross-site scripting (XSS) vulnerability in modules/out.php in
Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web
script or HTML via the id parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-1151 |
Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote
attackers to inject arbitrary web script or HTML via the id parameter
to the top-level URI, possibly related to a SQL error.
|
| CVE-2007-1145 |
Multiple cross-site scripting (XSS) vulnerabilities in Kayako
SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors related to
a (1) lostpassword or (2) register action in index.php, (3)
unspecified vectors in the Submit form in a submit action in
index.php, and (4) the user's name in index.php; and (5) allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors related to the Admin and Staff Control Panel.
NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or
CVE-2005-0842.
|
| CVE-2007-1142 |
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2
allows remote attackers to inject arbitrary web script or HTML via the
link_parameters parameter in (1) news.php and (2) n_layouts.php.
|
| CVE-2007-1141 |
PHP remote file inclusion vulnerability in preview.php in Magic News
Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a
URL in the php_script_path parameter. NOTE: This issue may overlap
CVE-2006-0723.
|
| CVE-2007-1132 |
Multiple cross-site scripting (XSS) vulnerabilities in the "Contact
Us" functionality in MTCMS 2.2 allow remote attackers to inject
arbitrary web script or HTML via the (1) message and (2) title fields.
|
| CVE-2007-1125 |
Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer
Simple one-file gallery allows remote attackers to inject arbitrary
web script or HTML via the f parameter.
|
| CVE-2007-1115 |
The child frames in Opera 9 before 9.20 inherit the default charset
from the parent window when a charset is not specified in an HTTP
Content-Type header or META tag, which allows remote attackers to
conduct cross-site scripting (XSS) attacks, as demonstrated using the
UTF-7 character set.
|
| CVE-2007-1114 |
The child frames in Microsoft Internet Explorer 7 inherit the default
charset from the parent window when a charset is not specified in an
HTTP Content-Type header or META tag, which allows remote attackers to
conduct cross-site scripting (XSS) attacks, as demonstrated using the
UTF-7 character set.
|
| CVE-2007-1111 |
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar
1.2.0 allow remote attackers to inject arbitrary web script or HTML
via the css parameter to (1) flatevents.php, (2) js.php, (3)
mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7)
xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
|
| CVE-2007-1109 |
Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery
1.4.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) login or (2) mail_address field in Register.php, or the
(3) search_author, (4) mode, (5) start_year, (6) end_year, or (7)
date_type field in Search.php, a different vulnerability than
CVE-2006-1674. NOTE: 1.6.2 and other versions might also be affected.
|
| CVE-2007-1101 |
Multiple cross-site scripting (XSS) vulnerabilities in Photostand
1.2.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) message ("comment") or (2) name field, or the (3) q
parameter in a search action in index.php.
|
| CVE-2007-1096 |
Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart
before 20070116 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors. NOTE: this issue might overlap
CVE-2007-0376.
|
| CVE-2007-1085 |
Cross-site scripting (XSS) vulnerability in Google Desktop allows
remote attackers to bypass protection schemes and inject arbitrary web
script or HTML, and possibly gain full access to the system, by using
an XSS vulnerability in google.com to extract the signature for the
internal web server, then calling the "under" parameter in Advanced
Search with the proper signature.
|
| CVE-2007-1055 |
Cross-site scripting (XSS) vulnerability in the AJAX features in
index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
rs parameter. NOTE: this issue might be a duplicate of CVE-2007-0177.
|
| CVE-2007-1054 |
Cross-site scripting (XSS) vulnerability in the AJAX features in
index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is
enabled, allows remote attackers to inject arbitrary web script or
HTML via a UTF-7 encoded value of the rs parameter, which is processed
by Internet Explorer.
|
| CVE-2007-1050 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
AbleDesign MyCalendar allow remote attackers to inject arbitrary web
script or HTML via (1) the go parameter, (2) the keyword parameter in
the search menu (go=search), or (3) the username or (4) the password
in a go=Login action.
|
| CVE-2007-1049 |
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce
function in the nonce AYS functionality (wp-includes/functions.php)
for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote
attackers to inject arbitrary web script or HTML via the file
parameter to wp-admin/templates.php, and possibly other vectors
involving the action variable.
|
| CVE-2007-1028 |
Cross-site scripting (XSS) vulnerability in the Barry Jaspan Image
Pager 4.7.x-1.x-dev and 5.x-1.x-dev before 2007-02-08 module for
Drupal allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to HTML entities and the IMG element.
|
| CVE-2007-1020 |
Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31
allows remote attackers to inject arbitrary web script or HTML via the
hier parameter.
|
| CVE-2007-1012 |
Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0
allows remote attackers to inject arbitrary web script or HTML via the
article parameter.
|
| CVE-2007-0996 |
The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before
2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from
the parent window, which allows remote attackers to conduct cross-site
scripting (XSS) attacks, as demonstrated using the UTF-7 character
set.
|
| CVE-2007-0982 |
Cross-site scripting (XSS) vulnerability in error.php in TaskFreak!
0.5.5 allows remote attackers to inject arbitrary web script or HTML
via the tznMessage parameter. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2007-0973 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Jupiter CMS 1.1.5 allow remote attackers to inject arbitrary web
script or HTML via the Referer HTTP header and certain other HTTP
headers, which are displayed without proper sanitization when an
administrator performs a Logged Guest action.
|
| CVE-2007-0970 |
Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and
earlier allow remote attackers to execute arbitrary SQL commands via
the testID parameter to directions.php, and unspecified parameters to
other files that accept GET or POST input.
|
| CVE-2007-0969 |
Multiple cross-site scripting (XSS) vulnerabilities in WebTester
5.0.20060927 and earlier allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors related to POST parameters
to multiple files.
|
| CVE-2007-0953 |
Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61
and earlier allows remote attackers to inject arbitrary web script or
HTML via the keywords parameter.
|
| CVE-2007-0952 |
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net
Virtual Calendar allow remote attackers to inject arbitrary web script
or HTML via the (1) t and (2) yr parameters, and the (3) sho parameter
when the m parameter is outside the intended range.
|
| CVE-2007-0951 |
SQL injection vulnerability in listmain.asp in Fullaspsite ASP Hosting
Site allows remote attackers to execute arbitrary SQL commands via the
cat parameter.
|
| CVE-2007-0950 |
Cross-site scripting (XSS) vulnerability in listmain.asp in
Fullaspsite ASP Hosting Site allows remote attackers to inject
arbitrary web script or HTML via the cat parameter.
|
| CVE-2007-0939 |
Cross-site scripting (XSS) vulnerability in Microsoft Content
Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors
involving HTML redirection queries, aka "Cross-site Scripting and
Spoofing Vulnerability."
|
| CVE-2007-0925 |
Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx
in Community Server allows remote attackers to inject arbitrary web
script or HTML via the q parameter.
|
| CVE-2007-0923 |
buscador/buscador.htm in Portal Search allows remote attackers to
obtain sensitive information (business logic) via a query string
composed of a search for certain characters.
|
| CVE-2007-0922 |
Cross-site scripting (XSS) vulnerability in buscador/buscador.htm in
Portal Search allows remote attackers to inject arbitrary web script
or HTML via the query string.
|
| CVE-2007-0921 |
Portal Search allows remote attackers to redirect a URL to an
arbitrary web site by placing the URL in the query string to the
top-level URI.
|
| CVE-2007-0901 |
Multiple cross-site scripting (XSS) vulnerabilities in Info pages in
MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script
or HTML via the (1) hitcounts and (2) general parameters, different
vectors than CVE-2007-0857. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2007-0896 |
Cross-site scripting (XSS) vulnerability in the (1) Sage before
1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers
to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='"
sequence in an RSS feed, a different vulnerability than CVE-2006-4712.
|
| CVE-2007-0891 |
Cross-site scripting (XSS) vulnerability in the GetCurrentCompletePath
function in phpmyvisites.php in phpMyVisites before 2.2 allows remote
attackers to inject arbitrary web script or HTML via the query string.
|
| CVE-2007-0890 |
Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in
cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote
attackers to inject arbitrary web script or HTML via the password
parameter.
|
| CVE-2007-0885 |
Cross-site scripting (XSS) vulnerability in
jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen)
extension allows remote attackers to inject arbitrary web script or
HTML via the id parameter.
|
| CVE-2007-0876 |
Cross-site scripting (XSS) vulnerability in Quick Digital Image
Gallery (Qdig) 1.2.9.3 and devel-20060624 allows remote attackers to
inject arbitrary web script or HTML via the Qwd parameter to the
top-level URI.
|
| CVE-2007-0874 |
Allons_voter 1.0 allows remote attackers to bypass authentication and
access certain administrative functionality via a direct request for
(1) admin_ajouter.php or (2) admin_supprimer.php. NOTE: this could be
leveraged to conduct cross-site scripting (XSS) attacks.
|
| CVE-2007-0869 |
Cross-site scripting (XSS) vulnerability in the Attachment Manager
(admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote
attackers to inject arbitrary web script or HTML via the Extension
field. NOTE: this might be a duplicate of CVE-2007-0830.5. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2007-0857 |
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before
1.5.7 allow remote attackers to inject arbitrary web script or HTML
via (1) the page info, or the page name in a (2) AttachFile, (3)
RenamePage, or (4) LocalSiteMap action.
|
| CVE-2007-0852 |
Cross-site scripting (XSS) vulnerability in DevTrack 6.x allows remote
attackers to inject arbitrary web script or HTML via the "Keyword
search" form field and unspecified other form fields that populate a
public saved query. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-0846 |
Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia
Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to
inject arbitrary HTML or web script via the name parameter.
|
| CVE-2007-0840 |
Cross-site scripting (XSS) vulnerability in HLstats before 1.35 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors in the search class. NOTE: it is possible that
this issue overlaps CVE-2006-4543.3 or CVE-2006-4454.
|
| CVE-2007-0834 |
Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 allows
remote attackers to inject arbitrary web script or HTML via the user
name field when the user joins a chat room, a different vulnerability
than CVE-2007-0807. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2007-0830 |
** DISPUTED **
Multiple cross-site scripting (XSS) vulnerabilities in the Admin
Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote
authenticated administrators to inject arbitrary web script or HTML
via unspecified vectors related to the (1) User Group Manager, (2)
User Rank Manager, (3) User Title Manager, (4) BB Code Manager, (5)
Attachment Manager, (6) Calendar Manager, and (7) Forums & Moderators
functions. NOTE: the vendor disputes this issue, stating that
modifying HTML is an intended privilege of an administrator. NOTE: it
is possible that this issue overlaps CVE-2006-6040.
|
| CVE-2007-0817 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web
server allows remote attackers to inject arbitrary HTML or web script
via the User-Agent HTTP header, which is not sanitized before being
displayed in an error page.
|
| CVE-2007-0815 |
Cross-site scripting (XSS) vulnerability in images_archive.asp in
Uapplication Uphotogallery 1.1 allows remote authenticated
administrators to inject arbitrary web script or HTML via the s
parameter. NOTE: the thumbnails.asp vector is already covered by
CVE-2006-3023.
|
| CVE-2007-0814 |
Multiple cross-site scripting (XSS) vulnerabilities in Adrenalin's ASP
Chat allow remote attackers to inject arbitrary web script or HTML (1)
via the psuedo (pseudo) field or (2) during chat.
|
| CVE-2007-0813 |
Cross-site scripting (XSS) vulnerability in Home production
MySearchEngine allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2007-0807 |
Cross-site scripting (XSS) vulnerability in info.php in flashChat
4.7.8 allows remote attackers to inject arbitrary web script or HTML
via a channel title (aka room name) that is not properly handled by
the "who's online" feature.
|
| CVE-2007-0798 |
Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload
1.0.5 allow remote attackers to inject arbitrary web script or HTML
via unspecified parameters to (1) login.asp; and allow remote
authenticated users to inject arbitrary web script or HTML via
unspecified parameters to (2) badword.asp, (3) polls.asp, and (4)
users.asp.
|
| CVE-2007-0791 |
Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla
2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1,
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-0788 |
Cross-site scripting (XSS) vulnerability in MediaWiki 1.9.x before
1.9.2 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to "sortable tables JavaScript."
|
| CVE-2007-0780 |
browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before
2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to
identify child windows, which allows remote attackers to conduct
cross-site scripting (XSS) attacks by opening a blocked popup
originating from a javascript: URI in combination with multiple frames
having the same data: URI.
|
| CVE-2007-0769 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in register.php in Phorum
5.1.18 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors. NOTE: the vendor disputes this
vulnerability, stating that "The characters are escaped properly."
|
| CVE-2007-0768 |
Multiple cross-site scripting (XSS) vulnerabilities in the Contact
Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow
user-assisted remote attackers to inject arbitrary web script or HTML
via a javascript: URI in the SRC attribute of an IMG element to the
(1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of
these details are obtained from third party information.
|
| CVE-2007-0767 |
Cross-site scripting (XSS) vulnerability in the core in Phorum before
5.1.18 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2007-0763 |
Cross-site scripting (XSS) vulnerability in the news comment
functionality in F3Site 2.1 and earlier allows remote attackers to
inject arbitrary web script or HTML via the Autor field.
|
| CVE-2007-0696 |
Cross-site scripting (XSS) vulnerability in error messages in Free LAN
In(tra|ter)net Portal (FLIP) before 1.0-RC3 allows remote attackers to
inject arbitrary web script or HTML via unspecified parameters,
different vectors than CVE-2007-0611.
|
| CVE-2007-0694 |
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1
allows remote attackers to inject arbitrary web script or HTML via the
copyright parameter.
|
| CVE-2007-0693 |
SQL injection vulnerability in news.php in DGNews 2.1 allows remote
attackers to execute arbitrary SQL commands via the catid parameter in
a newslist action. NOTE: this issue can produce resultant cross-site
scripting (XSS).
|
| CVE-2007-0660 |
Cross-site scripting (XSS) vulnerability in the IFrame module before
03.02.01 for DotNetNuke (DNN) allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors related to "Pass
through values."
|
| CVE-2007-0651 |
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable
Professional before 2.37 allow remote attackers to inject arbitrary
Javascript script via (1) e-mail messages and (2) the ID parameter to (a)
right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in
mewebmail/base/default/lang/EN/.
|
| CVE-2007-0649 |
Variable overwrite vulnerability in interface/globals.php in OpenEMR
2.8.2 and earlier allows remote attackers to overwrite arbitrary
program variables and conduct other unauthorized activities, such as
conduct (a) remote file inclusion attacks via the srcdir parameter in
custom/import_xml.php or (b) cross-site scripting (XSS) attacks via
the rootdir parameter in interface/login/login_frame.php, via vectors
associated with extract operations on the (1) POST and (2) GET
superglobal arrays. NOTE: this issue was originally disputed before
the extract behavior was identified in post-disclosure analysis.
Also, the original report identified "Open Conference Systems," but
this was an error.
|
| CVE-2007-0628 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System
Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before
20070129 allow remote attackers to inject arbitrary web script or HTML
via the (1) goto or (2) gx-charset parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2007-0611 |
Multiple cross-site scripting (XSS) vulnerabilities in Free LAN
In(tra|ter)net Portal (FLIP) before 1.0-RC2 allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors in (1)
inc.page.php and (2) inc.text.php.
|
| CVE-2007-0610 |
Cross-site scripting (XSS) vulnerability in the mailform feature in
CMSimple 2.7 fix1 allows remote attackers to inject arbitrary web
script or HTML via the sender parameter. NOTE: The provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-0609 |
Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows
remote attackers to bypass .htaccess settings, and execute arbitrary
PHP local files or read arbitrary local templates, via a .. (dot dot)
in a lang cookie, followed by a filename without its .php extension,
as demonstrated via a request to index.php.
|
| CVE-2007-0605 |
Cross-site scripting (XSS) vulnerability in picture.php in Advanced
Guestbook 2.4.2 allows remote attackers to inject arbitrary web script
or HTML via the picture parameter.
|
| CVE-2007-0604 |
Cross-site scripting (XSS) vulnerability in Movable Type (MT) before
3.34 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to the MTCommentPreviewIsStatic tag,
which can open the "comment entry screen," a different vulnerability
than CVE-2007-0231.
|
| CVE-2007-0595 |
Cross-site scripting (XSS) vulnerability in search in High 5 Review
Site allows remote attackers to inject arbitrary web script or HTML
via the q parameter (aka the search box).
|
| CVE-2007-0592 |
Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to admin/login.php and the Admin Panel
Database.
|
| CVE-2007-0590 |
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre
1.0 remote attackers to inject arbitrary web script or HTML via the
palavra parameter.
|
| CVE-2007-0583 |
Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander
6.0, and possibly earlier, allow remote attackers to inject arbitrary
web script or HTML via the (1) LogoffMessage parameter to
logofflast.aspx or the (2) txtUsername parameter to Default.aspx.
NOTE: The provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2007-0567 |
Cross-site scripting (XSS) vulnerability in admin.php in
Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote
attackers to inject arbitrary web script or HTML via the _p parameter.
|
| CVE-2007-0563 |
Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web
Security (SWS) before 3.0.1.85 allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors related to (1)
error messages and (2) blocked page messages produced by SWS.
|
| CVE-2007-0553 |
Multiple cross-site scripting (XSS) vulnerabilities in index.inc.php
in PHProxy before 0.5 beta 2 allow remote attackers to inject
arbitrary web script or HTML via the (1) data[realm] and (2) _url
parameters, different vectors than CVE-2004-2604. NOTE: some of these
details are obtained from third party information.
|
| CVE-2007-0552 |
Cross-site scripting (XSS) vulnerability in
install/default/error404.html in Oh no! Not another CMS (Onnac)
0.0.8.4 and earlier allows remote attackers to inject arbitrary web
script or HTML via the error_url parameter.
|
| CVE-2007-0550 |
Cross-site scripting (XSS) vulnerability in search.php in 212cafeBoard
0.08 Beta allows remote attackers to inject arbitrary web script or
HTML via keyword parameter.
|
| CVE-2007-0549 |
Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard
6.30 Beta allows remote attackers to inject arbitrary web script or
HTML via the user parameter.
|
| CVE-2007-0547 |
Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2007-0544 |
Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka
MyBulletinBoard) allows remote authenticated users to inject arbitrary
web script or HTML via the Subject field, a different vector than
CVE-2006-2949.
|
| CVE-2007-0542 |
Cross-site scripting (XSS) vulnerability in show.php in 212cafe
Guestbook 4.00 beta allows remote attackers to inject arbitrary web
script or HTML via the user parameter.
|
| CVE-2007-0537 |
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not
properly parse HTML comments, which allows remote attackers to conduct
cross-site scripting (XSS) attacks and bypass some XSS protection
schemes by embedding certain HTML tags within a comment in a title
tag, a related issue to CVE-2007-0478.
|
| CVE-2007-0534 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project
issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0
through 5.x before 20070123 modules for Drupal allow remote
authenticated users to inject arbitrary web script or HTML via (a)
certain "fields on project nodes" or (b) "certain project-specific
settings regarding issue tracking."
|
| CVE-2007-0529 |
Cross-site scripting (XSS) vulnerability in index.html (aka the
administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
crafted link, which is triggered when the administrator uses the
"Validate Links" functionality.
|
| CVE-2007-0526 |
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.3.1
allow remote attackers to inject arbitrary web script or HTML via the
URL (PATH_INFO) to (1) articles/edit.php, (2) articles/list.php, (3)
blogs/list_blogs.php, or (4) blogs/rankings.php.
|
| CVE-2007-0519 |
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U
Instant Messenger allows remote authenticated users to inject
arbitrary web script or HTML via the recipient field.
|
| CVE-2007-0514 |
Multiple cross-site scripting (XSS) vulnerabilities in multiple
Hitachi Web Server, uCosminexus, and Cosminexus products before
20070124 allow remote attackers to inject arbitrary web script or HTML
via (1) HTTP Expect headers or (2) image maps.
|
| CVE-2007-0509 |
Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have
unknown impact and attack vectors, possibly relating to cross-site
scripting (XSS) in the slogan parameter in main.tpl, or information
leaks in error messages.
|
| CVE-2007-0483 |
Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1
allow remote attackers to inject arbitrary web script or HTML via the
URI for (1) show_owned.php or (2) show_joined.php. NOTE: The
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2007-0478 |
WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does
not properly parse HTML comments in TITLE elements, which allows
remote attackers to conduct cross-site scripting (XSS) attacks and
bypass some XSS protection schemes by embedding certain HTML tags
within an HTML comment.
|
| CVE-2007-0477 |
Cross-site scripting (XSS) vulnerability in Openads 2.0.x before
2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before
0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 allows
remote attackers to inject arbitrary web script or HTML via (1) the
keyword parameter in admin-search.php and (2) affiliate-search.php.
NOTE: this issue may overlap CVE-2007-0363.
|
| CVE-2007-0437 |
Multiple cross-site scripting (XSS) vulnerabilities in the sample
Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote
attackers to inject arbitrary web script or HTML via (1) the TO
parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3)
the PAGE parameter to showsource.csp in csp/samples/; and allow remote
authenticated users to inject arbitrary web script or HTML via (4) the
ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified
vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.
|
| CVE-2007-0407 |
Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain
Black WebGUI before 7.3.5 (beta) allows remote attackers to inject
arbitrary web script or HTML via the username parameter during
anonymous registration, a different vector than CVE-2007-0308. NOTE:
it is possible that a separate "WikiPage titles" issue was also fixed.
|
| CVE-2007-0402 |
Cross-site scripting (XSS) vulnerability in admin/edit_member.php in
Easebay Resources Paypal Subscription Manager allows remote attackers
to inject arbitrary web script or HTML via the username parameter.
|
| CVE-2007-0400 |
Cross-site scripting (XSS) vulnerability in admin/memberlist.php in
Easebay Resources Login Manager 3.0 allows remote attackers to inject
arbitrary web script or HTML via the keyword parameter.
|
| CVE-2007-0399 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users
to inject arbitrary web script or HTML via the (1) recipient or (2)
BCC field when selecting send in a pm action.
|
| CVE-2007-0398 |
Multiple cross-site scripting (XSS) vulnerabilities in forum.php3 in
Arnaud Guyonne (aka Arnotic) a-forum allow remote attackers to inject
arbitrary web script or HTML via the (1) Sujet or (2) Pseudo field.
|
| CVE-2007-0390 |
Cross-site scripting (XSS) vulnerability in index.php in sabros.us 1.7
allows remote attackers to inject arbitrary web script or HTML via the
tag parameter.
|
| CVE-2007-0384 |
Cross-site scripting (XSS) vulnerability in preview in the reviews
section in PostNuke 0.764 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2007-0379 |
Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-0376 |
Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2007-0365 |
Multiple cross-site scripting (XSS) vulnerabilities in All In One
Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to
inject arbitrary web script or HTML via unspecified vectors. NOTE:
this is probably a different vulnerability than CVE-2006-5830.
|
| CVE-2007-0364 |
Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com
INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) error_msg parameter to (a)
suggest_category.php; the (2) u parameter to (b) user_detail.php; the
(3) friend_name, (4) friend_email, (5) error_msg, (6) my_name, (7)
my_email, and (8) id parameters to (c) tell_friend.php; the (9)
error_msg, (10) email, (11) name, and (12) subject parameters to (d)
sendmail.php; the (13) email, (14) error_msg, and (15) username
parameters to (e) send_pwd.php; the (16) keyword parameter to (f)
search.php; the (17) error_msg, (18) username, (19) password, (20)
password2, and (21) email parameters to (g) register.php; the (22)
url, (23) contact_name, and (24) email parameters to (h)
power_search.php; the (25) path and (26) total parameters to (i)
new.php; the (27) query parameter to (j) modify.php; the (28)
error_msg parameter to (k) login.php; the (29) error_msg and (30)
email parameters to (l) mailing_list.php; the (31) gateway parameter
to (m) upgrade.php; and another unspecified vector.
|
| CVE-2007-0363 |
Cross-site scripting (XSS) vulnerability in admin-search.php in (1)
Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads
(aka phpAdsNew) before 2.0.10 allows remote attackers to inject
arbitrary web script or HTML via unspecified parameters.
|
| CVE-2007-0362 |
Cross-site scripting (XSS) vulnerability in the RSS feed component in
FreshReader before 1.0.07010600 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, possibly related
to tag attributes.
|
| CVE-2007-0353 |
Cross-site scripting (XSS) vulnerability in (1) index.php and (2)
login.php in myBloggie 2.1.5 allows remote attackers to inject
arbitrary web script or HTML via the PATH_INFO string.
|
| CVE-2007-0341 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and
earlier, when Microsoft Internet Explorer 6 is used, allows remote
attackers to inject arbitrary web script or HTML via a javascript: URI
in a CSS style in the convcharset parameter to the top-level URI, a
different vulnerability than CVE-2005-0992.
|
| CVE-2007-0332 |
(1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques
2.1 do not require authentication, which allows remote attackers to
perform unauthorized administrative actions using a direct request.
|
| CVE-2007-0331 |
Cross-site scripting (XSS) vulnerability in liens.php3 in
liens_dynamiques 2.1 allows remote attackers to inject arbitrary web
script or HTML by using the ajouter=1 query string and the add menu.
|
| CVE-2007-0308 |
Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before
7.3.4 (beta) allows remote attackers to inject arbitrary web script or
HTML via Wiki Page titles.
|
| CVE-2007-0302 |
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP
4.1.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) SessionID parameter to (a) Logon.aspx, and the (2)
Username and (3) Update parameters to (b) Members1.aspx.
|
| CVE-2007-0275 |
Cross-site scripting (XSS) vulnerability in Oracle Reports Web
Cartridge (RWCGI60) in the Workflow Cartridge component, as used in
Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server
9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and
Oracle E-Business Suite and Applications 11.5.10CU2; allows remote
authenticated users to inject arbitrary HTML or web script via the
genuser parameter to rwcgi60, aka OWF01.
|
| CVE-2007-0273 |
Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8,
10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related
to XMLDB, aka DB06. NOTE: as of 20070123, Oracle has not disputed
claims by a reliable researcher that DB06 is for multiple cross-site
scripting (XSS) vulnerabilities.
|
| CVE-2007-0265 |
Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal
System Beta 0.7.6 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) the pic parameter to
custom/piczoom.asp, (2) the nocatname parameter to
boxx/user-upload.asp, or (3) the iid parameter to
indexes/newscomments.asp.
|
| CVE-2007-0258 |
Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo
2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to
inject arbitrary web script or HTML via the p parameter. NOTE: some of
these details are obtained from third party information.
|
| CVE-2007-0249 |
Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites
3.0 allows remote attackers to inject arbitrary web script or HTML via
the o parameter.
|
| CVE-2007-0242 |
The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does
not reject long UTF-8 sequences as required by the standard, which
allows remote attackers to conduct cross-site scripting (XSS) and
directory traversal attacks via long sequences that decode to
dangerous metacharacters.
|
| CVE-2007-0240 |
Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors in a HTTP GET request.
|
| CVE-2007-0231 |
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33,
when nofollow is disabled and unmoderated comments are enabled, allows
remote attackers to inject arbitrary web script or HTML via the
Comments field.
|
| CVE-2007-0225 |
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in
VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to
inject arbitrary web script or HTML via the msg parameter.
|
| CVE-2007-0220 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)
in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows
remote attackers to execute arbitrary scripts, spoof content, or
obtain sensitive information via certain UTF-encoded, script-based
e-mail attachments, involving an "incorrectly handled UTF character
set label".
|
| CVE-2007-0204 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
before 2.9.2-rc1 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors. NOTE: some of these details are
obtained from third party information.
|
| CVE-2007-0191 |
Cross-site scripting (XSS) vulnerability in admin.php in MKPortal
allows remote attackers to inject arbitrary web script or HTML via two
certain fields in a contents_new operation in the ad_contents section.
|
| CVE-2007-0186 |
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL
VPN allow remote attackers to inject arbitrary web script or HTML via
(1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue,
(4) wtopblue, and certain other Custom color parameters in a per
action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312,
and certain other Front Door custom text color parameters in a per
action to vdesk/admincon/index.php; the (8) ua parameter in a bro
action to vdesk/admincon/index.php; the (9) app_param and (10)
app_name parameters to webyfiers.php; (11) double eval functions; (12)
JavaScript contained in an <FP_DO_NOT_TOUCH> element; and (13) the
vhost parameter to my.activation.php. NOTE: it is possible that this
candidate overlaps CVE-2006-3550.
|
| CVE-2007-0183 |
Cross-site scripting (XSS) vulnerability in /search in iPlanet Web
Server 4.x allows remote attackers to inject arbitrary web script or
HTML via the NS-max-records parameter. NOTE: The provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2007-0177 |
Cross-site scripting (XSS) vulnerability in the AJAX module in
MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9
before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-0176 |
Cross-site scripting (XSS) vulnerability in search/advanced_search.php
in GForge 4.5.11 allows remote attackers to inject arbitrary web
script or HTML via the words parameter.
|
| CVE-2007-0175 |
Cross-site scripting (XSS) vulnerability in htsrv/login.php in
b2evolution 1.8.6 allows remote attackers to inject arbitrary web
script or HTML via scriptable attributes in the redirect_to parameter.
|
| CVE-2007-0146 |
Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips
CMS 1.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) id parameter in (a) delete-announce.php; the (2)
Announcement form field in (b) staff.php; the (3) Client Name, (4)
Business Name, (5) Street, (6) Address 2, (7) Town/City, (8) Postcode,
(9) Phone Number, (10) Email Address and (11) Website Address form
fields in (c) new_customer.php; and unspecified fields in (d)
search.php and (e) client-results.php.
|
| CVE-2007-0144 |
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing
Quote And Ordering System 1.0 allows remote authenticated attackers to
inject arbitrary web script or HTML via the ordernum parameter.
|
| CVE-2007-0141 |
Cross-site scripting (XSS) vulnerability in yald.php in Yet Another
Link Directory 1.0 allows remote attackers to inject arbitrary web
script or HTML via the search parameter.
|
| CVE-2007-0137 |
Cross-site scripting (XSS) vulnerability in SimpleBoxes/SerendipityNZ
Serene Bach 2.05R and earlier, and 2.08D and earlier in the 2.08
series; and (2) sb 1.13D and earlier, and 1.18R and earlier in the
1.18 series; allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2007-0136 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal before
4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters in the (1)
filter and (2) system modules. NOTE: some of these details are
obtained from third party information.
|
| CVE-2007-0121 |
Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3
allows remote attackers to inject arbitrary web script or HTML via the
q parameter.
|
| CVE-2007-0119 |
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2
allow remote attackers to inject arbitrary web script or HTML via the
plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.
|
| CVE-2007-0110 |
Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell
Access Manager Identity Server before 3.0.0-1013 allows remote
attackers to inject arbitrary web script or HTML via the IssueInstant
parameter, which is not properly handled in the resulting error
message.
|
| CVE-2007-0106 |
Cross-site scripting (XSS) vulnerability in the CSRF protection scheme
in WordPress before 2.0.6 allows remote attackers to inject arbitrary
web script or HTML via a CSRF attack with an invalid token and quote
characters or HTML tags in URL variable names, which are not properly
handled when WordPress generates a new link to verify the request.
|
| CVE-2007-0083 |
Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
javascript: URI in a getURL statement in a .swf file, as demonstrated
by "Remote Cookie Disclosure." NOTE: it could be argued that this is
an issue in Shockwave instead of Nuked Klan.
|
| CVE-2007-0056 |
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe
4.5 and AShop Administration Panel allow remote attackers to inject
arbitrary web script or HTML via the (1) cat parameter to (a)
ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to
ashop/catalogue.php, the (3) searchstring parameter to (c)
ashop/search.php, the (4) checkout and (5) action parameters to (d)
ashop/shipping.php, the cat parameter to (f)
cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to
(g) cart-path/admin/salesadmin.php.
|
| CVE-2007-0054 |
Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior
Foundry vCard PRO allows remote attackers to inject arbitrary web
script or HTML via the sortby parameter.
|
| CVE-2007-0045 |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat
Reader Plugin before 8.0.0, and possibly the plugin distributed with
Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2,
for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome,
Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote
attackers to inject arbitrary JavaScript and conduct other attacks via
a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and
(3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor
identifier, aka "Universal XSS (UXSS)."
|
| CVE-2006-7238 |
Cross-site scripting (XSS) vulnerability in MyShoutPro before 1.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-7233 |
Cross-site scripting (XSS) vulnerability in the login form (login.jsp)
of the admin console in Openfire (formerly Wildfire) 2.6.0, and
possibly other versions before 3.5.3, allows remote attackers to
inject arbitrary web script or HTML via the url parameter.
|
| CVE-2006-7209 |
Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA
before 1.2beta2 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors related to keywords results in the (1)
main, (2) daily, (3) weekly, (4) monthly, (5) new trends, (6)
individual page, and (7) search engine statistics.
|
| CVE-2006-7196 |
Cross-site scripting (XSS) vulnerability in the calendar application
example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31,
5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers
to inject arbitrary web script or HTML via the time parameter to
cal2.jsp and possibly unspecified other vectors. NOTE: this may be
related to CVE-2006-0254.1.
|
| CVE-2006-7195 |
Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in
Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows
remote attackers to inject arbitrary web script or HTML via certain
header values.
|
| CVE-2006-7192 |
Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle
comment (/* */) enclosures, which allows remote attackers to bypass
request filtering and conduct cross-site scripting (XSS) attacks, or
cause a denial of service, as demonstrated via an xss:expression STYLE
attribute in a closing XSS HTML tag.
|
| CVE-2006-7190 |
Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl
in web-app.net WebAPP before 20060515 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors in the
viewnews function, related to use of doubbctopic instead of doubbc.
|
| CVE-2006-7189 |
Cross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in
web-app.net WebAPP before 20060403 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors related to the
Statistics Log Viewer.
|
| CVE-2006-7187 |
Cross-site scripting (XSS) vulnerability in the show_recent_searches
function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before
20060909 allows remote attackers to inject arbitrary web script or
HTML via the srch variable.
|
| CVE-2006-7158 |
Cross-site scripting (XSS) vulnerability in Oracle Application Express
(APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to
inject arbitrary web script or HTML via the NOTIFICATION_MSG
parameter. NOTE: it is likely that this issue overlaps one of the
identifiers in CVE-2006-5351.
|
| CVE-2006-7149 |
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x
allow remote attackers to inject arbitrary web script or HTML via (1)
the query string to (a) index.php, which reflects the string in an
error message from mod_login.php; and the (2) mcname parameter to (b)
moscomment.php and (c) com_comment.php.
|
| CVE-2006-7143 |
Cross-site scripting (XSS) vulnerability in Call Center Software 0.93
and earlier allows remote attackers to inject arbitrary web script or
HTML via the problem description field.
|
| CVE-2006-7137 |
Cross-site scripting (XSS) vulnerability in TinyPortal before 0.8.6
allows remote attackers to inject arbitrary web script or HTML via the
shoutbox.
|
| CVE-2006-7125 |
Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0
and 2.2.1 allows remote attackers to inject arbitrary web script or
HTML via the HTTP Referer header, which is not properly handled when
the administrator views site statistics.
|
| CVE-2006-7122 |
Cross-site scripting (XSS) vulnerability in the IP Address Lookup
functionality in BSQ Sitestats (component for Joomla) 1.8.0, and
possibly other versions before 2.2.1, allows remote attackers to
inject arbitrary web script and HTML via the ip parameter.
|
| CVE-2006-7093 |
Cross-site scripting (XSS) vulnerability in Mambo LaiThai 4.5.4
Security Patch 2 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-7085 |
Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers
to add arbitrary content and conduct XSS attacks via a direct request
to add_art.php. NOTE: this issue was originally reported as SQL
injection, but this is not likely.
|
| CVE-2006-7078 |
Multiple cross-site scripting (XSS) vulnerabilities in Professional
Home Page Tools Login Script, as of July 2006, allow remote attackers
to inject arbitrary web script or HTML via the (1) name, (2) vorname,
and (3) nachname parameters in the register script. NOTE: some details
have been obtained from third party sources.
|
| CVE-2006-7077 |
SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4
for phpBB allows remote attackers to execute arbitrary SQl commands
via the entry parameter.
|
| CVE-2006-7076 |
Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced
Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary
web script or HTML via the entry parameter. NOTE: this issue might be
resultant from SQL injection.
|
| CVE-2006-7073 |
Cross-site scripting (XSS) vulnerability in Opentools Attachment Mod
before 2.4.5 allows remote attackers to inject arbitrary web script or
HTML in Internet Explorer via unknown vectors related to the uploaded
attachments form. NOTE: some details were obtained from third party
information.
|
| CVE-2006-7072 |
Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise
2.0.5.2 and earlier allows remote attackers to inject arbitrary web
script and HTML via the (1) b[username] and (2) c parameters to (a)
index.php, the b[username] parameter to (b) admin/index.php, and (3)
c[phone] parameter to register.php.
|
| CVE-2006-7064 |
Cross-site scripting (XSS) vulnerability in forum/admin.php for
Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers
to inject arbitrary web script or HTML as the administrator via the
phpinfo parameter.
|
| CVE-2006-7061 |
Scriptsez.net E-Dating System stores data files with predictable names
under the web document root with insufficient access control, which
allows remote attackers to read private messages and leverage them for
cross-site scripting (XSS) attacks.
|
| CVE-2006-7060 |
cindex.php in Scriptsez.net E-Dating System allows remote attackers to
obtain the full path via an invalid id parameter in a dologin action,
which leaks the path in an error message.
|
| CVE-2006-7059 |
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net
E-Dating System allow remote attackers to inject arbitrary web script
or HTML via encoded entities (') in IMG tags to (1) messages,
(2) profile fields, or (3) the id parameter in a dologin operation to
cindex.php.
|
| CVE-2006-7058 |
Multiple cross-site scripting (XSS) vulnerabilities in Sphider before
1.3.1c allow remote attackers to inject arbitrary web script or HTML
via the catid parameter to (1) templates/standard/search_form.html and
(2) templates/dark/search_form.html. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-7050 |
Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki)
before 1.1.6.2 allows remote attackers to inject arbitrary javascript
via (1) events in forced links (url parameter) that are not properly
handled in formatters/wakka.php, and possibly (2) other vectors in
wikka.php.
|
| CVE-2006-7043 |
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk
Blogger allow remote authenticated users to inject arbitrary web
script or HTML via script tags in (1) posts and (2) profile names; and
(3) a javascript URI in a URL argument in the photo gallery.
|
| CVE-2006-7042 |
Cross-site scripting (XSS) vulnerability in directory/index.php in
Chipmunk directory allows remote attackers to inject arbitrary web
script or HTML via the start parameter.
|
| CVE-2006-7033 |
Cross-site scripting (XSS) vulnerability in Super Link Exchange Script
1.0 allows remote attackers to inject arbitrary web script or HTML via
IMG tags in the search box.
|
| CVE-2006-7023 |
Multiple cross-site scripting (XSS) vulnerabilities in fx-APP 0.0.8.1
allow remote attackers to inject arbitrary HTML or web script via (1)
the search box, and the (2) url, (3) website, (4) comment, and (5)
signature fields in the profile, and possibly (6) a menu item.
|
| CVE-2006-7004 |
Cross-site scripting (XSS) vulnerability in email_request.php in PSY
Auction allows remote attackers to inject arbitrary web script or HTML
via the user_id parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-7002 |
Cross-site scripting (XSS) vulnerability in add_comment.php in
Wheatblog (wB) 1.1 allows remote attackers to inject arbitrary web
script or HTML via the Email field. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information. NOTE: this issue may overlap CVE-2006-5195.
|
| CVE-2006-6996 |
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS
1.0 allow remote attackers to inject arbitrary HTML and web script via
the (1) title and (2) newspost parameters to (a) newsadd.php, and the
(3) name, title, and (4) comment parameters to (b) news.php, a
different set of vectors than CVE-2006-1818. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-6995 |
mycontacts.php in V3 Chat allows remote authenticated users to gain
privileges as other users via a modified membername parameter.
|
| CVE-2006-6978 |
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar
Selection" in FCKEditor allows remote attackers to execute arbitrary
JavaScript via the javascript: URI in the (1) href or (2) onmouseover
attribute of the A HTML tag.
|
| CVE-2006-6977 |
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar
Selection" in FreeTextBox allows remote attackers to execute arbitrary
JavaScript via the javascript: URI in the (1) href or (2) onmouseover
attribute of the A HTML tag.
|
| CVE-2006-6968 |
Cross-site scripting (XSS) vulnerability in the group moderation
control center page in Phorum before 5.1.19 might allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2006-6965 |
CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki
2006-03-09e, and possibly earlier, allows remote attackers to inject
arbitrary HTTP headers and conduct HTTP response splitting attacks via
CRLF sequences in the media parameter. NOTE: this issue can be
leveraged for XSS attacks.
|
| CVE-2006-6951 |
Cross-site scripting (XSS) vulnerability in blog.php in OdysseusBlog
allows remote attackers to inject arbitrary web script or HTML via the
page parameter.
|
| CVE-2006-6942 |
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin
before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web
script via (1) a comment for a table name, as exploited through (a)
db_operations.php, (2) the db parameter to (b) db_create.php, (3) the
newname parameter to db_operations.php, the (4) query_history_latest,
(5) query_history_latest_db, and (6) querydisplay_tab parameters to
(c) querywindow.php, and (7) the pos parameter to (d) sql.php.
|
| CVE-2006-6936 |
Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery
allows remote attackers to inject arbitrary HTML or web script via (1)
the catname parameter to displaypic.asp or (2) the search field.
NOTE: vector 1 likely overlaps CVE-2006-3032.
|
| CVE-2006-6935 |
SQL injection vulnerability in the login component in Portix-PHP 0.4.2
allows remote attackers to execute arbitrary SQL commands via the
username and passwd (password) fields.
|
| CVE-2006-6934 |
Multiple cross-site scripting (XSS) vulnerabilities in Portix-PHP
0.4.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) titre or (2) auteur field in a forum post.
|
| CVE-2006-6930 |
SQL injection vulnerability in viewad.asp in Rapid Classified 3.1
allows remote attackers to execute arbitrary SQL commands via the id
parameter.
|
| CVE-2006-6929 |
Multiple cross-site scripting (XSS) vulnerabilities in Rapid
Classified 3.1 allow remote attackers to inject arbitrary web script
or HTML via the (1) id parameter to (a) reply.asp or (b)
view_print.asp, the (2) SH1 parameter to (c) search.asp, the (3) name
parameter to reply.asp, or the (4) dosearch parameter to (d)
advsearch.asp.
|
| CVE-2006-6928 |
Multiple cross-site scripting (XSS) vulnerabilities in Rialto 1.6
allow remote attackers to inject arbitrary web script or HTML via the
(1) cat parameter to (a) listmain.asp or (b) searchmain.asp, the (2)
the Keyword parameter to (c) searchkey.asp, or the (3) refno parameter
to (d) forminfo.asp.
|
| CVE-2006-6925 |
Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the message title field when submitting an article to
articles/edit.php, (2) the message title field when submitting a blog
post to blogs/post.php, or (3) the message description field when
editing in the Sandbox in wiki/edit.php.
|
| CVE-2006-6924 |
bitweaver 1.3.1 and earlier allows remote attackers to obtain
sensitive information via a sort_mode=-98 query string to (1)
blogs/list_blogs.php, (2) fisheye/index.php, (3)
wiki/orphan_pages.php, or (4) wiki/list_pages.php, which forces a SQL
error. NOTE: the fisheye/list_galleries.php vector is already covered
by CVE-2005-4380.
|
| CVE-2006-6923 |
SQL injection vulnerability in newsletters/edition.php in bitweaver
1.3.1 and earlier allows remote attackers to execute arbitrary SQL
commands via the tk parameter.
|
| CVE-2006-6920 |
Cross-site scripting (XSS) vulnerability in Nucleus before 3.24 allows
remote attackers to inject arbitrary web script or HTML via unknown
vectors, possibly involving (1) lib/ADMIN.php and (2) lib/SKIN.php.
|
| CVE-2006-6892 |
Cross-site scripting (XSS) vulnerability in the GetLocation function
in online.php in Jonathon J. Freeman OvBB 0.13a allows remote
attackers to inject arbitrary web script or HTML via the aRequest
variable.
|
| CVE-2006-6882 |
Cross-site scripting (XSS) vulnerability in golden book allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2006-6874 |
Multiple cross-site scripting (XSS) vulnerabilities in friend.php in
eNdonesia 8.4 allow remote attackers to inject arbitrary web script or
HTML via the (1) Message or (2) Your Name field. NOTE: The provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-6871 |
Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4
allow remote attackers to inject arbitrary web script or HTML via (1)
the mod parameter in a viewlink operation in mod.php, (2) the intypeid
parameter in a showinfo operation in the informasi module in mod.php,
(3) the "your Friend" field in friend.php, or (4) the "Main Text"
field in admin.php.
|
| CVE-2006-6868 |
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web
Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2006-6862 |
Multiple cross-site scripting (XSS) vulnerabilities in Outfront Spooky
Login 2.7 allow remote attackers to inject arbitrary web script or
HTML via unspecified parameters to (1) login/login.asp or (2)
login/register.asp.
|
| CVE-2006-6857 |
Cross-site scripting (XSS) vulnerability in
modules/credits/credits.php in Docebo LMS allows remote attackers to
inject arbitrary web script or HTML via the lang parameter.
|
| CVE-2006-6851 |
Multiple cross-site scripting (XSS) vulnerabilities in contact_us.php
in ac4p Mobilelib gold 2 allow remote attackers to inject arbitrary
web script or HTML via the (1) email or (2) errr parameter.
|
| CVE-2006-6845 |
Cross-site scripting (XSS) vulnerability in index.php in CMS Made
Simple 1.0.2 allows remote attackers to inject arbitrary web script or
HTML via the cntnt01searchinput parameter in a Search action.
|
| CVE-2006-6844 |
Cross-site scripting (XSS) vulnerability in the optional user comment
module in CMS Made Simple 1.0.2 allows remote attackers to inject
arbitrary web script or HTML via the user comment form.
|
| CVE-2006-6832 |
Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, possibly related to poll.php or the module title.
|
| CVE-2006-6824 |
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad
Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) getdate parameter in
(a) day.php, (b) month.php, (c) year.php, (d) week.php, (e)
search.php, (f) rss/index.php, (g) print.php, and (h) preferences.php;
the (2) cpath parameter in (i) day.php, (j) month.php, (k) year.php,
(l) week.php, and (m) search.php; the (3) query parameter in
search.php; and possibly the cpath, (4) unset, and (5) set parameters
in a setcookie action in preferences.php; different vectors than
CVE-2006-3319. NOTE: it was later reported that vectors b, c, and d
also affect 2.24.
|
| CVE-2006-6815 |
Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure
Login Manager 1.0 allow remote authenticated administrators to inject
arbitrary web script or HTML via unspecified parameters to (1)
set_preferences.asp, (2) send_password_preferences.asp, and (3)
SecureLoginManager/list.asp in the Local-Admin Panel.
|
| CVE-2006-6808 |
Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in
WordPress 2.0.5 allows remote attackers to inject arbitrary web script
or HTML via the file parameter. NOTE: some sources have reported this
as a vulnerability in the get_file_description function in
wp-admin/admin-functions.php.
|
| CVE-2006-6782 |
Cross-site scripting (XSS) vulnerability in pnamazu 2006.02.28 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-6779 |
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows
remote attackers to inject arbitrary web script or HTML via an SWF
file that uses ActionScript to trigger execution of JavaScript.
|
| CVE-2006-6778 |
Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf
1.2.2 allows remote attackers to inject arbitrary web script or HTML
via the nid parameter.
|
| CVE-2006-6777 |
Cross-site scripting (XSS) vulnerability in index.cfm in Future
Internet allows remote attackers to inject arbitrary web script or
HTML via the categoryId parameter in a Portal.ShowPage action.
|
| CVE-2006-6776 |
Multiple SQL injection vulnerabilities in Future Internet allow remote
attackers to execute arbitrary SQL commands via the (1) newsId or (2)
categoryid parameter in a Portal.Showpage action in index.cfm, or (3)
the langId parameter in index.cfm.
|
| CVE-2006-6769 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) search_string parameter in (a) setup/transcripts.php,
the (2) l parameter in (b) index.php, the (3) login field in (c)
phplive/index.php, and the (4) deptid and (5) x parameters in (d)
phplive/message_box.php.
|
| CVE-2006-6768 |
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in
PWP Technologies The Classified Ad System allow remote attackers to
inject arbitrary web script or HTML via the (1) cat or (2) main
parameter.
|
| CVE-2006-6747 |
SQL injection vulnerability in show_news.php in Xt-News 0.1 allows
remote attackers to execute arbitrary SQL commands via the id_news
parameter.
|
| CVE-2006-6746 |
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1
allow remote attackers to inject arbitrary web script or HTML via the
id_news parameter to (1) add_comment.php or (2) show_news.php.
|
| CVE-2006-6734 |
Cross-site scripting (XSS) vulnerability in modules/viewcategory.php
in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote
attackers to inject arbitrary web script or HTML via the catname
parameter.
|
| CVE-2006-6733 |
Cross-site scripting (XSS) vulnerability in support/view.php in
Support Cards 1 (osTicket) allows remote attackers to inject arbitrary
web script or HTML via the e parameter.
|
| CVE-2006-6729 |
Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-6721 |
Multiple cross-site scripting (XSS) vulnerabilities in shout.php in
Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary
web script or HTML via the (1) sbNick or (2) sbKommentar parameter.
|
| CVE-2006-6712 |
Cross-site scripting (XSS) vulnerability in SugarCRM Open Source
4.5.0f and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors in crafted email messages.
|
| CVE-2006-6709 |
Multiple SQL injection vulnerabilities in MGinternet Property Site
Manager allow remote attackers to execute arbitrary SQL commands via
the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc
parameter to (b) listings.asp; or the (5) Password or (6) Username
parameter to (c) admin_login.asp. NOTE: some of these details are
obtained from third party information.
|
| CVE-2006-6708 |
Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet
Property Site Manager allows remote attackers to inject arbitrary web
script or HTML via the s parameter.
|
| CVE-2006-6704 |
Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail
before 4.6 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors involving "unescaped data in the
database."
|
| CVE-2006-6703 |
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal
9i and 10g allow remote attackers to inject arbitrary JavaScript via
the tc parameter in webapp/jsp/container_tabs.jsp, and other
unspecified vectors.
|
| CVE-2006-6702 |
Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before
4.61 allows remote attackers to inject arbitrary web script or HTML
via crafted e-mail messages. NOTE: The provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2006-6700 |
Cross-site scripting (XSS) vulnerability in @Mail WebMail allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: This information is based upon a vague
initial disclosure. Details will be updated after the grace period has
ended.
|
| CVE-2006-6695 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Carsen Klock TextSend 1.5 allow remote attackers to inject arbitrary
web script or HTML via the (1) error or (2) success parameter. NOTE:
The provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2006-6687 |
Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal
(WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET),
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: The provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-6675 |
Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support
Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote
attackers to inject arbitrary web script or HTML via unspecified
parameters in Welcome web-app.
|
| CVE-2006-6669 |
Cross-site scripting (XSS) vulnerability in export_handler.php in
WebCalendar 1.0.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via the format parameter.
|
| CVE-2006-6668 |
Cross-site scripting (XSS) vulnerability in VerliAdmin 0.3 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: The provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-6649 |
Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2
and earlier allows remote attackers to inject arbitrary web script or
HTML via an encoded frm_action parameter. NOTE: the vendor disputes
this issue, but it is not certain whether the dispute is about the
severity of the issue, or its existence.
|
| CVE-2006-6647 |
Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before
4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote
attackers to inject arbitrary web script or HTML via the Title field
when editing a page. NOTE: some details were obtained from third party
information.
|
| CVE-2006-6646 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1)
Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project
4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters, which do not
use the check_plain function.
|
| CVE-2006-6640 |
Multiple cross-site scripting (XSS) vulnerabilities in Omniture
SiteCatalyst allow remote attackers to inject arbitrary web script or
HTML via the (1) ss parameter in (a) search.asp and the (2) company
and (3) username fields on (b) the web login page. NOTE: some details
were obtained from third party information.
|
| CVE-2006-6626 |
Cross-site scripting (XSS) vulnerability in an unspecified component
of Moodle 1.5 allows remote attackers to inject arbitrary web script
or HTML via a javascript URI in the SRC attribute of an IMG element.
NOTE: The provenance of this information is unknown; the details are
obtained solely from third party information. NOTE: It is unclear
whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.
|
| CVE-2006-6625 |
Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in
Moodle 1.6.1 allows remote attackers to inject arbitrary web script or
HTML via the navtail parameter. NOTE: The provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-6600 |
Cross-site scripting (XSS) vulnerability in dir.php in TorrentFlux
2.2, when allows remote attackers to inject arbitrary web script or
HTML via double URL-encoded strings in the dir parameter, a related
issue to CVE-2006-5609.
|
| CVE-2006-6589 |
Cross-site scripting (XSS) vulnerability in
ecommerce/control/keywordsearch in the Apache Open For Business
Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject
arbitrary web script or HTML via the SEARCH_STRING parameter, a
different issue than CVE-2006-6587. NOTE: some of these details are
obtained from third party information.
|
| CVE-2006-6587 |
Cross-site scripting (XSS) vulnerability in the forum implementation
in the ecommerce component in the Apache Open For Business Project
(OFBiz) allows remote attackers to inject arbitrary web script or HTML
by posting a message.
|
| CVE-2006-6582 |
Multiple cross-site scripting (XSS) vulnerabilities in ScriptMate User
Manager 2.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) members_username (user) and (2)
members_password (password) fields in a login action in
members/default.asp, and (3) the Search box. NOTE: some of these
details are obtained from third party information.
|
| CVE-2006-6571 |
Multiple cross-site scripting (XSS) vulnerabilities in form.php in
GenesisTrader 1.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) cuve, (2) chem, (3) do, and possibly other
parameters.
|
| CVE-2006-6548 |
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost
Manager (WHM) 3.1.0 allow remote authenticated users to inject
arbitrary web script or HTML via the domain parameter to (1)
scripts2/changeemail, (2) scripts2/limitbw, or (3)
scripts/rearrangeacct. NOTE: the feature parameter to
scripts2/dofeaturemanager is already covered by CVE-2006-6198.
|
| CVE-2006-6544 |
Cross-site scripting (XSS) vulnerability in CM68 News allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors. NOTE: The provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2006-6536 |
Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber
Free Edition allows remote attackers to inject arbitrary web script or
HTML via the hata parameter. NOTE: The provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2006-6534 |
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce
3.0a3 allow remote attackers to inject arbitrary web script or HTML
via the (1) set parameter to admin/modules.php, the (2) selected_box
parameter to definitiva/admin/customers.php, the (3) lID parameter to
admin/languages_definitions.php, or the (4) pID parameter to
admin/products.php.
|
| CVE-2006-6532 |
Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite
1.3 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) StrMsg or (2) Topic_ID parameter to (a)
vf_info.asp, (b) vf_newtopic.asp, (c) vf_settings.asp, and (d)
vf_replytopic.asp, different vectors than CVE-2006-6447. NOTE: The
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2006-6531 |
Cross-site scripting (XSS) vulnerability in the Help Tip module before
4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web
script or HTML, and possibly obtain administrative access, via node
titles.
|
| CVE-2006-6523 |
Cross-site scripting (XSS) vulnerability in mail/manage.html in
BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary
web script or HTML via the account parameter.
|
| CVE-2006-6522 |
Multiple cross-site scripting (XSS) vulnerabilities in WikiTimeScale
TwoZero before 2.31 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors in the (1) forum module and (2)
event descriptions. NOTE: some of these details are obtained from
third party information.
|
| CVE-2006-6521 |
SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0
allows remote attackers to execute arbitrary SQL commands via the aa
parameter.
|
| CVE-2006-6520 |
Multiple cross-site scripting (XSS) vulnerabilities in
Messageriescripthp 2.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) pseudo parameter to (a) existepseudo.php,
the (2) email parameter to (b) existeemail.php, or the (3) pageName or
(4) cssform parameter to (c) Contact/contact.php.
|
| CVE-2006-6519 |
SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows
remote attackers to execute arbitrary SQL commands via the aa
parameter.
|
| CVE-2006-6518 |
Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) pseudo, (2) email, (3) date, (4) sujet, (5) message, (6) site, and
(7) lien parameters to (a) admin/change.php, and the (8) aa parameter
to (b) lire-avis.php.
|
| CVE-2006-6517 |
Multiple cross-site scripting (XSS) vulnerabilities in KDPics 1.16 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) categories parameter to (a) index.php3 or (b)
galeries.inc.php3.
|
| CVE-2006-6509 |
Cross-site scripting (XSS) vulnerability in the skinning feature in
SiteKiosk before 6.5.150 allows local users to bypass security
protections and inject arbitrary web script or HTML via an ABOUT: URI,
which is displayed in the title bar of the browser.
|
| CVE-2006-6507 |
Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass
Cross-Site Scripting (XSS) protection via vectors related to a
Function.prototype regression error.
|
| CVE-2006-6503 |
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird
before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to
bypass cross-site scripting (XSS) protection by changing the src
attribute of an IMG element to a javascript: URI.
|
| CVE-2006-6487 |
Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook
(dt_guestbook) 1.0f, when register_globals is enabled, allows remote
attackers to inject arbitrary web script or HTML via the error[]
parameter.
|
| CVE-2006-6485 |
Multiple cross-site scripting (XSS) vulnerabilities in ShopSite 8.1
and earlier allow remote attackers to inject arbitrary web script or
HTML via the prevlocation parameter in shopper/sc/registration.cgi and
other unspecified vectors.
|
| CVE-2006-6483 |
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML
tags when protecting against cross-site scripting (XSS) attacks, which
allows remote attackers to inject arbitrary web script or HTML via a
NULL byte (%00) in certain HTML tags, as demonstrated using
"%00script" in a tag.
|
| CVE-2006-6479 |
Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP
2.0 allow remote attackers to inject arbitrary web script or HTML via
the email parameter in (1) erreurinscription.php, (2)
Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4)
membre.dwt.php, and (5) admin/admin_config/Aide.php.
|
| CVE-2006-6466 |
Multiple cross-site scripting (XSS) vulnerabilities in WBmap.php in
WikyBlog 1.3.2 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) key, (2) d, (3) l, or (4) v parameter.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information. NOTE: CVE disputes the l
vector because l is validated by ctype_alpha before use.
|
| CVE-2006-6459 |
Cross-site scripting (XSS) vulnerability in toplist.php in PhpBB
Toplist 1.3.7 allows remote attackers to inject arbitrary HTML or web
script via the (1) Name and (2) Information fields when adding a new
site (toplistnew action).
|
| CVE-2006-6457 |
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other
versions allows remote attackers to obtain sensitive information
(MySQL username and password) via an invalid (large or negative) ver
parameter, which leaks the information in an error message.
|
| CVE-2006-6452 |
Multiple cross-site scripting (XSS) vulnerabilities in the MyArticles
module before 0.6 beta 1, for RunCMS, allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters to (1)
topics.php, (2) submit.php, and (3) class/calendar.class.php.
|
| CVE-2006-6451 |
Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk
8.0.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via unspecified parameters to (1) get_password.php or
(2) login_up.php3.
|
| CVE-2006-6447 |
Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite
1.3 and 1.5 allow remote attackers to inject arbitrary web script or
HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a
URL in the SRC attribute of an IFRAME element that is submitted to
vf_newtopic.asp.
|
| CVE-2006-6436 |
Cross-site scripting (XSS) vulnerability in the Network controller in
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before
13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers
to inject arbitrary web script or HTML via HTTP TRACE messages.
|
| CVE-2006-6421 |
Cross-site scripting (XSS) vulnerability in the private message box
implementation (privmsg.php) in phpBB 2.0.x allows remote
authenticated users to inject arbitrary web script or HTML via the
"Message body" field in a message to a non-existent user.
|
| CVE-2006-6420 |
Multiple cross-site scripting (XSS) vulnerabilities in jce.php in the
JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0
beta 2 and earlier for Joomla! (com_jce) allow remote attackers to
inject arbitrary web script or HTML via the (1) img, (2) title, (3) w,
or (4) h parameter, different vectors than CVE-2006-6166. NOTE: The
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2006-6413 |
Cross-site scripting (XSS) vulnerability in Amateras sns 3.11 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-6403 |
mystats.php in MyStats 1.0.8 and earlier allows remote attackers to
obtain the installation path via (1) details and (2) by array
parameters, probably resulting in a path disclosure in an error
message.
|
| CVE-2006-6402 |
SQL injection vulnerability in mystats.php in MyStats 1.0.8 and
earlier allows remote attackers to execute arbitrary SQL commands via
the details parameter.
|
| CVE-2006-6401 |
Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in
MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) connexion, (2) by, and (3) details
parameter.
|
| CVE-2006-6393 |
Cross-site scripting (XSS) vulnerability in Jonas Gauffin Publicera
1.0-rc2 and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors related to the
InputFilter::getString function.
|
| CVE-2006-6389 |
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile
allow remote attackers to inject arbitrary web script or HTML via the
(1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks
parameters to (b) polls.php, different vectors than CVE-2006-5770.
|
| CVE-2006-6388 |
Cross-site scripting (XSS) vulnerability in naprednaPretraga.php in
LINK Content Management Server (CMS) allows remote attackers to inject
arbitrary web script or HTML via the txtPretraga parameter. NOTE: The
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2006-6386 |
Cross-site scripting (XSS) vulnerability in the CVS management/tracker
4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution
release system) for Drupal allows remote attackers to inject arbitrary
web script or HTML via the motivation field in the CVS application
page, which is not passed through check_markup on display.
|
| CVE-2006-6380 |
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate
HelpDesk allows remote attackers to inject arbitrary web script or
HTML via the keyword parameter.
|
| CVE-2006-6375 |
Cross-site scripting (XSS) vulnerability in display.php in Simple
Machines Forum (SMF) 1.1 Final and earlier allows remote attackers to
inject arbitrary web script or HTML via the contents of a file that is
uploaded with the image parameter set, which can be interpreted as
script by Internet Explorer's automatic type detection.
|
| CVE-2006-6372 |
Multiple cross-site scripting (XSS) vulnerabilities in pbguestbook.php
in JAB Guest Book 20061205 allow remote attackers to inject arbitrary
web script or HTML via the (1) topic or (2) message parameter. NOTE:
The provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2006-6371 |
Cross-site scripting (XSS) vulnerability in pbguestbook.php in JAB
Guest Book allows remote attackers to inject arbitrary web script or
HTML via the author parameter.
|
| CVE-2006-6366 |
Cross-site scripting (XSS) vulnerability in
includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3,
2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject
arbitrary web script or HTML via the js parameter. NOTE: The
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2006-6364 |
Cross-site scripting (XSS) vulnerability in error.php in Inside
Systems Mail (ISMail) 2.0 and earlier allows remote attackers to
inject arbitrary web script or HTML via the error parameter.
|
| CVE-2006-6363 |
Cross-site scripting (XSS) vulnerability in admin.pl in BlueSocket
Secure Controller (BSC) before 5.2, or without 5.1.1-BluePatch, allows
remote attackers to inject arbitrary web script or HTML via the
ad_name parameter.
|
| CVE-2006-6359 |
Cross-site scripting (XSS) vulnerability in Stefan Frech
online-bookmarks 0.6.12 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2006-6358 |
SQL injection vulnerability in the login function in auth.inc in
Stefan Frech online-bookmarks 0.6.12 allows remote attackers to
execute arbitrary SQL commands via the (1) username and possibly the
(2) password parameter. NOTE: some of these details are obtained from
third party information.
|
| CVE-2006-6357 |
Cross-site scripting (XSS) vulnerability in templates/cat_temp.php in
PHPNews 1.3.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors. NOTE: The provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-6356 |
Multiple cross-site scripting (XSS) vulnerabilities in
templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to
inject arbitrary web script or HTML via the (1) url, (2) id, (3)
subject, (4) username, or (5) time parameter.
|
| CVE-2006-6349 |
Multiple SQL injection vulnerabilities in PWP Technologies The
Classified Ad System allow remote attackers to execute arbitrary SQL
commands via (1) the main parameter in a view action
(includes/mainpage/view.asp) in default.asp or (2) a query in the
search engine.
|
| CVE-2006-6348 |
Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6
allows remote attackers to inject arbitrary web script or HTML via the
forum_name[] parameter.
|
| CVE-2006-6300 |
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows
remote attackers to inject arbitrary web script or HTML via the result
parameter.
|
| CVE-2006-6283 |
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard
0.1.2 allow remote attackers to inject arbitrary web script or HTML
via the subject field of (1) a private message (PM) or (2) a bulletin
board post.
|
| CVE-2006-6279 |
index.php in @lex Guestbook 4.0.1 allows remote attackers to obtain
sensitive information via a skin parameter referencing a nonexistent
skin, which reveals the installation path in an error message.
|
| CVE-2006-6278 |
Cross-site scripting (XSS) vulnerability in index.php in @lex
Guestbook 4.0.1 allows remote attackers to inject arbitrary web script
or HTML via the skin parameter.
|
| CVE-2006-6276 |
HTTP request smuggling vulnerability in Sun Java System Proxy Server
before 20061130, when used with Sun Java System Application Server or
Sun Java System Web Server, allows remote attackers to bypass HTTP
request filtering, hijack web sessions, perform cross-site scripting
(XSS), and poison web caches via unspecified attack vectors.
|
| CVE-2006-6274 |
SQL injection vulnerability in articles.asp in Expinion.net iNews (1)
Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows
remote attackers to execute arbitrary SQL commands via the ex
parameter. NOTE: early reports of this issue reported it as XSS, but
this was erroneous. The original report was for News Manager, but
there is strong evidence that the correct product is Publisher.
|
| CVE-2006-6272 |
Cross-site scripting (XSS) vulnerability in sp_index.php in Simple PHP
Gallery 1.1 allows remote attackers to inject arbitrary web script or
HTML via the dir parameter.
|
| CVE-2006-6271 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPOLL 0.96
allow remote attackers to inject arbitrary web script or HTML via the
language parameter to (1) index.php, (2) info.php; and (3) index.php,
(4) votanti.php, (5) risultati_config.php, (6) modifica_band.php, (7)
band_editor.php, and (8) config_editor.php in admin/.
|
| CVE-2006-6258 |
The phpmyadmin subsystem in AlternC 0.9.5 and earlier transmits the
SQL password in cleartext in a cookie, which might allow remote
attackers to obtain the password by sniffing or by conducting a
cross-site scripting (XSS) attack.
|
| CVE-2006-6256 |
Cross-site scripting (XSS) vulnerability in the file manager in
admin/bro_main.php in AlternC 0.9.5 and earlier allows remote
attackers to inject arbitrary web script or HTML via a folder name.
|
| CVE-2006-6249 |
Cross-site scripting (XSS) vulnerability in Chama Cargo 4.36 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-6228 |
Cross-site scripting (XSS) vulnerability in Codewalkers ltwCalendar
(aka PHP Event Calendar) before 4.2.1 allows remote attackers to
inject arbitrary HTML or web script via unknown vectors.
|
| CVE-2006-6223 |
Cross-site scripting (XSS) vulnerability in Google Search Appliance
and Google Mini allows remote attackers to inject arbitrary web script
or HTML via a UTF-7 encoded q parameter.
|
| CVE-2006-6219 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
dev4u CMS allow remote attackers to inject arbitrary web script or
HTML via the (1) user_name, (2) passwort, and (3) go_target
parameters.
|
| CVE-2006-6211 |
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) msg parameter to (a) admin/admincore.php, the (2) month parameter
to (b) admin/comments.php or (c) admin/entries.php, or the (3) page
parameter to (d) admin/logs.php, different vectors than CVE-2006-5064.
|
| CVE-2006-6205 |
Multiple cross-site scripting (XSS) vulnerabilities in result.asp in
Enthrallweb eHomes allow remote attackers to inject arbitrary web
script or HTML via the (1) city or (2) State parameter.
|
| CVE-2006-6198 |
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost
Manager (WHM) 3.1.0 allow remote authenticated users to inject
arbitrary web script or HTML via the (1) email parameter to (a)
scripts2/dochangeemail, the (2) supporturl parameter to (b)
cgi/addon_configsupport.cgi, the (3) pkg parameter to (c)
scripts/editpkg, the (4) domain parameter to (d) scripts2/domts2 and
(e) scripts/editzone, the (5) feature parameter to (g)
scripts2/dofeaturemanager, and the (6) ndomain parameter to (h)
scripts/park.
|
| CVE-2006-6197 |
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution
1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web
script or HTML via the (1) app_name parameter in (a)
_404_not_found.page.php, (b) _410_stats_gone.page.php, and (c)
_referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter
in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI
parameter in (e) inc/VIEW/errors/_referer_spam.page.php.
|
| CVE-2006-6196 |
Cross-site scripting (XSS) vulnerability in the search functionality
in Fixit iDMS Pro Image Gallery allows remote attackers to inject
arbitrary web script or HTML via a search field (txtsearchtext
parameter).
|
| CVE-2006-6188 |
Cross-site scripting (XSS) vulnerability in view_search.asp in
ClickTech Click Gallery allows remote attackers to inject arbitrary
web script or HTML via the txtKeyWord parameter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2006-6180 |
Cross-site scripting (XSS) vulnerability in articles.asp in
Expinion.net iNews Publisher (iNP) 2.5 and earlier allows remote
attackers to inject arbitrary web script or HTML via the hl parameter.
NOTE: The provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2006-6176 |
Cross-site scripting (XSS) vulnerability in admin.php in Blogn before
1.9.4 allows remote attackers to inject arbitrary web script or HTML
via unspecified parameters.
|
| CVE-2006-6174 |
Cross-site scripting (XSS) vulnerability in tDiary before 2.0.3 and
2.1.x before 2.1.4.20061126 allows remote attackers to inject
arbitrary web script or HTML via the conf parameter in (1) tdiary.rb
and (2) skel/conf.rhtml.
|
| CVE-2006-6166 |
Cross-site scripting (XSS) vulnerability in jce.php in the JCE Admin
Component in Ryan Demmer Joomla Content Editor (JCE) 1.0.4 for Joomla!
(com_jce), without the 20060821 jce_patch, allows remote attackers to
inject arbitrary web script or HTML via the mosConfig_live_site
parameter.
|
| CVE-2006-6163 |
Cross-site scripting (XSS) vulnerability in tiki-setup_base.php in
TikiWiki before 1.9.7 allows remote attackers to inject arbitrary
JavaScript via unspecified parameters.
|
| CVE-2006-6162 |
Cross-site scripting (XSS) vulnerability in tiki-edit_structures.php
in TikiWiki 1.9.6 allows remote attackers to inject arbitrary web
script or HTML via the pageAlias parameter. NOTE: The provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-6159 |
Multiple cross-site scripting (XSS) vulnerabilities in newticket.php
in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary
web script or HTML via the (1) message or (2) subject parameter.
|
| CVE-2006-6158 |
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help
Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c)
Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web
script or HTML via the (1) id or email parameter to ticketview.php, or
(2) the email parameter to ticket.php.
|
| CVE-2006-6156 |
Cross-site scripting (XSS) vulnerability in auth/message.php in HIOX
Star Rating System Script (HSRS) 1.0 and earlier allows remote
attackers to inject arbitrary web script or HTML via the query string
(PHP_SELF). NOTE: The provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2006-6153 |
Multiple cross-site scripting (XSS) vulnerabilities in vSpin.net
Classified System 2004 allow remote attackers to inject arbitrary web
script or HTML via (1) catname parameter to cat.asp or the (2)
minprice parameter to search.asp.
|
| CVE-2006-6148 |
Multiple cross-site scripting (XSS) vulnerabilities in submitlink.asp
in JiRos Links Manager allow remote attackers to inject arbitrary web
script or HTML via the (1) lName, (2) lURL, (3) lImage, and (4)
lDescription parameters. NOTE: some of these details are obtained from
third party information.
|
| CVE-2006-6147 |
Multiple SQL injection vulnerabilities in JiRos Links Manager allow
remote attackers to execute arbitrary SQL commands via the (1) LinkID
parameter to openlink.asp or the (2) CategoryID parameter to
viewlinks.asp.
|
| CVE-2006-6142 |
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail
1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web
script or HTML via the (1) mailto parameter in (a) webmail.php, the
(2) session and (3) delete_draft parameters in (b) compose.php, and
(4) unspecified vectors involving "a shortcoming in the magicHTML
filter."
|
| CVE-2006-6124 |
Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server
1.0 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-6123 |
Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals
enabled, allows remote attackers to bypass XSS protection and set
arbitrary variables via a query string that causes the variable to be
defined in global space, with separate _GET, _REQUEST, or other
critical parameters, which are unset by the protection scheme and
prevent the original variable from being detected.
|
| CVE-2006-6118 |
Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery
1.55 allows remote attackers to inject arbitrary web script or HTML
via the page parameter.
|
| CVE-2006-6108 |
Cross-site scripting (XSS) vulnerability in EC-CUBE before 1.0.1a-beta
allows remote attackers to inject arbitrary web script or HTML via
unknown attack vectors.
|
| CVE-2006-6096 |
Cross-site scripting (XSS) vulnerability in activenews_search.asp in
ActiveNews Manager allows remote attackers to inject arbitrary web
script or HTML via the query parameter.
|
| CVE-2006-6091 |
Cross-site scripting (XSS) vulnerability in Grim Pirate GrimBB before
2006_11_21 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2006-6090 |
Multiple SQL injection vulnerabilities in BaalAsp forum allow remote
attackers to execute arbitrary SQL commands via the (1) password
parameter to (a) adminlogin.asp, the (2) name or (3) password
parameter to (b) userlogin.asp, or the (3) search parameter to
search.asp.
|
| CVE-2006-6089 |
Multiple cross-site scripting (XSS) vulnerabilities in addpost1.asp in
BaalAsp forum allow remote attackers to inject arbitrary web script or
HTML via the (1) title (Subject), (2) groupname (Group Name), or (3)
detail (Message) field.
|
| CVE-2006-6088 |
Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar
i-Gallery 3.4 allow remote attackers to inject arbitrary web script or
HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an
unspecified parameter related to search, possibly the Search Gallery
field, or the myquery parameter, in search.asp. NOTE: some of these
details are obtained from third party information.
|
| CVE-2006-6087 |
Cross-site scripting (XSS) vulnerability in weblog.php in my little
weblog allows remote attackers to inject arbitrary web script or HTML
via the action parameter.
|
| CVE-2006-6083 |
SQL injection vulnerability in search.asp in CreaScripts Creadirectory
allows remote attackers to execute arbitrary SQL commands via the
category parameter.
|
| CVE-2006-6082 |
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts
Creadirectory allow remote attackers to inject arbitrary web script or
HTML via the (1) cat parameter to addlisting.asp or the (2) search
parameter to search.asp.
|
| CVE-2006-6075 |
Cross-site scripting (XSS) vulnerability in addpost1.asp in BaalAsp
forum allows remote attackers to inject arbitrary web script or HTML
via the name parameter. NOTE: The provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-6046 |
Multiple cross-site scripting (XSS) vulnerabilities in eggblog 3.1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) edit parameter to (a) admin/articles.php or (b)
admin/comments.php, or the (2) add parameter to admin/users.php.
|
| CVE-2006-6040 |
Multiple cross-site scripting (XSS) vulnerabilities in
admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to
inject arbitrary web script or HTML via (1) the prefs parameter in a
buildnavprefs action or (2) the navprefs parameter in a savenavprefs
action.
|
| CVE-2006-6037 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Dan Jensen Travelsized CMS 0.4.1 and earlier allow remote attackers to
inject arbitrary web script or HTML via (1) page, (2) page_id, or (3)
language parameter.
|
| CVE-2006-6035 |
Cross-site scripting (XSS) vulnerability in list.php in BLOG:CMS 4.1.3
and earlier allows remote attackers to inject arbitrary web script or
HTML via the FADDR parameter.
|
| CVE-2006-6032 |
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog
(SPHPBlog), probably 0.4.8, allow remote attackers to inject arbitrary
web script or HTML via (1) the action parameter in add_block.php or
(2) the entry parameter in index.php, different vectors than
CVE-2005-1135. NOTE: this has been reported to affect 0.8, but as of
20061121, the most recent version is only 0.4.9.
|
| CVE-2006-6022 |
Cross-site scripting (XSS) vulnerability in login_form.asp in
BestWebApp Dating Site allows remote attackers to inject arbitrary web
script or HTML via the msg parameter.
|
| CVE-2006-6021 |
SQL injection vulnerability in the login component in BestWebApp
Dating Site allows remote attackers to execute arbitrary SQL commands
via the (1) username and (2) passwd parameters.
|
| CVE-2006-6020 |
Cross-site scripting (XSS) vulnerability in announce.php in Blog
Torrent Preview 0.92 allows remote attackers to inject arbitrary web
script or HTML via the left parameter.
|
| CVE-2006-6019 |
Cross-site scripting (XSS) vulnerability in
extensions/googiespell/googlespell_proxy.php in Bill Roberts Bloo 1.0
allows remote attackers to inject arbitrary web script or HTML via the
lang parameter.
|
| CVE-2006-6012 |
Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in
MGinternet Car Site Manager (CSM) allows remote attackers to inject
arbitrary web script or HTML via the p parameter. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-5986 |
admin/options.php in Extreme CMS 0.9, and possibly earlier, does not
require authentication, which might allow remote attackers to conduct
unauthorized activities. NOTE: this issue can be combined with
another vulnerability to expand the scope of a cross-site scripting
(XSS) attack without authentication. NOTE: the provenance of this
information is unknown; details are obtained from third party sources.
|
| CVE-2006-5985 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/options.php in Extreme CMS 0.9, and possibly earlier, allow
remote attackers to inject arbitrary web script or HTML via the (1)
bg1, (2) bg2, (3) text, or (4) size parameters. NOTE: the provenance
of this information is unknown; details are obtained from third party
sources.
|
| CVE-2006-5984 |
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web
Hosting Control Panel 3.2.10 allow remote authenticated users to
inject arbitrary web script or HTML via the (1) txtCompanyName, (2)
txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4)
setThemeColour parameter to (b) default.asp in the Reseller and Admin
levels; or the (5) setThemeColour parameter to default.asp in the User
level. NOTE: the txtDomainName parameter to domains.asp is covered by
CVE-2006-1407, which suggests that this vector is fixed in 3.2.10
stable.
|
| CVE-2006-5983 |
Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software
DirectAdmin 1.28.1 allow remote authenticated users to inject
arbitrary web script or HTML via the (1) user parameter to (a)
CMD_SHOW_RESELLER or (b) CMD_SHOW_USER in the Admin level; the (2)
TYPE parameter to (c) CMD_TICKET_CREATE or (d) CMD_TICKET, the (3)
user parameter to (e) CMD_EMAIL_FORWARDER_MODIFY, (f)
CMD_EMAIL_VACATION_MODIFY, or (g) CMD_FTP_SHOW, and the (4) name
parameter to (h) CMD_EMAIL_LIST in the User level; or the (5) user
parameter to (i) CMD_SHOW_USER in the Reseller level.
|
| CVE-2006-5976 |
Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe
3.0 allow remote attackers to execute arbitrary SQL commands via the
(1) Username or (2) Password field. NOTE: some of these details are
obtained from third party information.
|
| CVE-2006-5975 |
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in
BlogMe 3.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) Name, (2) URL, or (3) Comments field.
|
| CVE-2006-5960 |
Multiple cross-site scripting (XSS) vulnerabilities in
account_login.asp in A+ Store E-Commerce allow remote attackers to
inject arbitrary web script or HTML via the (1) username (txtUserName)
and (2) password (txtPassword) parameters. NOTE: portions of these
details are obtained from third party information.
|
| CVE-2006-5959 |
SQL injection vulnerability in browse.asp in A+ Store E-Commerce
allows remote attackers to execute arbitrary SQL commands via the
ParentID parameter.
|
| CVE-2006-5958 |
Multiple cross-site scripting (XSS) vulnerabilities in INFINICART
allow remote attackers to inject arbitrary web script or HTML via the
(1) username and (2) password fields in (a) login.asp, (3) search
field in (b) search.asp, and (4) email field in (c) sendpassword.asp.
|
| CVE-2006-5957 |
** DISPUTED **
Multiple SQL injection vulnerabilities in INFINICART allow remote
attackers to execute arbitrary SQL commands via the (1) groupid
parameter in (a) browse_group.asp, (2) productid parameter in (b)
added_to_cart.asp, and (3) catid and (4) subid parameter in (c)
browsesubcat.asp. NOTE: the vendor has disputed this report, saying
"The vulnerabilities mentioned were never present in our official
released products but only in the unofficial demo version. However we
do appreciate the information. We have update our demo version and
made sure all those vulnerabilities are fixed."
|
| CVE-2006-5945 |
Multiple SQL injection vulnerabilities in MGinternet Car Site Manager
(CSM) allow remote attackers to execute arbitrary SQL commands via the
(1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or
(4) loc parameter to (b) csm/asp/listings.asp.
|
| CVE-2006-5944 |
Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in
MGinternet Car Site Manager (CSM) allows remote attackers to inject
arbitrary web script or HTML via the s parameter.
|
| CVE-2006-5943 |
Multiple SQL injection vulnerabilities in inventory/display/imager.asp
in Website Designs for Less Inventory Manager allow remote attackers
to execute arbitrary SQL commands via the (1) pictable, (2) picfield,
or (3) where parameter.
|
| CVE-2006-5942 |
Cross-site scripting (XSS) vulnerability in
inventory/display/display_results.asp in Website Designs For Less
Inventory Manager allows remote attackers to inject arbitrary web
script or HTML via the category parameter.
|
| CVE-2006-5924 |
Cross-site scripting (XSS) vulnerability in index.php in Efficient IP
iPmanager (IPm) 2.3 allows remote attackers to inject arbitrary web
script or HTML via the errmsg parameter. NOTE: the provenance of this
information is unknown; details are obtained from third party sources.
|
| CVE-2006-5922 |
index.php in Wheatblog (wB) allows remote attackers to obtain
sensitive information via certain values of the postPtr[] and next
parameters, which reveals the path in an error message.
|
| CVE-2006-5921 |
Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php
in Wheatblog (wB) allow remote attackers to inject arbitrary web
script or HTML via the (1) Name, (2) WWW, and (3) Comment fields.
NOTE: this issue may overlap CVE-2006-5195.
|
| CVE-2006-5915 |
Multiple cross-site scripting (XSS) vulnerabilities in ls.php in
SAMEDIA LandShop allow remote attackers to inject arbitrary web script
or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area,
(5) search_type, (6) infield, or (7) search_order parameter.
|
| CVE-2006-5914 |
SQL injection vulnerability in ls.php in SAMEDIA LandShop allows
remote attackers to execute arbitrary SQL commands via the infield
parameter. NOTE: the start, search_order, search_type, and search_area
parameters are already covered by CVE-2005-4018.
|
| CVE-2006-5900 |
Cross-site scripting (XSS) vulnerability in the
incubator/tests/Zend/Http/_files/testRedirections.php sample code in
Zend Framework Preview 0.2.0 allows remote attackers to inject
arbitrary web script or HTML via arbitrary parameters.
|
| CVE-2006-5886 |
SQL injection vulnerability in propertysdetails.asp in Dynamic
Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers
to execute arbitrary SQL commands via the PropID parameter.
|
| CVE-2006-5883 |
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow
remote authenticated users to inject arbitrary web script or HTML via
the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir
parameters in (b) newuser.html.
|
| CVE-2006-5860 |
Cross-site scripting (XSS) vulnerability in the administrator console
for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to
inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2006-5859 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0
and 7.0.1, when Global Script Protection is not enabled, allows remote
attackers to inject arbitrary HTML and web script via unknown vectors,
possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.
|
| CVE-2006-5853 |
Cross-site scripting (XSS) vulnerability in logon.aspx in Immediacy
CMS (Immediacy .NET CMS) 5.2 allows remote attackers to inject
arbitrary web script or HTML via the lang parameter, which is returned
to the client in a lang cookie.
|
| CVE-2006-5847 |
Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop
2.2.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via the cat parameter.
|
| CVE-2006-5846 |
Directory traversal vulnerability in index.php in FreeWebshop 2.2.2
and earlier allows remote attackers to read and include arbitrary
files via a .. (dot dot) in the page parameter, a different vector
than CVE-2006-5773.
|
| CVE-2006-5843 |
Cross-site scripting (XSS) vulnerability in index.php in Speedywiki
2.0 allows remote attackers to inject arbitrary web script or HTML via
the showRevisions parameter.
|
| CVE-2006-5832 |
All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote
attackers to obtain the full path of the web server via certain
requests to (1) public/code/cp_dpage.php, possibly involving the
aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php,
possibly involving the order_field[] parameter, and (3)
public/code/cp_show_page_help.php, possibly involving the hp[]
parameter, which reveal the path in various error messages.
|
| CVE-2006-5831 |
PHP remote file inclusion vulnerability in admin/code/index.php in All
In One Control Panel (AIOCP) 1.3.007 and earlier allows remote
attackers to execute arbitrary PHP code via a URL in the load_page
parameter.
|
| CVE-2006-5830 |
Multiple cross-site scripting (XSS) vulnerabilities in All In One
Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) topid, (2) forid, and
(3) catid parameters to code/cp_forum_view.php; (4) choosed_language
parameter to cp_dpage.php; (5) orderdir parameter to
cp_links_search.php; (6) order_field parameter to (a)
cp_show_ec_products.php and (b) cp_users_online.php; and the (7)
signature and (8) fiscal code fields in the user profile.
|
| CVE-2006-5829 |
Multiple SQL injection vulnerabilities in All In One Control Panel
(AIOCP) 1.3.007 and earlier allow remote attackers to execute
arbitrary SQL commands via the (1) choosed_language parameter to (a)
cp_dpage.php, (b) cp_news.php, (c) cp_forum_view.php, (d)
cp_edit_user.php, (e) cp_newsletter.php, (f) cp_links.php, (g)
cp_contact_us.php, (h) cp_login.php, and (i) cp_codice_fiscale.php in
public/code/; (2) news_category parameter to public/code/cp_news.php;
(3) nlmsg_nlcatid parameter to public/code/cp_newsletter.php; (4)
links_category parameter to public/code/cp_links.php; (5)
product_category_id parameter to public/code/cp_show_ec_products.php;
(6) order_field parameter to public/code/cp_show_ec_products.php; (7)
firstrow parameter to public/code/cp_users_online.php; and (8)
orderdir parameter to public/code/cp_links_search.php.
|
| CVE-2006-5827 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
phpComasy CMS 0.7.9pre and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) username or (2) password
parameters.
|
| CVE-2006-5825 |
Cross-site scripting (XSS) vulnerability in index.php in Kayako
SupportSuite 3.00.32 allows remote attackers to inject arbitrary web
script or HTML via the query string.
|
| CVE-2006-5810 |
Cross-site scripting (XSS) vulnerability in
modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers
to inject arbitrary web script or HTML via the newdownloadshowdays
parameter.
|
| CVE-2006-5800 |
Cross-site scripting (XSS) vulnerability in default.asp in
xenis.creator CMS allows remote attackers to inject arbitrary web
script or HTML via the nav parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-5799 |
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in
xenis.creator CMS allow remote attackers to inject arbitrary web
script or HTML via the (1) contid or (2) search parameters.
|
| CVE-2006-5791 |
Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG
2.6.2 and earlier allow remote attackers to inject arbitrary HTML or
web script via (1) the filename for downloading, which is not quoted
in an error message by the send_file_direct function, and (2) the Type
or Category values in a New entry, which is not properly handled in an
error message by the submit_elog function.
|
| CVE-2006-5775 |
Cross-site scripting (XSS) vulnerability in profile.php in FunkBoard
0.71 before 4 November 2006 at 18:16 GMT allows remote attackers to
inject arbitrary web script or HTML, possibly via the name parameter.
|
| CVE-2006-5774 |
Cross-site scripting (XSS) vulnerability in Hyper NIKKI System before
2.19.9 allows remote attackers to inject arbitrary web script or HTML
via unknown vectors.
|
| CVE-2006-5771 |
Cross-site scripting (XSS) vulnerability in Arkoon SSL360 1.0 and 2.0
before 2.0/2 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2006-5770 |
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile
allow remote attackers to inject arbitrary web script or HTML via (1)
Bloks, (2) Newnews, (3) lBlok, and (4) foooot parameter in (a)
index.php; Newnews, (5) newmsgs, and Bloks parameter in (b)
MobileNews.php; Newnews parameter in (c) polls.php; (6) cats parameter
in (d) send.php; (7) footer parameter in (e) up.php; and (8) pagenav
parameter in (f) cp/index.php.
|
| CVE-2006-5769 |
Multiple cross-site scripting (XSS) vulnerabilities in admin.tool CMS
3 and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) fSid or (2) fSrcBegriffe parameters in unspecified
vectors.
|
| CVE-2006-5761 |
Cross-site scripting (XSS) vulnerability in index.php in Rhadrix
If-CMS 1.01 and 2.07 allows remote attackers to inject arbitrary web
script or HTML via the rns parameter.
|
| CVE-2006-5759 |
index.php in Rhadrix If-CMS, possibly 1.01 and 2.07, allows remote
attackers to obtain the full path of the web server via empty (1)
rns[] or (2) pag[] arguments, which reveals the path in an error
message.
|
| CVE-2006-5752 |
Cross-site scripting (XSS) vulnerability in mod_status.c in the
mod_status module in Apache HTTP Server (httpd), when ExtendedStatus
is enabled and a public server-status page is used, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors involving charsets with browsers that perform "charset
detection" when the content-type is not specified.
|
| CVE-2006-5743 |
Multiple cross-site scripting (XSS) vulnerabilities in Highwall
Enterprise and Highwall Endpoint 4.0.2.11045 management interface
allow remote attackers to inject arbitrary web script or HTML via (1)
an Access Point with a crafted SSID, (2) the name of the sensor WIDS,
(3) the name of the Highwall EndPoint workstation, or other
unspecified vectors.
|
| CVE-2006-5741 |
Multiple cross-site scripting (XSS) vulnerabilities in AirMagnet
Enterprise before 7.5 build 6307 allow remote attackers to inject
arbitrary web script or HTML via (1) the 404 error page of the Smart
Sensor Edge Sensor; (2) the user name for a failed logon, when
displayed in the audit journals reviewing interface
(/AirMagnetSensor/AMSensor.dll/XH) by the Smart Sensor Edge Sensor log
viewer; and (3) an SSID of an AP, when displayed on an ACL page
(/Amom/Amom.dll/BD) of the Enterprise Server Status Overview in the
Enterprise Server Web interface.
|
| CVE-2006-5718 |
Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin
2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web
script or HTML via UTF-7 or US-ASCII encoded characters, which are
injected into an error message, as demonstrated by a request with a
utf7 charset parameter accompanied by UTF-7 data.
|
| CVE-2006-5717 |
Multiple cross-site scripting (XSS) vulnerabilities in Zend Google
Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers
to inject arbitrary web script or HTML via unspecified parameters in
(1) basedemo.php and (2) calenderdemo.php in samples/, and other
unspecified files.
|
| CVE-2006-5713 |
Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS)
Web Server 4.0 allows remote attackers to inject arbitrary web script
or HTML via the (1) author, (2) content, or (3) title parameters when
posting a forum thread. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-5712 |
Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows
remote attackers to inject arbitrary web script via the expression
Cascading Style Sheets (CSS) function, as demonstrated using the width
style for an IMG element.
|
| CVE-2006-5703 |
Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in
Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script
or HTML via a url parameter that evades filtering, as demonstrated by
a parameter value containing malformed, nested SCRIPT elements.
|
| CVE-2006-5702 |
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information
(MySQL username and password) via an empty sort_mode parameter in (1)
tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php,
(4) messu-mailbox.php, (5) messu-sent.php, (6)
tiki-directory_add_site.php, (7) tiki-directory_ranking.php, (8)
tiki-directory_search.php, (9) tiki-forums.php, (10)
tiki-view_forum.php, (11) tiki-friends.php, (12) tiki-list_blogs.php,
(13) tiki-list_faqs.php, (14) tiki-list_trackers.php, (15)
tiki-list_users.php, (16) tiki-my_tiki.php, (17)
tiki-notepad_list.php, (18) tiki-orphan_pages.php, (19)
tiki-shoutbox.php, (20) tiki-usermenu.php, and (21)
tiki-webmail_contacts.php, which reveal the information in certain
database error messages.
|
| CVE-2006-5661 |
Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech
Netquery allows remote attackers to inject arbitrary web script or
HTML via the User-Agent HTTP header.
|
| CVE-2006-5653 |
Cross-site scripting (XSS) vulnerability in the errorHTML function in
the index script in Sun Java System Messenger Express 6 allows remote
attackers to inject arbitrary web script or HTML via the error
parameter. NOTE: this issue might be related to CVE-2006-5486,
however due to the vagueness of the initial advisory and different
researchers a new CVE was assigned.
|
| CVE-2006-5652 |
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging
Server Messenger Express allows remote attackers to inject arbitrary
web script via the expression Cascading Style Sheets (CSS) function,
as demonstrated by setting the width style for an IMG element. NOTE:
this issue might be related to CVE-2006-5486, however due to the
vagueness of the initial advisory and different researchers, it has
been assigned a new CVE.
|
| CVE-2006-5643 |
Cross-site scripting (XSS) vulnerability in search_de.html in foresite
CMS allows remote attackers to inject arbitrary web script or HTML via
the query parameter.
|
| CVE-2006-5632 |
Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop
1.4 allows remote attackers to inject arbitrary web script or HTML via
the id parameter, a different vulnerability than CVE-2006-5631. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2006-5631 |
Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop
1.4 allows remote attackers to inject arbitrary web script or HTML via
arbitrary query strings when the action parameter is not "1", as
demonstrated using script in the action parameter, a different
vulnerability than CVE-2006-5632.
|
| CVE-2006-5626 |
Cross-site scripting (XSS) vulnerability in
cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management
System (CMS) before 1.3.36 on 20061026 allows remote attackers to
inject arbitrary web script or HTML, probably via arbitrary parameters
in the query string, as demonstrated with a vigilon parameter. NOTE:
earlier downloads of 1.3.36 have the vulnerability; the software was
updated without changing the version number.
|
| CVE-2006-5605 |
Multiple cross-site scripting (XSS) vulnerabilities in
phpcards.footer.php in phpCards 1.3 allow remote attackers to inject
arbitrary web script or HTML via the CardFontFace parameter and other
unspecified parameters.
|
| CVE-2006-5599 |
Cross-site scripting (XSS) vulnerability in Oracle Application Express
(formerly HTML DB) before 2.2.1 allows remote attackers to inject
arbitrary HTML or web script via the WWV_FLOW_ITEM_HELP package. NOTE:
it is likely that this issue overlaps one of the Oracle VulnIDs
covered by CVE-2006-5351. Oracle has not publicly disputed claims by a
reliable researcher that this has been fixed by the October 2006 CPU.
|
| CVE-2006-5598 |
Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery
2.0, and possibly other versions before 2.0.3, allows remote attackers
to inject arbitrary HTML or web script via the image parameter.
|
| CVE-2006-5564 |
Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro
1.0.76 allows remote attackers to inject arbitrary web script or HTML
via the op parameter. NOTE: the provenance of this information is
unknown; the details are obtained from third party information.
|
| CVE-2006-5560 |
Cross-site scripting (XSS) vulnerability in heading.php in Boesch
ProgSys 0.151 and earlier allows remote attackers to inject arbitrary
web script or HTML via the PATH_INFO to admin/index.php, and
unspecified vectors related to certain other files. NOTE: some of
these details are obtained from third party information.
|
| CVE-2006-5537 |
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/webcm
in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allow remote
attackers to inject arbitrary web script or HTML via the (1)
upnp:settings/state or (2) upnp:settings/connection parameters.
|
| CVE-2006-5535 |
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager
(WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject
arbitrary web script or HTML via the (1) theme parameter to
scripts/dosetmytheme and the (2) template parameter to
scripts2/editzonetemplate.
|
| CVE-2006-5534 |
Multiple cross-site scripting (XSS) vulnerabilities in index.htm in
Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow
remote attackers to inject arbitrary web script or HTML via the (1)
cat, (2) Kat, (3) id, or (4) no parameters. NOTE: some of these
details are obtained from third party information.
|
| CVE-2006-5532 |
Cross-site scripting (XSS) vulnerability in rmgs/images.php in RMSOFT
Gallery System 2.0 allows remote attackers to inject arbitrary web
script or HTML via the kw parameter. NOTE: some of these details are
obtained from third party information.
|
| CVE-2006-5530 |
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews
before 2.34.01 allow remote attackers to inject arbitrary web script
or HTML via unspecified parameters to (1) admin/index.php, (2)
admin/pwlost.php, and unspecified other files. NOTE: the provenance of
this information is unknown; the details are obtained from third party
information.
|
| CVE-2006-5529 |
Cross-site scripting (XSS) vulnerability in
smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows
remote attackers to inject arbitrary web script or HTML via the query
parameter in a search operation in the katalog module. NOTE: some of
these details are obtained from third party information.
|
| CVE-2006-5524 |
Cross-site scripting (XSS) vulnerability in index.php in phplist
2.10.2 allows remote attackers to inject arbitrary web script or HTML
via the p parameter. NOTE: This issue might overlap CVE-2006-5321.
|
| CVE-2006-5516 |
Multiple cross-site scripting (XSS) vulnerabilities in
actions/usersettings.php in WikiNi before 0.4.4 allow remote attackers
to inject arbitrary web script or HTML via the (1) name and (2) email
parameters to wakka.php.
|
| CVE-2006-5515 |
Cross-site scripting (XSS) vulnerability in lib-history.inc.php in
phpAdsNew and phpPgAds before 2.0.8-pr1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors, related
to injected data that is stored by a delivery script and displayed by
the admin interface.
|
| CVE-2006-5512 |
Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen
Online Shop allows remote attackers to inject arbitrary web script or
HTML via the cat parameter.
|
| CVE-2006-5504 |
Cross-site scripting (XSS) vulnerability in index.php in Simple
Machines Forum (SMF) allows remote attackers to inject arbitrary web
script or HTML via a base64 encoded params value in the action
parameter.
|
| CVE-2006-5503 |
Cross-site scripting (XSS) vulnerability in index.php in Simple
Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject
arbitrary web script or HTML via the action parameter.
|
| CVE-2006-5499 |
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity
(s9y) 1.0.1 and earlier allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors in the media manager
administration page.
|
| CVE-2006-5496 |
Multiple cross-site scripting (XSS) vulnerabilities in Timothy Claason
KnowledgeBank 1.01 allow remote attackers to inject arbitrary web
script or HTML via unspecified parameters to (1) index.php, (2)
addknowledge.php, and (3) addscreenshot.php.
|
| CVE-2006-5486 |
Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System
Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2
allows remote attackers to execute arbitrary Javascript via crafted
messages.
|
| CVE-2006-5475 |
Multiple cross-site scripting (XSS) vulnerabilities in the XML parser
in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote
attackers to inject arbitrary web script or HTML via a crafted RSS
feed.
|
| CVE-2006-5457 |
Multiple cross-site scripting (XSS) vulnerabilities in the
registration form in Casinosoft Casino Script (Masvet) 3.2 allow
remote attackers to inject arbitrary web script or HTML via the (1)
name or (2) surname field.
|
| CVE-2006-5453 |
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x
before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x
before 2.23.3 allow remote authenticated users to inject arbitrary web
script or HTML via (1) page headers using the H1, H2, and H3 HTML tags
in global/header.html.tmpl, (2) description fields of certain items in
various edit cgi scripts, and (3) the id parameter in
showdependencygraph.cgi.
|
| CVE-2006-5451 |
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) action, (2) file, and (3) users array variables in (a) admin.php,
which are not properly handled when the administrator views the
Activity Log; and the (4) torrent parameter, as used by the
displayName variable, in (b) startpop.php, different vectors than
CVE-2006-5227.
|
| CVE-2006-5447 |
Cross-site scripting (XSS) vulnerability in index.php in DEV Web
Management System (WMS) 1.5 allows remote attackers to inject
arbitrary web script or HTML via the action parameter.
|
| CVE-2006-5442 |
ViewVC 1.0.2 and earlier does not specify a charset in its HTTP
headers or HTML documents, which allows remote attackers to conduct
cross-site scripting (XSS) attacks that inject arbitrary UTF-7 encoded
JavaScript code via a view.
|
| CVE-2006-5430 |
Cross-site scripting (XSS) vulnerability in the search functionality
in db-central (dbc) Enterprise CMS and db-central CMS allows remote
attackers to inject arbitrary web script or HTML via the needle
parameter. NOTE: the provenance of this information is unknown; the
details are obtained from third party information.
|
| CVE-2006-5416 |
Cross-site scripting (XSS) vulnerability in my.acctab.php3 in F5
Networks FirePass 1000 SSL VPN 5.5, and possibly earlier, allows
remote attackers to inject arbitrary web script or HTML via the sid
parameter.
|
| CVE-2006-5408 |
Multiple cross-site scripting (XSS) vulnerabilities in the wireless
IDS management interface for Highwall Enterprise and Highwall Endpoint
4.0.2.11045 allow remote attackers to inject arbitrary HTML or web
script via unspecified vectors.
|
| CVE-2006-5351 |
Multiple unspecified vulnerabilities in Oracle Application Express
(formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote
attack vectors, aka Vuln# (1) APEX01, (2) APEX02, (3) APEX03, (4)
APEX05, (5) APEX06, (6) APEX07, (7) APEX08, (8) APEX09, (9) APEX10,
(10) APEX11, (11) APEX12, (12) APEX13, (13) APEX14, (14) APEX15, (15)
APEX16, (16) APEX17, (17) APEX18, (18) APEX19, (19) APEX22, (20)
APEX23, (21) APEX24, (22) APEX25, (23) APEX26, (24) APEX27, (25)
APEX28, (26) APEX29, (27) APEX30, (28) APEX31, (29) APEX32, (30)
APEX33, (31) APEX34, and (32) APEX35. NOTE: as of 20061027, it is
likely that some of these identifiers are associated with cross-site
scripting (XSS) in WWV_FLOW_ITEM_HELP and NOTIFICATION_MSG, but these
have been provided separate identifiers.
|
| CVE-2006-5321 |
Multiple cross-site scripting (XSS) vulnerabilities in phplist before
2.10.3 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-5299 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Gcontact 0.6.5 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2006-5294 |
Cross-site scripting (XSS) vulnerability in index.php in phplist
before 2.10.3 allows remote attackers to inject arbitrary web script
or HTML via the unsubscribeemail parameter.
|
| CVE-2006-5293 |
Cross-site scripting (XSS) vulnerability in index.php in
PhpOutsourcing Noah's Classifieds 1.3 and earlier allows remote
attackers to inject arbitrary web script or HTML via the frommethod
parameter.
|
| CVE-2006-5264 |
Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper
1.21 b6 allows remote attackers to inject arbitrary web script or HTML
via the db parameter.
|
| CVE-2006-5247 |
Multiple cross-site scripting (XSS) vulnerabilities in Eazy Cart allow
remote attackers to inject arbitrary web script or HTML via
easycart.php, possibly related to the (1) des and (2) qty parameters
in an add action, and via other unspecified vectors. NOTE: some
details are obtained from third party information.
|
| CVE-2006-5239 |
Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the query string (PHP_SELF) in kalender.php or (2) the
captcha_session_code parameter in pre_details.php.
|
| CVE-2006-5227 |
Cross-site scripting (XSS) vulnerability in admin.php in TorrentFlux
2.1 allows remote attackers to inject arbitrary web script or HTML via
(1) the $user_agent variable, probably obtained from the User-Agent
HTTP header, and possibly (2) the $ip_resolved variable.
|
| CVE-2006-5204 |
Cross-site scripting (XSS) vulnerability in action_admin/member.php in
Invision Power Board (IPB) 2.1.7 and earlier allows remote
authenticated users to inject arbitrary web script or HTML via a
reference to a script in the avatar setting, which can be leveraged
for a cross-site request forgery (CSRF) attack involving forced SQL
execution by an admin.
|
| CVE-2006-5195 |
Multiple cross-site scripting (XSS) vulnerabilities in Wheatblog 1.0
and 1.1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors. NOTE: the provenance of this information is
unknown; the details are obtained from third party information.
|
| CVE-2006-5194 |
Cross-site scripting (XSS) vulnerability in index.php in net2ftp 0.93
allows remote attackers to inject arbitrary web script or HTML via the
username parameter. NOTE: some of these details are obtained from
third party information.
|
| CVE-2006-5190 |
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2
Milestone 2 Update 060817 allow remote attackers to inject arbitrary
web script or HTML via the (1) page parameter in the (a)
banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d)
currencies.php, (e) languages.php, (f) manufacturers.php, (g)
newsletters.php, (h) orders_status.php, (i) products_attributes.php,
(j) products_expected.php, (k) reviews.php, (l) specials.php, (m)
stats_products_purchased.php, (n) stats_products_viewed.php, (o)
tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in
/admin, and the (2) zpage parameter in (r) admin/geo_zones.php.
|
| CVE-2006-5169 |
Cross-site scripting (XSS) vulnerability in John Himmelman (aka
DaRk2k1) PowerPortal 1.1 allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors, possibly related to
registering a user. NOTE: the provenance of this information is
unknown; the details are obtained from third party information.
|
| CVE-2006-5168 |
Cross-site scripting (XSS) vulnerability in the search functionality
in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to
inject arbitrary web script or HTML via the query string.
|
| CVE-2006-5164 |
Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum
Effect Software digiSHOP 4.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) sortBy or (2) search
parameters.
|
| CVE-2006-5152 |
Cross-site scripting (XSS) vulnerability in Microsoft Internet
Explorer allows remote attackers to inject arbitrary web script or
HTML via a UTF-7 encoded URL that is returned in a large HTTP 404
error message without an explicit charset, a related issue to
CVE-2006-0032.
|
| CVE-2006-5146 |
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow
remote attackers to inject arbitrary web script or HTML via the (1) id
parameter in (a) funk.php, or the (2) action parameter in (b) tem.php
and (c) uss.php.
|
| CVE-2006-5144 |
Cross-site scripting (XSS) vulnerability in userupload.php in
OlateDownload 3.4.0 allows remote attackers to inject arbitrary web
script or HTML via the description_small parameter.
|
| CVE-2006-5134 |
Mercury SiteScope 8.2 (8.1.2.0) allows remote authenticated users to
cause a denial of service (loss of connectivity to the classic
interface) via attempted HTML injection into the "new monitor
description" field.
|
| CVE-2006-5130 |
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just
another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject
arbitrary web script or HTML via the (1) name, (2) url, (3) title, and
(4) about parameters in a forum post. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-5129 |
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just
another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject
arbitrary web script or HTML via (1) the message parameter, and
possibly other parameters, in module/shout/jafshout.php (aka the
shoutbox); and (2) the message body in a forum post in
module/forum/topicwin.php, related to the name, email, title, date,
ldate, and lname variables.
|
| CVE-2006-5127 |
Multiple cross-site scripting (XSS) vulnerabilities in Bartels Schoene
ConPresso before 4.0.5a allow remote attackers to inject arbitrary web
script or HTML via (1) the nr parameter in detail.php, (2) the msg
parameter in db_mysql.inc.php, and (3) the pos parameter in index.php.
|
| CVE-2006-5122 |
Multiple cross-site scripting (XSS) vulnerabilities in Mercury
SiteScope 8.2 (8.1.2.0) allow remote authenticated users to inject
arbitrary web script or HTML via (1) "any field create name field"
except "create new group name" or (2) any description field.
|
| CVE-2006-5120 |
Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer
Red Mombin 0.7 allow remote attackers to inject arbitrary web script
or HTML via unspecified vectors related to (1) index.php and (2)
process_login.php.
|
| CVE-2006-5119 |
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart 1.3.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) admin_name or (2) admin_pass parameter in (a) admin/login.php, or
the (3) admin_email parameter in (b) admin/password_forgotten.php.
|
| CVE-2006-5114 |
Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP
Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers
to inject arbitrary web script or HTML via the (1) ~urlmime or (2)
~command parameter, different vectors than CVE-2003-0749.
|
| CVE-2006-5110 |
Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice
2.2 allows remote attackers to inject arbitrary web script or HTML via
the msg parameter, a different vector than CVE-2006-5074. NOTE: the
provenance of this information is unknown; the details are obtained
from third party information.
|
| CVE-2006-5108 |
Multiple cross-site scripting (XSS) vulnerabilities in Devellion
CubeCart 2.0.x allow remote attackers to inject arbitrary web script
or HTML via the order_id parameter in (1) admin/print_order.php and
(2) view_order.php; the (3) site_url and (4) la_search_home parameters
and (5) certain language parameters in admin/nav.php; the (6) image
parameter in admin/image.php; the (7) site_name, (8) la_adm_header,
(9) charset, and (10) certain other parameters in
admin/header.inc.php; the (12) la_pow_by parameter in footer.inc.php;
and the (13) site_name parameter and (14) certain other parameters in
header.inc.php.
|
| CVE-2006-5106 |
Cross-site scripting (XSS) vulnerability in FacileForms before 1.4.7
for Mambo and Joomla!, when either register_globals or RG_EMULATION is
enabled, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2006-5096 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition
CMS 1.0.11, and possibly earlier, allow remote attackers to inject
arbitrary web script or HTML via the Itemid parameter in a (1)
com_contact or (2) subscribe action.
|
| CVE-2006-5090 |
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix
Evolution CMS (PECMS) allow remote attackers to inject arbitrary web
script or HTML via the (1) mod or (2) action parameters in index.php,
or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the
provenance of this information is unknown; the details are obtained
from third party information.
|
| CVE-2006-5080 |
Cross-site scripting (XSS) vulnerability in the search function in Six
Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and
1.02, allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-5074 |
Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice
2.2 allows remote attackers to inject arbitrary web script or HTML via
the alert parameter.
|
| CVE-2006-5071 |
Multiple cross-site scripting (XSS) vulnerabilities in eyeOS before
0.9.1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors involving (1) eyeNav and (2)
system/baixar.php.
|
| CVE-2006-5069 |
Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php
in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the search parameter.
|
| CVE-2006-5066 |
Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport
0.5, and other versions before 1.0, allow remote attackers to inject
arbitrary web script or HTML via the (1) page parameter in index.php
or the (2) do parameter in admin.php.
|
| CVE-2006-5064 |
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) entryid parameter in comment.php, (2) page parameter
in index.php, or the (3) uid parameter in user.php. NOTE: the
provenance of this information is unknown; the details are obtained
from third party information.
|
| CVE-2006-5063 |
Cross-site scripting (XSS) vulnerability in Elog 2.6.1 allows remote
attackers to inject arbitrary web script or HTML by editing log
entries in HTML mode.
|
| CVE-2006-5060 |
Cross-site scripting (XSS) vulnerability in login.php in Jamroom
3.0.16 and possibly earlier allows remote attackers to inject
arbitrary web script or HTML via the forgot parameter in the forgot
mode.
|
| CVE-2006-5059 |
Multiple cross-site scripting (XSS) vulnerabilities in WWWthreads
5.4.2 and earlier allow remote attackers to inject arbitrary web
script or HTML via the Cat parameter to (1) dosearch.php, (2)
postlist.php, (3) showmembers.php, (4) faq_english.php, (5)
online.php, (6) login.php, (7) newuser.php, (8) wwwthreads.php, (9)
search.php, or (10) postlist.php.
|
| CVE-2006-5057 |
Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net
PhotoStore allow remote attackers to inject arbitrary web script or
HTML via the (1) gid parameter in details.php, or the (2) photogid
parameter in view_photog.php.
|
| CVE-2006-5056 |
Cross-site scripting (XSS) vulnerability in index.php in Opial
Audio/Video Download Management 1.0 allows remote attackers to inject
arbitrary web script or HTML via the destination parameter in the
Login view.
|
| CVE-2006-5037 |
** DISPUTED **
MySource Matrix after 3.8 allows remote attackers to use the
application as an HTTP proxy server via a MIME encoded URL in the
sq_content_src parameter to access arbitrary sites with the server's
IP address and conduct cross-site scripting (XSS) attacks. NOTE: the
researcher reports that "The vendor does not consider this a
vulnerability."
|
| CVE-2006-5036 |
** DISPUTED **
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote
attackers to use the application as an HTTP proxy server via the
sq_remote_page_url parameter to access arbitrary sites with the
server's IP address and conduct cross-site scripting (XSS) attacks.
NOTE: the researcher reports that "The vendor does not consider this a
vulnerability."
|
| CVE-2006-5035 |
Multiple cross-site scripting (XSS) vulnerabilities in Paul Smith
Computer Services vCAP 1.7.0 allow remote attackers to inject
arbitrary web script or HTML via (1) the statusmsg parameter in
RegisterPage.cgi or (2) a URI corresponding to a nonexistent file.
NOTE: the provenance of this information is unknown; the details are
obtained from third party information.
|
| CVE-2006-4988 |
Multiple cross-site scripting (XSS) vulnerabilities in Patrick
Michaelis Wili-CMS allow remote attackers to inject arbitrary web
script or HTML via (1) the query string to relocate.php, (2) the
globals[pageid] parameter in example-view/inc/print_button.php, and
other unspecified vectors.
|
| CVE-2006-4985 |
Multiple cross-site scripting (XSS) vulnerabilities in Grayscale
BandSite CMS allow remote attackers to inject arbitrary web script or
HTML via (1) the max_file_size_purdy parameter in
adminpanel/includes/helpfiles/help_mp3.php, (2) the message_text
parameter in adminpanel/includes/mailinglist/sendemail.php, (3) the
this_year parameter in includes/footer.php, and the band parameter
in (4) adminpanel/includes/helpfiles/help_news.php (5)
adminpanel/includes/helpfiles/help_merch.php, (6)
adminpanel/includes/header.php, and (7) adminpanel/login_header.php;
and includes/content/ files including (8) bio_content.php, (9)
gbook_content.php, (10) interview_content.php, (11) links_content.php,
(12) lyrics_content.php, (13) member_content.php, (14)
merch_content.php, (15) mp3_content.php, (16) news_content.php, (17)
pastshows_content.php, (18) photo_content.php, (19)
releases_content.php, (20) reviews_content.php, (21)
shows_content.php, and (22) signgbook_content.php.
|
| CVE-2006-4973 |
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual
Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before
4.3.5, allows remote attackers to inject arbitrary HTML via the error
parameter.
|
| CVE-2006-4972 |
Cross-site scripting (XSS) vulnerability in
archive/index.php/forum-4.html in MyBB (aka MyBulletinBoard) allows
remote attackers to inject arbitrary web script or HTML via the
navbits[][name] parameter.
|
| CVE-2006-4967 |
Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart
allow remote attackers to inject arbitrary web script or HTML via (1)
the CatId parameter in a product category action in index.php or (2)
the SearchWd parameter in an index search action in index.php.
|
| CVE-2006-4964 |
Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before
20060918 allows remote attackers to inject arbitrary web script or
HTML via (1) vectors that bypass the XSS protection mechanisms of the
pnVarCleanFromInput function, and (2) unspecified vectors related to
the AntiCracker.
|
| CVE-2006-4960 |
Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon
2.9.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via the m parameter, which is reflected in an error
message resulting from a failed SQL query.
|
| CVE-2006-4958 |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure
Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors, possibly involving (1) taarchives.cgi, (2)
ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5)
ttawebtop.cgi, (6) ttaabout.cgi, or (7) test-cgi. NOTE: This
information is based upon a vague initial disclosure. Details will be
updated as they become available.
|
| CVE-2006-4956 |
Cross-site scripting (XSS) vulnerability in the updateuser servlet in
Neon WebMail for Java before 5.08 allows remote attackers to inject
arbitrary web script or HTML via the in_name parameter, as used by the
Name field.
|
| CVE-2006-4949 |
Cross-site scripting (XSS) vulnerability in the Drupal 4.6 Site
Profile Directory (profile_pages.module) before 1.1.2.1 and the Drupal
4.7 Site Profile Directory (profile_pages.module) before 1.2.2.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to "lack of validation on output,"
possibly in the name and title parameters.
|
| CVE-2006-4947 |
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search
Keywords module before 1.15 2006/09/15 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors related to
"lack of validation on output."
|
| CVE-2006-4941 |
Multiple cross-site scripting (XSS) vulnerabilities in Moodle before
1.6.2 might allow remote attackers to inject arbitrary web script or
HTML via (1) the choose parameter in files/index.php and (2) the sub
parameter in doc/index.php.
|
| CVE-2006-4923 |
Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat
Portal System allows remote attackers to inject arbitrary web script
or HTML via the what parameter.
|
| CVE-2006-4917 |
Cross-site scripting (XSS) vulnerability in search.php in PT News
1.7.8 allows remote attackers to inject arbitrary web script or HTML
via the pgname parameter.
|
| CVE-2006-4915 |
Cross-site scripting (XSS) vulnerability in index.php in Innovate
Portal 2.0 allows remote attackers to inject arbitrary web script or
HTML via the content parameter.
|
| CVE-2006-4909 |
Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS
Mitigation Appliance before 5.1(6), when anti-spoofing is enabled,
allows remote attackers to inject arbitrary web script or HTML via
certain character sequences in a URL that are not properly handled
when the appliance sends a meta-refresh.
|
| CVE-2006-4895 |
IDevSpot NexieAffiliate 1.9 and earlier allows remote attackers to
delete arbitrary affiliates via a modified id parameter to delete.php.
|
| CVE-2006-4894 |
Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in
iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to
inject arbitrary web script or HTML via the error parameter.
|
| CVE-2006-4884 |
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot
iSupport 1.8 allow remote attackers to inject arbitrary web script or
HTML via (1) the suser parameter in support/rightbar.php, (2) the
ticket_id parameter in support/open_tickets.php, and (3) the
cons_page_title parameter in index.php. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-4883 |
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot
BizDirectory allow remote attackers to inject arbitrary web script or
HTML via (1) the stylesheet parameter in Feed.php or (2) the message
parameter in status.php.
|
| CVE-2006-4881 |
Multiple cross-site scripting (XSS) vulnerabilities in David Bennett
PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) the replyuser parameter in (a)
pm.php; (2) the txt_jumpto parameter in (b) dropdown.php; the (3)
txt_error and (4) txt_templatenotexist parameters in (c) template.php;
the (5) split parameter in certain files, as demonstrated by (d)
editprofile.php, (e) search.php, (f) index.php, and (g) pm.php; and
the (6) txt_login parameter in (h) loginline.php; and allow remote
authenticated users to inject arbitrary web script or HTML via the (7)
txt_logout parameter in (i) loginline.php.
|
| CVE-2006-4874 |
Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS
allow remote attackers to inject arbitrary web script or HTML via the
(1) language[Admin name] and (2) language[Admin back] parameters in
(a) modules/blocks.php; the (3) language[Register title] and (4)
language[Register title2] parameters in (b) modules/register.php; the
(5) language[Mass-Email form title], (6) language[Mass-Email form
desc], (7) language[Mass-Email form desc2] (8) language[Mass-Email
form desc3], and (9) language[Mass-Email form desc4] parameters in (c)
modules/mass-email.php; the (10) language[Forgotten title], (11)
language[Forgotten desc], (12) language[Forgotten desc2], (13)
language[Forgotten desc3], (14) language[Forgotten desc4], and (15)
language[Forgotten desc5] parameters in (d) modules/register.php; and
the (16) language[Search view desc], (17) language[Search view desc2],
(18) language[Search view desc3], (19) language[Search view desc4],
(20) language[Search view desc5], (21) language[Search view desc6],
(22) language[Search view desc7], and (23) language[Search view desc8]
parameters in (e) modules/search.php.
|
| CVE-2006-4856 |
Multiple cross-site scripting (XSS) vulnerabilities in Roller
WebLogger 2.3 allow remote attackers to inject arbitrary web script or
HTML via the (1) name, (2) email, or (3) url parameters; (4) certain
content parameters in the preview method; or (5) the q parameter in
(a) sitesearch.do.
|
| CVE-2006-4843 |
Cross-site scripting (XSS) vulnerability in the Active Content Filter
feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1
allows remote attackers to inject arbitrary web script or HTML via
unspecified "code sequences" that bypass the protection scheme.
|
| CVE-2006-4838 |
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE
6.0 allow remote attackers to inject arbitrary web script or HTML via
the (1) root_url and (2) dcp_version parameters in (a)
admin/inc/footer.inc.php, and the root_url, (3) page_top_name, (4)
page_name, and (5) page_options parameters in (b)
admin/inc/header.inc.php.
|
| CVE-2006-4829 |
Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki
Blojsom 2.31 allow remote attackers to inject arbitrary web script or
HTML via the (1) blog-category-description, (2) blog-entry-title, (3)
rss-enclosure-url, (4) technorati-tagsi, or (5) blog-category-name
parameter in a blog post.
|
| CVE-2006-4825 |
Multiple cross-site scripting (XSS) vulnerabilities in
cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and
possibly earlier, allow remote attackers to inject arbitrary web
script or HTML via the (1) ti, (2) bi, or (3) cbgi parameters.
|
| CVE-2006-4822 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
eMuSOFT emuCMS 0.3 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) query or (2) page parameters.
|
| CVE-2006-4821 |
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview
module before 1.19 2006/09/12 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-4797 |
Cross-site scripting (XSS) vulnerability in tag.php in CloudNine
Interactive CJ Tag Board 3.0 allows remote attackers to inject
arbitrary web script or HTML via a JavaScript event in a url BBcode
tag in the cjmsg parameter.
|
| CVE-2006-4796 |
Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums
2000 3.4.06 allows remote attackers to inject arbitrary web script or
HTML via the sortorder parameter (strtopicsortord variable).
|
| CVE-2006-4794 |
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5
allow remote attackers to inject arbitrary web script or HTML via the
query string (PATH_INFO) in (1) contact.php, (2) download.php, (3)
admin.php, (4) fpw.php, (5) news.php, (6) search.php, (7) signup.php,
(8) submitnews.php, and (9) user.php. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-4784 |
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1
and earlier might allow remote attackers to inject arbitrary web
script or HTML via unspecified parameters to (1) doc/index.php or (2)
files/index.php.
|
| CVE-2006-4771 |
Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4
allows remote attackers to inject arbitrary web script or HTML via the
nb_connecte parameter.
|
| CVE-2006-4762 |
Multiple cross-site scripting (XSS) vulnerabilities in Ykoon RssReader
allow remote attackers to inject arbitrary web script or HTML via a
web feed, as demonstrated by certain test cases of the Robert Auger
and Caleb Sima RSS and Atom feed reader test suite.
|
| CVE-2006-4761 |
Multiple cross-site scripting (XSS) vulnerabilities in Luke Hutteman
SharpReader allow remote attackers to inject arbitrary web script or
HTML via a web feed, as demonstrated by certain test cases of the
Robert Auger and Caleb Sima RSS and Atom feed reader test suite.
|
| CVE-2006-4760 |
Multiple cross-site scripting (XSS) vulnerabilities in Benjamin Pasero
and Tobias Eichert RSSOwl allow remote attackers to inject arbitrary
web script or HTML via a web feed, as demonstrated by certain test
cases of the Robert Auger and Caleb Sima RSS and Atom feed reader test
suite.
|
| CVE-2006-4755 |
Cross-site scripting (XSS) vulnerability in alpha.php in
phpMyDirectory 10.4.6 and earlier allows remote attackers to inject
arbitrary web script or HTML via the letter parameter. NOTE: the
provenance of this information is unknown; the details are obtained
from third party information.
|
| CVE-2006-4754 |
Cross-site scripting (XSS) vulnerability in index.php in PHProg before
1.1 allows remote attackers to inject arbitrary web script or HTML via
the album parameter, which is used in an opendir call. NOTE: the same
primary issue can be used for full path disclosure with an invalid
parameter that reveals the installation path in an error message.
|
| CVE-2006-4753 |
Directory traversal vulnerability in index.php in PHProg before 1.1
allows remote attackers to read arbitrary files via a .. (dot dot) in
the lang parameter.
|
| CVE-2006-4752 |
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote
attackers to obtain the installation path via a query to the engine
module, probably with an invalid action parameter.
|
| CVE-2006-4751 |
Cross-site scripting (XSS) vulnerability in index.php in Laurentiu
Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to
inject arbitrary web script or HTML via the errcode parameter.
|
| CVE-2006-4747 |
Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot
TextAds allow remote attackers to inject arbitrary web script or HTML
via (1) the id parameter in delete.php and (2) the error parameter in
error.php.
|
| CVE-2006-4742 |
Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot
PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web
script or HTML via the msg parameter.
|
| CVE-2006-4741 |
PHP remote file inclusion vulnerability in bits_listings.php in
IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute
arbitrary code via the svr_rootPhpStart parameter.
|
| CVE-2006-4739 |
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS
allow remote attackers to inject arbitrary web script or HTML, as
demonstrated via the OriginalImageData parameter to phpthumb.php.
|
| CVE-2006-4727 |
Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in
Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly
other versions before 6.3.2, allows remote attackers to inject
arbitrary web script or HTML via the (1) lineId and (2) sort
parameters.
|
| CVE-2006-4726 |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1
through 7.02 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors involving a ColdFusion error page.
|
| CVE-2006-4718 |
Multiple cross-site scripting (XSS) vulnerabilities in livre_or.php in
KorviBlog 1.3.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) prenom, (2) emailFrom, or (3) body parameters.
|
| CVE-2006-4712 |
Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6
allow remote attackers to inject arbitrary web script or HTML via
JavaScript in a content:encoded element within an item element in an
RSS feed, as demonstrated by four example content:encoded elements
that use XMLHttpRequest to read arbitrary local files, aka "Cross
Context Scripting."
|
| CVE-2006-4711 |
Multiple cross-site scripting (XSS) vulnerabilities in Sage allow
remote attackers to inject arbitrary web script or HTML via an Atom
1.0 feed, as demonstrated by certain test cases of the James M. Snell
Atom 1.0 feed reader test suite.
|
| CVE-2006-4710 |
Multiple cross-site scripting (XSS) vulnerabilities in NewsGator
FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary
web script or HTML via an Atom 1.0 feed, as demonstrated by certain
test cases of the James M. Snell Atom 1.0 feed reader test suite.
|
| CVE-2006-4708 |
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard
0.1b allow remote attackers to inject arbitrary web script or HTML via
the (1) act parameter in (a) help.php and (b) search.php, and the (2)
p parameter in report.php.
|
| CVE-2006-4707 |
Cross-site scripting (XSS) vulnerability in admin/global.php (aka the
Admin CP login form) in MyBB (aka MyBulletinBoard) 1.1.7 allows remote
attackers to inject arbitrary web script or HTML via the query string
($_SERVER[PHP_SELF]).
|
| CVE-2006-4706 |
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in
MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject
arbitrary web script or HTML via a url BBCode tag that contains a
javascript URI with an SGML numeric character reference and an
embedded space, as demonstrated using "java& #115;cript," a different
vulnerability than CVE-2006-3761.
|
| CVE-2006-4668 |
Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley
AckerTodo 4.0 allows remote attackers to inject arbitrary web script
or HTML via the task_id parameter in an edit_task command.
|
| CVE-2006-4665 |
Cross-site scripting (XSS) vulnerability in index.php in MKPortal M1.1
Rc1 allows remote attackers to inject arbitrary web script or HTML via
the ind parameter, possibly related to the PHP_SELF variable. NOTE:
Some details are obtained from third party information.
|
| CVE-2006-4660 |
Multiple cross-site scripting (XSS) vulnerabilities in the RSS Feed
module in AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll)
allow remote attackers to process arbitrary web script or HTML in the
Feeds interface context via the (1) title and (2) description elements
within an item element in an RSS feed.
|
| CVE-2006-4646 |
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto
module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto
module before pathauto_node.inc 1.14.2.1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-4634 |
Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows
remote attackers to inject arbitrary web script or HTML via the UserID
parameter, a different vector than CVE-2006-1133 and CVE-2005-2441.
|
| CVE-2006-4628 |
Cross-site scripting (XSS) vulnerability in VCD-db before 0.983 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors when handling comments.
|
| CVE-2006-4608 |
Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome
php-Revista 1.1.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) cadena parameter in busqueda.php and the
(2) email parameter in lista.php.
|
| CVE-2006-4607 |
admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote
attackers to bypass authentication controls by setting the ID_ADMIN
and SUPER_ADMIN parameters to 1.
|
| CVE-2006-4606 |
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista
1.1.2 allow remote attackers to execute arbitrary SQL commands via the
(1) id_temas parameter in busqueda_tema.php, the (2) cadena parameter
in busqueda.php, the (3) id_autor parameter in autor.php, the (4)
email parameter in lista.php, and the (5) id_articulo parameter in
articulo.php.
|
| CVE-2006-4605 |
PHP remote file inclusion vulnerability in index.php in Longino Jacome
php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP
code via the adodb parameter.
|
| CVE-2006-4593 |
Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1
and earlier allows remote attackers to inject arbitrary web script or
HTML via the page parameter.
|
| CVE-2006-4587 |
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM
4.2.4, and possibly earlier, allow remote attackers to inject
arbitrary web script or HTML via the (1) description parameter in
unspecified modules or the (2) solution parameter in the HelpDesk
module.
|
| CVE-2006-4577 |
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e
allow remote attackers to inject arbitrary web script or HTML via Javascript
events in the (1) email, (2) websites, and (3) groupAddName parameters in (a)
save.php; the (4) errorMsg parameter in (b) index.php; and the (5) goTo and
(6) search parameters in (c) search.php.
|
| CVE-2006-4576 |
Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows
remote attackers to inject arbitrary web script or HTML by uploading the HTML
file with a GIF or JPG extension, which is rendered by Internet Explorer.
|
| CVE-2006-4569 |
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked
popups" display in the context of the Location bar instead of the
subframe from which the popup originated, which might make it easier
for remote user-assisted attackers to conduct cross-site scripting
(XSS) attacks.
|
| CVE-2006-4563 |
Cross-site scripting (XSS) vulnerability in the MyHeadlines before
4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary
web script or HTML via the myh_op parameter to modules.php.
|
| CVE-2006-4552 |
Cross-site scripting (XSS) vulnerability in CHXO Feedsplitter
2006-01-21 allows remote attackers to inject arbitrary web script or
HTML via the RSS feed.
|
| CVE-2006-4543 |
Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34
allows remote attackers to inject arbitrary web script or HTML via the
(1) game parameter in players mode, the (2) weapon parameter in
weaponinfo mode, the (3) st parameter in search mode, the (4) action
parameter in actioninfo mode, and the (5) map parameter in mapinfo
mode.
|
| CVE-2006-4542 |
Webmin before 1.296 and Usermin before 1.226 do not properly handle a
URL with a null ("%00") character, which allows remote attackers to
conduct cross-site scripting (XSS), read CGI program source code, list
directories, and possibly execute programs.
|
| CVE-2006-4540 |
Cross-site scripting (XSS) vulnerability in learncenter.asp in
Learn.com LearnCenter allows remote attackers to inject arbitrary web
script or HTML via the id parameter.
|
| CVE-2006-4530 |
Direct static code injection vulnerability in include/change.php in
membrepass 1.5 allows remote attackers to execute arbitrary PHP code
via the aifon parameter, which is injected into include/variable.php.
|
| CVE-2006-4529 |
SQL injection vulnerability in recherchemembre.php in membrepass 1.5.
allows remote attackers to execute arbitrary SQL commands via the
recherche parameter.
|
| CVE-2006-4528 |
Multiple cross-site scripting (XSS) vulnerabilities in membrepass 1.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) recherche parameter in recherchemembre.php and the (2) email
parameter in test.php.
|
| CVE-2006-4525 |
Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and
earlier, when register_globals is enabled, allows remote attackers to
inject arbitrary web script or HTML via the links array.
|
| CVE-2006-4500 |
Cross-site scripting (XSS) vulnerability in index.php in ezPortal/ztml
CMS 1.0 allows remote attackers to inject arbitrary web script or HTML
via the (1) about, (2) again, (3) lastname, (4) email, (5) password,
(6) album, (7) id, (8) table, (9) desc, (10) doc, (11) mname, (12)
max, (13) htpl, (14) pheader, and possibly other parameters.
|
| CVE-2006-4496 |
Cross-site scripting (XSS) vulnerability in comments.php in IwebNegar
1.1 allows remote attackers to inject arbitrary web script or HTML via
the comment parameter.
|
| CVE-2006-4479 |
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual
Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary
web script or HTML via the subgroupname parameter.
|
| CVE-2006-4478 |
SQL injection vulnerability in headeruserdata.php in Visual Shapers
ezContents 2.0.3 allows remote attackers to execute arbitrary SQL
commands via the groupname parameter.
|
| CVE-2006-4477 |
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers
ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code
via an empty GLOBALS[rootdp] parameter and an ftps URL in the (1)
GLOBALS[admin_home] parameter in (a) diary/event_list.php, (b)
gallery/gallery_summary.php, (c) guestbook/showguestbook.php, (d)
links/showlinks.php, and (e) reviews/review_summary.php; and the (2)
GLOBALS[language_home] parameter in (f) calendar/calendar.php, (g)
news/shownews.php, (h) poll/showpoll.php, (i) search/search.php, (j)
toprated/toprated.php, and (k) whatsnew/whatsnew.php.
|
| CVE-2006-4474 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.0.11 allow remote attackers to inject arbitrary web script or HTML
via unspecified parameters in (1) Admin Module Manager, (2) Admin
Help, and (3) Search.
|
| CVE-2006-4460 |
Cross-site scripting (XSS) vulnerability in PHP iAddressBook before
0.96 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-4454 |
Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats
1.34 allows remote attackers to inject arbitrary web script or HTML
via the q parameter.
|
| CVE-2006-4453 |
Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors involving "table markups".
|
| CVE-2006-4449 |
Cross-site scripting (XSS) vulnerability in attachment.php in
MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote
attackers to inject arbitrary web script or HTML via a GIF image that
contains URL-encoded Javascript, which is rendered by Internet
Explorer.
|
| CVE-2006-4442 |
Cross-site scripting (XSS) vulnerability in PHP iAddressBook before
0.95 allows remote attackers to inject arbitrary web script or HTML
via the cat_name parameter, related to adding a category. (categories
field). NOTE: some details are obtained from third party information.
|
| CVE-2006-4421 |
Cross-site scripting (XSS) vulnerability in
template/default/thanks_comment.php in Yet Another PHP Image Gallery
(YaPIG) 0.95b allows remote attackers to inject arbitrary web script
or HTML via the D_REFRESH_URL parameter.
|
| CVE-2006-4377 |
Multiple SQL injection vulnerabilities in Guder und Koch
Netzwerktechnik Eichhorn Portal allow remote attackers to execute
arbitrary SQL commands via unspecified vectors, possibly including the
(1) profil_nr and (2) sprache parameters in the main portion of the
portal, the (3) suchstring field in suchForm in the main portion of
the portal, the (4) GaleryKey and (5) Breadcrumbs parameters in the
gallerie module, and the (6) GGBNSaction parameter in the ggbns
module.
|
| CVE-2006-4376 |
Multiple cross-site scripting (XSS) vulnerabilities in Guder und Koch
Netzwerktechnik Eichhorn Portal allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors, possibly
including the (1) profil_nr and (2) sprache parameters in the main
portion of the portal, the (3) suchstring field in suchForm in the
main portion of the portal, the (4) GaleryKey and (5) Breadcrumbs
parameters in the gallerie module, and the (6) GGBNSaction parameter
in the ggbns module.
|
| CVE-2006-4362 |
Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid
Mail allows remote attackers to inject arbitrary web script or HTML
via the ps parameter.
|
| CVE-2006-4361 |
Multiple cross-site scripting (XSS) vulnerabilities in
jobseekers/forgot.php in Diesel Job Site allow remote attackers to
inject arbitrary web script or HTML via the (1) uname or (2) SEmail
parameters.
|
| CVE-2006-4360 |
Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal
before file.module 1.37.2.4 (20060812) allows remote authenticated
users with the "create products" permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2006-4358 |
Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay
allows remote attackers to inject arbitrary web script or HTML via the
read parameter.
|
| CVE-2006-4355 |
Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module
(easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-4351 |
Cross-site scripting (XSS) vulnerability in index.php in OneOrZero
1.6.4.1 allows remote attackers to inject arbitrary web script or HTML
via the id parameter.
|
| CVE-2006-4350 |
SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows
remote attackers to execute arbitrary SQL commands via the id
parameter.
|
| CVE-2006-4328 |
SQL injection vulnerability in admin.php in CloudNine Interactive
Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows
remote attackers to execute arbitrary SQL commands via the nick
parameter.
|
| CVE-2006-4327 |
Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in
CloudNine Interactive Links Manager 2006-06-12 allow remote attackers
to inject arbitrary web script or HTML via the (1) title, (2)
description, or (3) keywords parameters.
|
| CVE-2006-4325 |
Cross-site scripting (XSS) vulnerability in gbook.php in Doika
guestbook 2.5, and possibly earlier, allows remote attackers to inject
arbitrary web script or HTML via the page parameter.
|
| CVE-2006-4324 |
Cross-site scripting (XSS) vulnerability in add_url2.php in
CityForFree indexcity 1.0 allows remote attackers to inject arbitrary
web script or HTML via the url parameter.
|
| CVE-2006-4323 |
SQL injection vulnerability in list.php in CityForFree indexcity 1.0,
when magic_quotes_gpc is disabled, allows remote attackers to execute
arbitrary SQL commands via the cate_id parameter.
|
| CVE-2006-4317 |
Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab
Burning Board (WBB) 2.3.5 allows remote attackers to inject arbitrary
web script or HTML via a GIF image that contains URL-encoded
Javascript.
|
| CVE-2006-4308 |
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard
Learning System 6, Blackboard Learning and Community Portal Suite
6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject
arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript,
and (3) malformed javascript URIs in various HTML tags when posting to
the Discussion Board.
|
| CVE-2006-4299 |
Cross-site scripting (XSS) vulnerability in tiki-searchindex.php in
TikiWiki 1.9.4 allows remote attackers to inject arbitrary web script
or HTML via the highlight parameter. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-4295 |
Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda
ActiveScan 5.53.00 allows remote attackers to inject arbitrary web
script or HTML via the email parameter.
|
| CVE-2006-4293 |
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow
remote attackers to inject arbitrary web script or HTML via the (1)
dir parameter in dohtaccess.html, or the (2) file parameter in (a)
editit.html or (b) showfile.html.
|
| CVE-2006-4273 |
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4
and 3.6.0 allows remote attackers to inject arbitrary web script or
HTML by uploading an attachment with a .pdf extension that contains
JavaScript, which is processed as script by Microsoft Internet
Explorer 6.
|
| CVE-2006-4268 |
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) file, (2) x, and (3) y parameters in (a)
admin/filemanager/preview.php; and the (4) email parameter in (b)
admin/login.php.
|
| CVE-2006-4259 |
Cross-site scripting (XSS) vulnerability in index.php in Fotopholder
1.8 allows remote attackers to inject arbitrary web script or HTML via
the path parameter. NOTE: this might be resultant from a directory
traversal vulnerability.
|
| CVE-2006-4256 |
index.php in Horde Application Framework before 3.1.2 allows remote
attackers to include web pages from other sites, which could be useful
for phishing attacks, via a URL in the url parameter, aka "cross-site
referencing." NOTE: some sources have referred to this issue as XSS,
but it is different than classic XSS.
|
| CVE-2006-4255 |
Cross-site scripting (XSS) vulnerability in horde/imp/search.php in
Horde IMP H3 before 4.1.3 allows remote attackers to include arbitrary
web script or HTML via multiple unspecified vectors related to folder
names, as injected into the vfolder_label form field in the IMP search
screen.
|
| CVE-2006-4224 |
Cross-site scripting (XSS) vulnerability in calendar.php in Virtual
War (VWar) 1.5.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the year parameter. NOTE: The page
parameter vector is covered by CVE-2006-4009.
|
| CVE-2006-4220 |
Multiple cross-site scripting (XSS) vulnerabilities in webacc in
Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow
remote attackers to inject arbitrary web script or HTML via the (1)
User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang
parameters.
|
| CVE-2006-4211 |
Cross-site scripting (XSS) vulnerability in b0zz and Chris Vincent Owl
Intranet Engine 0.90 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-4206 |
Cross-site scripting (XSS) vulnerability in calendar.asp in
ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly
other versions before October 15, 2006, allows remote attackers to
inject arbitrary web script or HTML via the calendarID parameter.
|
| CVE-2006-4199 |
Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83
and earlier allows remote attackers to inject arbitrary web script or
HTML via the URL, which is not properly sanitized before it is
returned in an error page, a different vulnerability than
CVE-2004-1512.
|
| CVE-2006-4165 |
Cross-site scripting (XSS) vulnerability in NetCommons 1.0.8 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-4162 |
Cross-site scripting (XSS) vulnerability in Dragonfly CMS 9.0.6.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the search field.
|
| CVE-2006-4157 |
Cross-site scripting (XSS) vulnerability in index.php in Yet another
Bulletin Board (YaBB) allows remote attackers to inject arbitrary web
script or HTML via the categories parameter.
|
| CVE-2006-4133 |
Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40
and earlier, and 7.00 and earlier, allows remote attackers to cause a
denial of service (crash) or execute arbitrary code via an HTTP
request with an ADM:GETLOGFILE command and a long portwatcher
argument, which triggers the overflow during error message
construction when the _snprintf function returns a negative value that
is used in a memcpy operation.
|
| CVE-2006-4120 |
Cross-site scripting (XSS) vulnerability in the Recipe module
(recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2006-4109 |
Cross-site scripting (XSS) vulnerability in Bibliography
(biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before
revision 1.13.2.5 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-4106 |
Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3
allows remote attackers to inject arbitrary web script or HTML via a
comment title.
|
| CVE-2006-4105 |
Cross-site scripting (XSS) vulnerability in Fill Threads Database
(FTD) 3.7.3 allows remote attackers to inject arbitrary web script or
HTML via the (1) search field or (2) an e-mail message.
|
| CVE-2006-4104 |
Cross-site scripting (XSS) vulnerability in admin.cgi in
mojoscripts.com mojoGallery allows remote attackers to inject
arbitrary web script or HTML via "password input."
|
| CVE-2006-4091 |
Multiple cross-site scripting (XSS) vulnerabilities in Archangel
Management Archangel Weblog 0.90.02 allow remote attackers to inject
arbitrary web script or HTML via the (1) Name or (2) Comment section.
|
| CVE-2006-4090 |
Cross-site scripting (XSS) vulnerability in Webligo BlogHoster 2.2
allows remote attackers to inject arbitrary web script or HTML via the
"From: part of the comment post," probably involving the nickname
parameter to previewcomment.php.
|
| CVE-2006-4088 |
Multiple cross-site scripting (XSS) vulnerabilities in CivicSpace
0.8.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) Subject, (2) Comment, and (3) Add new comment sections.
|
| CVE-2006-4087 |
Cross-site scripting (XSS) vulnerability in admin.cgi in
mojoscripts.com mojoGallery allows remote attackers to inject
arbitrary web script or HTML via the username parameter. NOTE: the
provenance of this information is unknown; the details are obtained
from third party information.
|
| CVE-2006-4086 |
Cross-site scripting (XSS) vulnerability in index.php in Elaine Aquino
Online Zone Journals (OZJournals) 1.5 allows remote attackers to
inject arbitrary web script or HTML via the keywords parameter. NOTE:
the provenance of this information is unknown; the details are
obtained from third party information.
|
| CVE-2006-4080 |
DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5
hash of a password, which allows remote attackers to gain privileges
by sniffing or cross-site scripting (XSS) and conduct password
guessing attacks.
|
| CVE-2006-4079 |
Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB
1.08, and possibly earlier, allows remote attackers to inject
arbitrary web script or HTML via the subject parameter (aka the topic
title field).
|
| CVE-2006-4069 |
Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino
Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject
arbitrary web script or HTML via the (1) m and (2) c parameters in
index.php, (3) a search action, and (4) a "submit comment" action.
|
| CVE-2006-4067 |
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in
CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary
web script or HTML via the URL, which is reflected back in a 404 ("Not
Found") error page. NOTE: some of these details are obtained from
third party information.
|
| CVE-2006-4058 |
Cross-site scripting (XSS) vulnerability in archive.php in Simplog
0.9.3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the keyw parameter when performing a search. NOTE:
some details are obtained from third party information.
|
| CVE-2006-4038 |
Multiple cross-site scripting (XSS) vulnerabilities in eintragen.php
in GaesteChaos 0.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) gastname or (2) gastwohnort
parameters.
|
| CVE-2006-4017 |
Cross-site scripting (XSS) vulnerability in the search module in Inter
Network Marketing (INM) CMS G3 allows remote attackers to inject
arbitrary web script or HTML via the search_string parameter.
|
| CVE-2006-4016 |
Cross-site scripting (XSS) vulnerability in /toendaCMS in toendaCMS
stable 1.0.3 and earlier, and unstable 1.1 and earlier, allows remote
attackers to inject arbitrary web script or HTML via the s parameter.
|
| CVE-2006-4010 |
SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and
earlier allows remote attackers to execute arbitrary SQL commands via
the page parameter. NOTE: other vectors are covered by CVE-2006-3139.
|
| CVE-2006-4009 |
Cross-site scripting (XSS) vulnerability in war.php in Virtual War
(Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the page parameter.
|
| CVE-2006-4002 |
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6
before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject
arbitrary web script or HTML via the msg parameter. NOTE: portions of
these details are obtained from third party information.
|
| CVE-2006-3974 |
Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com
OfficeConnect Secure Router with firmware 1.04-168 allows remote
attackers to inject arbitrary web script or HTML via the tk parameter.
|
| CVE-2006-3971 |
Cross-site scripting (XSS) vulnerability in
visitor/livesupport/chat.php in Scott Weedon Ajax Chat, possibly 0.1,
allows remote attackers to inject arbitrary web script or HTML via the
userid parameter.
|
| CVE-2006-3958 |
Multiple unspecified cross-site scripting (XSS) vulnerabilities in
Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script
or HTML via (1) the Search Tasks system, or authenticated users via
(2) the Edit Task system, (3) the back-end Category Editor system, and
(4) "Pages that display task status, email addresses, URL, customer,
and project information."
|
| CVE-2006-3956 |
Multiple cross-site scripting (XSS) vulnerabilities in contact.php in
Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to
inject arbitrary web script or HTML via the (1) Name, (2)
AccountUsername and (3) Message parameters.
|
| CVE-2006-3954 |
Directory traversal vulnerability in usercp.php in MyBB (aka
MyBulletinBoard) 1.x allows remote attackers to read arbitrary files
via a .. (dot dot) in the gallery parameter in a (1) avatar or (2)
do_avatar action.
|
| CVE-2006-3953 |
Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka
MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web
script or HTML via the gallery parameter.
|
| CVE-2006-3948 |
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke
INP allows remote attackers to inject arbitrary web script or HTML via
the query parameter.
|
| CVE-2006-3933 |
Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before
6.2.2 allows remote authenticated users to inject arbitrary web script
or HTML via the message body.
|
| CVE-2006-3929 |
Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin
script on the Zyxel Prestige 660H-61 ADSL Router running firmware
3.40(PT.0)b32 allows remote attackers to inject arbitrary web script
or HTML via hex-encoded values in the a parameter.
|
| CVE-2006-3927 |
Cross-site scripting (XSS) vulnerability in auctionsearch.php in
PhpProBid 5.24 allows remote attackers to inject arbitrary web script
or HTML via the advsrc parameter.
|
| CVE-2006-3926 |
Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote
attackers to execute arbitrary SQL commands via the (1) view or (2)
start parameters to (a) viewfeedback.php or the (3) orderType
parameter to (b) categories.php.
|
| CVE-2006-3924 |
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos before
1.6.5 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-3923 |
Cross-site scripting (XSS) vulnerability in add.php in Fire-Mouse
Toplist 1.1 and earlier, when register_globals is enabled, allows
remote attackers to inject arbitrary web script or HTML via the
Seitenname parameter.
|
| CVE-2006-3918 |
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1
before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0
before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect
header from an HTTP request when it is reflected back in an error
message, which might allow cross-site scripting (XSS) style attacks
using web client components that can send arbitrary headers in
requests, as demonstrated using a Flash SWF file.
|
| CVE-2006-3916 |
Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka
Solucija News) 1.4 allows remote attackers to inject arbitrary web
script or HTML via the search_query parameter.
|
| CVE-2006-3914 |
Cross-site scripting (XSS) vulnerability in Blackboard Academic Suite
6.2.3.23 allows remote authenticated users to inject arbitrary HTML or
web script by bypassing client-side validation through disabling
JavaScript when submitting an essay response, which has no server-side
validation before being viewed via "View Attempt Details" in the
Gradebook.
|
| CVE-2006-3909 |
Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads
allows remote attackers to inject arbitrary web script or HTML via the
week parameter.
|
| CVE-2006-3903 |
CRLF injection vulnerability in (1) index.php and (2) admin.php in
myWebland MyBloggie 2.1.3 allows remote attackers to hijack sessions
and conduct cross-site scripting (XSS) attacks via a cookie.
|
| CVE-2006-3902 |
Cross-site scripting (XSS) vulnerability in index.php in phpFaber
TopSites 2.0.9 allows remote attackers to inject arbitrary web script
or HTML via the i_cat parameter. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-3900 |
Cross-site scripting (XSS) vulnerability in guestbook.php in TP-Book
1.00 and earlier allows remote attackers to inject arbitrary web
script or HTML via the name parameter.
|
| CVE-2006-3886 |
SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier
allows remote attackers to execute arbitrary SQL commands via the page
parameter in a viewgallery action in a request for the top-level URI.
NOTE: the start parameter/search action is already covered by
CVE-2006-1807, and the show parameter/top action is already covered by
CVE-2006-1360.
|
| CVE-2006-3883 |
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish
LinksCaffe 3.0 allow remote attackers to inject arbitrary web script
or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the
newdays parameter in (b) links.php; and the (3) tableborder, (4)
menucolor, (5) textcolor, and (6) bodycolor parameters in (c)
menu.inc.php.
|
| CVE-2006-3882 |
Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain
configuration information via a direct request to phpinfo.php, which
calls the phpinfo function.
|
| CVE-2006-3881 |
Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the id parameter in a request for the top-level URI. NOTE: the id
parameter in index.php, and the type and show parameters in a top
action, are already covered by CVE-2006-1349; and the term parameter
in a search action is already covered by CVE-2006-1806.
|
| CVE-2006-3852 |
Cross-site scripting (XSS) vulnerability in index.php in Micro
GuestBook allows remote attackers to execute arbitrary SQL commands
via the (1) name or (2) comment ("text") fields.
|
| CVE-2006-3848 |
Cross-site scripting (XSS) vulnerability in CGI wrapper for IP
Calculator (IPCalc) 0.40 allows remote attackers to inject arbitrary
web script or HTML via the URI (REQUEST_URI environment variable),
which is used in the actionurl variable.
|
| CVE-2006-3842 |
Cross-site scripting (XSS) vulnerability in Zoho Virtual Office 3.2
Build 3210 allows remote attackers to execute arbitrary web script or
HTML via an HTML message.
|
| CVE-2006-3841 |
Cross-site scripting (XSS) vulnerability in WebScarab before
20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or
Konqueror 3.5.3, allows remote attackers to inject arbitrary web
script or HTML via the URL, which is not sanitized before being
returned in an error message when WebScarab is not able to access the
URL.
|
| CVE-2006-3826 |
Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh
boastMachine (formerly bMachine) 3.1 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1)
user_login, (2) full_name, and (3) URL parameters in register.php; and
allow remote authenticated administrators to inject arbitrary web
script or HTML via the (4) cat_list and (5) key parameters in a
certain portion of the admin interface.
|
| CVE-2006-3821 |
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.3
allow remote attackers to inject arbitrary web script or HTML via the
(1) lang parameter in (a) index_list.php and (2) year, (3) month, and
(4) day parameter in (b) registration.php.
|
| CVE-2006-3820 |
Cross-site scripting (XSS) vulnerability in loudblog/index.php in
Loudblog before 0.5 allows remote attackers to inject arbitrary web
script or HTML via the page parameter.
|
| CVE-2006-3818 |
Cross-site scripting (XSS) vulnerability in the login page in Novell
GroupWise WebAccess 6.5 before 20060721 and WebAccess 7 before
20060727 allows remote attackers to inject arbitrary web script or
HTML via the GWAP.version parameter.
|
| CVE-2006-3817 |
Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess
6.5 and 7 before 20060727 allows remote attackers to inject arbitrary
web script or HTML via an encoded SCRIPT element in an e-mail message
with the UTF-7 character set, as demonstrated by the
"+ADw-SCRIPT+AD4-" sequence.
|
| CVE-2006-3810 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before
1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows
remote attackers to inject arbitrary web script or HTML via the
XPCNativeWrapper(window).Function construct.
|
| CVE-2006-3802 |
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and
SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM
methods from objects in another domain and conduct cross-site
scripting (XSS) attacks using DOM methods of the top-level object.
|
| CVE-2006-3800 |
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce
Shopping Cart allows remote attackers to inject arbitrary web script
or HTML via the "new review" text box.
|
| CVE-2006-3795 |
Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before
1.08 allow remote attackers to inject arbitrary web script or HTML via
the (1) membercookie cookie in header.php and the (2) redirect
parameter in misc.php.
|
| CVE-2006-3769 |
Multiple cross-site scripting (XSS) vulnerabilities in Top XL 1.1 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) pass and (2) pass2 parameters in (a) add.php or the (3) id
parameter in (b) members/index.php.
|
| CVE-2006-3767 |
Cross-site scripting (XSS) vulnerability in showprofile.php in
Darren's $5 Script Archive osDate 1.1.7 and earlier allows remote
attackers to inject arbitrary web script or HTML via the onerror
attribute in an HTML IMG tag with a non-existent source file in
txtcomment parameter, which is used when posting a comment.
|
| CVE-2006-3765 |
Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher
Webdesign hwdeGUEST 2.1.1 and earlier allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors, as demonstrated
by the "name input" field in new_entry.php.
|
| CVE-2006-3761 |
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in
MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote
attackers to inject arbitrary web script or HTML via a javascript URI
with an SGML numeric character reference in the url BBCode tag, as
demonstrated using "javascript".
|
| CVE-2006-3756 |
Cross-site scripting (XSS) vulnerability in Geeklog 1.4.0sr4 and
earlier, and 1.3.11sr6 and earlier, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors when validating
comments in (1) lib-comment.php (1.4.0sr4) or (2) comment.php
(0.3.11sr6).
|
| CVE-2006-3737 |
Cross-site scripting (XSS) vulnerability in
filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0
and earlier allows remote authenticated users to inject arbitrary web
script or HTML via the file parameter.
|
| CVE-2006-3695 |
Trac before 0.9.6 does not disable the "raw" or "include" commands
when providing untrusted users with restructured text
(reStructuredText) functionality from docutils, which allows remote
attackers to read arbitrary files, perform cross-site scripting (XSS)
attacks, or cause a denial of service via unspecified vectors. NOTE:
this might be related to CVE-2006-3458.
|
| CVE-2006-3681 |
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in
AWStats 6.5 build 1.857 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) refererpagesfilter, (2)
refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter,
or (6) hostfilterex parameters, a different set of vectors than
CVE-2006-1945.
|
| CVE-2006-3680 |
Cross-site scripting (XSS) vulnerability in photocycle in Photocycle
1.0 allows remote attackers to inject arbitrary web script or HTML via
the phpage parameter.
|
| CVE-2006-3665 |
SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows
remote attackers to hijack cookies in src/redirect.php via unknown
vectors. NOTE: while "cookie theft" is frequently associated with XSS,
the vendor disclosure is too vague to be certain of this.
|
| CVE-2006-3661 |
Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews
1.4.5 allows remote attackers to inject arbitrary web script or HTML
via unknown vectors. NOTE: the provenance of this information is
unknown; the details are obtained from third party information.
|
| CVE-2006-3643 |
Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and
6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded
resource files" in the Microsoft Management Console (MMC) library,
which allows remote authenticated users to execute arbitrary commands,
aka "MMC Redirect Cross-Site Scripting Vulnerability."
|
| CVE-2006-3636 |
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before
2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2006-3624 |
Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8
allow remote attackers to inject arbitrary web script or HTML via the
url parameter to (1) player.php or (2) popup.php.
|
| CVE-2006-3622 |
The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to
obtain sensitive information via a ' (single quote) in the p
parameter, which displays the path in an error message. NOTE: it is
not clear whether this is SQL injection or a forced SQL error.
|
| CVE-2006-3621 |
SQL injection vulnerability in the showtopic module in Koobi Pro CMS
5.6 allows remote attackers to execute arbitrary SQL commands via the
toid parameter.
|
| CVE-2006-3620 |
Cross-site scripting (XSS) vulnerability in the showtopic module in
Koobi Pro CMS 5.6 allows remote attackers to inject arbitrary web
script or HTML via the toid parameter.
|
| CVE-2006-3618 |
SQL injection vulnerability in pblguestbook.php in Pixelated By Lev
(PBL) Guestbook 1.32 and earlier allows remote attackers to execute
arbitrary SQL commands via the (1) name, (2) email, (3) website, (4)
comments, (5) rate, and (6) private parameters.
|
| CVE-2006-3617 |
Cross-site scripting (XSS) vulnerability in pblguestbook.php in
Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote
attackers to inject arbitrary web script or HTML via the (1) name, (2)
message (aka comments), (3) website, and (4) email parameters, which
bypasses XSS protection mechanisms that check for SCRIPT tags but not
others, as demonstrated by a javascript URI in an onMouseOver
attribute and the src attribute in an iframe tag. NOTE: some vectors
might overlap CVE-2006-2975, although the use of alternate
manipulations makes it unclear.
|
| CVE-2006-3616 |
Multiple cross-site scripting (XSS) vulnerabilities in Carbonize
Lazarus Guestbook 1.6 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) the show parameter in
codes-english.php and (2) the img parameter in picture.php, after the
name of an existing file.
|
| CVE-2006-3613 |
Multiple cross-site scripting (XSS) vulnerabilities in Chamberland
Technology ezWaiter 3.0 Online and possibly Enterprise Software (aka
enterprise edition) allow remote attackers to inject arbitrary web
script or HTML via the (1) itemfor (aka "Who is this item for?") and
(2) special (aka "Special Instructions") parameters to item.php, which
is accessed from showorder.php, or (3) unspecified parameters to the
login form at login.php.
|
| CVE-2006-3612 |
Cross-site scripting (XSS) vulnerability in Phorum 5.1.14 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-3609 |
Cross-site scripting (XSS) vulnerability in index.php in Orbitcoders
OrbitMATRIX 1.0 allows remote attackers to inject arbitrary web script
or HTML via the page_name parameter with an IMG tag containing a
javascript URI in the SRC attribute.
|
| CVE-2006-3607 |
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner
Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote
attackers to inject arbitrary web script or HTML via (1) the city
parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b)
lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.
|
| CVE-2006-3604 |
Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and
earlier allows remote attackers to bypass access restrictions for (1)
admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and
encoded / (%2f) sequence in the URL.
|
| CVE-2006-3603 |
Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH
Network Camera 3.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the URL.
|
| CVE-2006-3585 |
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS 2.1
SR1 allow remote attackers to inject arbitrary web script or HTML via
the (1) login parameter in admin/cms/index.php, (2) unspecified
parameters in the "Supply news" page in formmail.php, (3) the URL in
the "Site statistics" page, and the (5) query_string parameter when
performing a search.
|
| CVE-2006-3579 |
Cross-site scripting (XSS) vulnerability in Fujitsu ServerView 2.50 up
to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-3574 |
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi
Groupmax Collaboration Portal and Web Client before 07-20-/D, and
uCosminexus Collaboration Portal and Forum/File Sharing before
06-20-/C, allow remote attackers to "execute malicious scripts" via
unknown vectors (aka HS06-014-01).
|
| CVE-2006-3571 |
Multiple cross-site scripting (XSS) vulnerabilities in
interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) titel or (2) ausgabe
parameters.
|
| CVE-2006-3570 |
Cross-site scripting (XSS) vulnerability in the webform module in
Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-3568 |
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php
in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow
remote attackers to inject arbitrary web script or HTML via the (1)
first_name, (2) last_name, or (3) nickname parameters.
|
| CVE-2006-3567 |
Cross-site scripting (XSS) vulnerability in the web administration
interface logging feature in Juniper Networks (Redline) DX 5.1.x, and
possibly earlier versions, allows remote attackers to inject arbitrary
web script or HTML via the username login field.
|
| CVE-2006-3564 |
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the email, (2) cond, or (3) name parameters to (a)
addressbook.view.php, (4) the daysprune parameter to (b) index.php,
(5) the data[to] parameter to (c) compose.email.php, and (6) the
markas parameter to (d) read.markas.php.
|
| CVE-2006-3563 |
Cross-site scripting (XSS) vulnerability in gallery/thumb.php in
Winged Gallery 1.0 allows remote attackers to inject arbitrary web
script or HTML via the image parameter.
|
| CVE-2006-3559 |
Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62
allow remote attackers to execute arbitrary SQL commands and delete
all shoutbox messages via the (1) name and (2) pesan parameters.
|
| CVE-2006-3558 |
Multiple cross-site scripting (XSS) vulnerabilities in Arif Supriyanto
auraCMS 1.62 allow remote attackers to inject arbitrary web script or
HTML via (1) the judul_artikel parameter in teman.php and (2) the
title of an article sent to admin, which is displayed when
unauthenticated users visit index.php.
|
| CVE-2006-3555 |
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in
PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary
web script or HTML by using edit_profile.php to upload a (1) avatar or
(2) forum image attachment that has a .gif or .jpg extension, and
begins with a GIF header followed by JavaScript code, which is
executed by Internet Explorer.
|
| CVE-2006-3550 |
Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks
FirePass 4100 5.x allow remote attackers to inject arbitrary web
script or HTML via unspecified "writable form fields and hidden
fields," including "authentication frontends."
|
| CVE-2006-3548 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde
Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1
allow remote attackers to inject arbitrary web script or HTML via a
(1) javascript URI or an external (2) http, (3) https, or (4) ftp URI
in the url parameter in services/go.php (aka the dereferrer), (5) a
javascript URI in the module parameter in services/help (aka the help
viewer), and (6) the name parameter in services/problem.php (aka the
problem reporting screen).
|
| CVE-2006-3542 |
Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown
Shopping Cart 0.9 allow remote attackers to inject arbitrary web
script or HTML via the (1) shop name field in (a) editshop.php, (b)
edititem.php, and (c) index.php; and via the (2) item field in
editshop.php and edititem.php.
|
| CVE-2006-3539 |
Multiple cross-site scripting (XSS) vulnerabilities in DKScript.com
Dragon's Kingdom Script 1.0 allow remote attackers to inject arbitrary
web script or HTML via a javascript URI in the SRC attribute of an IMG
element in the (1) Subject and (2) Message fields in a do=write (aka
Send Mail Message) action in gamemail.php; the (3) Gender, (4)
Country/Location, (5) MSN Messenger, (6) AOL Instant Messenger, (7)
Yahoo Instant Messenger, and (8) ICQ fields in a do=onlinechar (aka
Edit your Profile) action in index.php, as accessed by dk.php; a
javascript URI in the SRC attribute of an IMG element in the (9) Title
and (10) Message fields in a do=new (aka Create Thread) action in
general.php; and a javascript URI in the SRC attribute of an IMG
element in unspecified fields in (11) other Forum posts and (12) Forum
replies.
|
| CVE-2006-3538 |
Multiple cross-site scripting (XSS) vulnerabilities in demo.php in
BeatificFaith Eprayer Alpha allow remote attackers to inject arbitrary
web script or HTML via the SRC attribute of a SCRIPT element in the
(1) "Your name" field and (2) "Enter Prayer Request here" field.
|
| CVE-2006-3533 |
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2
and earlier, when register_globals is enabled, allow remote attackers
to inject arbitrary web script or HTML via the (1) fg, (2) line1, (3)
line2, (4) bg, (5) c1, (6) c2, (7) c3, and (8) c4 parameters in (a)
includes/blogroll.php; (9) name and (10) js_name parameters in (b)
includes/editor/edit_menu.php; and, even if register_globals is not
enabled, the (11) h and (12) w parameters in (c) includes/photo.php.
|
| CVE-2006-3526 |
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php
in Sport-slo Advanced Guestbook 1.0 allow remote attackers to inject
arbitrary web script or HTML via (1) name and (2) form parameters.
|
| CVE-2006-3522 |
Cross-site scripting (XSS) vulnerability in Clearswift MIMEsweeper for
Web before 5.1.15 Hotfix allows remote attackers to inject arbitrary
web script or HTML via the URL, which is reflected back in an error
message when trying to access a blocked web site.
|
| CVE-2006-3521 |
Multiple cross-site scripting (XSS) vulnerabilities in
index/siteforge-bugs-action/proj.siteforge in SiteForge Collaborative
Development Platform 1.0.4 and earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) _status, (2) _extra1,
(3) _extra2, or (4) _extra3 parameters.
|
| CVE-2006-3519 |
Multiple cross-site scripting (XSS) vulnerabilities in The Banner
Engine (tbe) 4.0 allow remote attackers to execute arbitrary web
script or HTML via the (1) text parameter in a search action to (a)
top.php, and the (2) adminpass or (3) adminlogin parameter to (b)
signup.php.
|
| CVE-2006-3514 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/actions.php in PHP-Blogger 2.2.5, and possibly earlier versions,
allow remote attackers to execute arbitrary web script or HTML via the
(1) name, (2) title, (3) news, (4) description, and (5) sitename
parameters.
|
| CVE-2006-3494 |
Multiple cross-site scripting (XSS) vulnerabilities in Buddy Zone
1.0.1 allow remote attackers to inject arbitrary HTML and web script
via the (1) cat_id parameter to (a) view_classifieds.php; (2) id
parameter in (b) view_ad.php; (3) event_id parameter in (c)
view_event.php, (d) delete_event.php, and (e) edit_event.php; and (4)
group_id in (f) view_group.php.
|
| CVE-2006-3484 |
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before
1.5.3 allow remote attackers to inject arbitrary web script or HTML
via the (1) show_courses or (2) current_cat parameters to (a)
admin/create_course.php, show_courses parameter to (b)
users/create_course.php, (3) p parameter to (c) documentation/admin/,
(4) forgot parameter to (d) password_reminder.php, (5) cat parameter
to (e) users/browse.php, or the (6) submit parameter to
admin/fix_content.php.
|
| CVE-2006-3482 |
Cross-site scripting (XSS) vulnerability in maillist.php in
PHPMailList 1.8.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the email parameter.
|
| CVE-2006-3480 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.0.10 allow remote attackers to inject arbitrary web script or HTML
via unspecified parameters involving the (1) getUserStateFromRequest
function, and the (2) SEF and (3) com_messages modules.
|
| CVE-2006-3476 |
Cross-site scripting (XSS) vulnerability in comments.php in
PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote
attackers to inject arbitrary web script or HTML via the keyword
parameter.
|
| CVE-2006-3436 |
Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework
2.0 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors involving "ASP.NET controls that set the
AutoPostBack property to true".
|
| CVE-2006-3429 |
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows
remote attackers to inject arbitrary web script or HTML via the
currency parameter in (1) loan.php and (2) mortgage.php. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2006-3428 |
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows
remote attackers to inject arbitrary web script or HTML via the year
parameter in (1) loan.php and (2) mortgage.php.
|
| CVE-2006-3405 |
Cross-site scripting (XSS) vulnerability in qtofm.php in
QTOFileManager 1.0 allows remote attackers to inject arbitrary web
script or HTML via the (1) delete, (2) pathext, and (3) edit
parameters.
|
| CVE-2006-3399 |
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki
before 1.1.2-20060702 allows remote attackers to inject arbitrary
Javascript via the URL, which is reflected back in an error message, a
variant of CVE-2004-1632.
|
| CVE-2006-3397 |
Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu
before 2.0.1 allow remote attackers to inject arbitrary web script or
HTML via multiple unspecified parameters, including the (1) title and
(2) description parameters when creating a task.
|
| CVE-2006-3388 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2
allows remote attackers to inject arbitrary web script or HTML via the
table parameter.
|
| CVE-2006-3386 |
index.php in Vincent Leclercq News 5.2 allows remote attackers to
obtain sensitive information, such as the installation path, via a
mail[] parameter with invalid values.
|
| CVE-2006-3385 |
Cross-site scripting (XSS) vulnerability in divers.php in Vincent
Leclercq News 5.2 allows remote attackers to inject arbitrary web
script or HTML via the (1) id and (2) disabled parameters.
|
| CVE-2006-3384 |
SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2
allows remote attackers to execute arbitrary SQL commands via the (1)
id and (2) texte parameters.
|
| CVE-2006-3383 |
Cross-site scripting (XSS) vulnerability in index.php in mAds 1.0
allows remote attackers to inject arbitrary web script or HTML via
Javascript events such as onmouseover within a URL. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party reports.
|
| CVE-2006-3382 |
Cross-site scripting (XSS) vulnerability in search.php in mAds 1.0
allows remote attackers to inject arbitrary web script or HTML via the
"search string".
|
| CVE-2006-3377 |
Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP
3.02 and earlier, and AutoRank Pro 5.01 and earlier, allows remote
attackers to inject arbitrary web script or HTML via the (1) Keyword
parameter in search.php and the (2) Username parameter in main.cgi.
|
| CVE-2006-3366 |
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow
remote attackers to inject arbitrary web script or HTML via crafted
HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in
(a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in
(c) members/is_online.php; (3) site_id parameter in (d)
messenger/online.php, (e) messenger/search.php, and (f)
messenger/profile.php; (4) contact_name parameter in
messenger/search.php; (5) membername parameter in (g)
messenger/profileview.php; (6) unspecified parameters used when
"editing a profile"; and (7) cust_name parameter in (h)
messenger/expire.php. NOTE: The vendor disputes the vectors involving
files in the messenger directory, stating "... the referenced folder
'messenger' was never available to the general public...".
|
| CVE-2006-3365 |
V3 Chat allows remote attackers to obtain the installation path via
(1) an invalid id parameter to mail/index.php or (2) membername
parameter to messenger/online.php, which displays the path in an error
page due to an incorrect SQL statement.
|
| CVE-2006-3359 |
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006
PRO allow remote attackers to inject arbitrary web script or HTML via
the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in
(a) index.php; and the (5) category parameter in (b) inc/rss_feed.php.
|
| CVE-2006-3358 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script
or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters,
which are not sanitized before being returned in an error page. NOTE:
it is possible that some of these vectors are resultant from an SQL
injection issue.
|
| CVE-2006-3345 |
Cross-site scripting (XSS) vulnerability in AliPAGER, possibly 1.5 and
earlier, allows remote attackers to inject arbitrary web script or
HTML via a chat line.
|
| CVE-2006-3342 |
Cross-site scripting (XSS) vulnerability in index.php in Arctic 1.0.2
and earlier allows remote attackers to inject arbitrary web script or
HTML via the query parameter in a search cmd.
|
| CVE-2006-3338 |
Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors in a direct request to
secure/ConfigureReleaseNote.jspa, which are not sanitized before being
returned in an error page.
|
| CVE-2006-3337 |
Cross-site scripting (XSS) vulnerability in
frontend/x/files/select.html in cPanel 10.8.2-CURRENT 118 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
file parameter.
|
| CVE-2006-3333 |
Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum
3.5 allows remote attackers to inject web script or HTML via the
multiple unspecified parameters, including the (1) frommethod, (2)
list, and (3) method, which are reflected in an error message. NOTE:
some of these vectors might be resultant from SQL injection.
|
| CVE-2006-3330 |
Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL
Classifieds (PHP Classifieds) allows remote attackers to execute
arbitrary SQL commands via the (1) ProductName ("Title" field), (2)
url, and (3) Description parameters, possibly related to issues in
add1.php.
|
| CVE-2006-3328 |
new_ticket.cgi in Hostflow 2.2.1-15 allows remote attackers to steal
and replay authentication credentials via an IMG tag in the desc
parameter ("Ticket Description" field) that points to a URL that
captures referer URLs, possibly due to a cross-site scripting (XSS)
vulnerability or a leak of credentials in referer URLs.
|
| CVE-2006-3327 |
Cross-site scripting (XSS) vulnerability in Custom dating biz dating
script 1.0 allows remote attackers to inject arbitrary web script or
HTML via the (1) sn20_special_cases parameter ("Special Cases" field)
in profile/mini.php, (2) tyxx01_album_name parameter ("Album Name"
field) in profile/photo_create.php, and the (3) u parameter in
admin/user_view.php.
|
| CVE-2006-3321 |
Multiple cross-site scripting (XSS) vulnerabilities in openforum.asp
in OpenForum 1.2 Beta and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) ofdisp and (2) ofmsgid
parameters.
|
| CVE-2006-3320 |
Cross-site scripting (XSS) vulnerability in command.php in SiteBar
3.3.8 and earlier allows remote attackers to inject arbitrary web
script or HTML via the command parameter.
|
| CVE-2006-3319 |
Cross-site scripting (XSS) vulnerability in rss/index.php in PHP
iCalendar 2.22 and earlier allows remote attackers to inject arbitrary
web script or HTML via the cal parameter.
|
| CVE-2006-3313 |
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft
smartNet 2.0 allows remote attackers to inject arbitrary web script or
HTML via the keyWord parameter.
|
| CVE-2006-3312 |
Multiple cross-site scripting (XSS) vulnerabilities in ashmans and
Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) link_print, (2) link_upgrade,
(3) link_sql, (4) link_next, (5) link_prev, and (6) link_list
parameters in top.inc as included by queries_view_search.php; the (7)
msg, (8) component_name, and (9) component_desc parameters in (a)
components_copy_content.php, (b) components_modify_content.php, and
(c) components_new_content.php; the (10) title, (11) version, and (12)
content parameters in design_copy_content.php; the (13) plan_title and
(14) plan_content parameters in design_copy_plan_search.php; the (15)
title, (16) minor_version, (17) new_version, and (18) content
parameters in design_modify_content.php; the (19) title, (20) version,
and (21) content parameters in design_new_content.php; the (22)
plan_name and (23) plan_desc parameters in design_new_search.php; the
(24) file_name parameter in download.php; the (25) username and (26)
password parameters in login.php; the (27) title, (28) version, and
(29) content parameters in phase_copy_content.php; the (30) content
parameter in phase_delete_search.php; the (31) title, (32)
minor_version, (33) new_version, and (34) content parameters in
phase_modify_content.php; the (35) content, (36) title, (37) version,
and (38) content parameters in phase_modify_search.php; the (39)
content parameter in phase_view_search.php; the (40) msg, (41)
product_name, and (42) product_desc parameters in
products_copy_content.php; and possibly the (43) product_name and (44)
product_desc parameters in (d) products_copy_search.php, and a large
number of additional parameters and executables. NOTE: the vendor
notified CVE via e-mail that this issue has been fixed in the 6.8 RC
release.
|
| CVE-2006-3308 |
Unspecified vulnerability in the wpprop code for Project EROS
bbsengine before 20060622-0315 has unknown impact and remote attack
vectors via [img] tags, possibly cross-site scripting (XSS).
|
| CVE-2006-3306 |
Cross-site scripting (XSS) vulnerability in the preparestring function
in lib/common.php in Project EROS bbsengine before 20060501-0142-jam,
and possibly earlier versions dating back to 2006-02-23, might allow
remote attackers to inject arbitrary web script or HTML via unknown
vectors.
|
| CVE-2006-3305 |
Multiple cross-site scripting (XSS) vulnerabilities in UebiMiau
Webmail 2.7.10, and 2.7.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) f_user parameter in
index.php, the (2) pag parameter in messages.php, or the (3) lid, (4)
tid, and (5) sid parameters in error.php.
|
| CVE-2006-3303 |
Multiple cross-site scripting (XSS) vulnerabilities in pm.php in
DeluxeBB 1.07 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) subject or (2) to parameters.
|
| CVE-2006-3301 |
Multiple cross-site scripting (XSS) vulnerabilities in phpQLAdmin
2.2.7 and earlier allow remote attackers to inject arbitrary web
script or HTML via the domain parameter in (1) user_add.php or (2)
unit_add.php.
|
| CVE-2006-3299 |
Cross-site scripting (XSS) vulnerability in index.php in Usenet Script
0.5 allows remote attackers to inject arbitrary web script or HTML via
the group parameter.
|
| CVE-2006-3297 |
Cross-site scripting (XSS) vulnerability in error.php in UebiMiau
Webmail 2.7.10 and earlier allows remote attackers to inject arbitrary
web script or HTML via the icq parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-3295 |
Cross-site scripting (XSS) vulnerability in header.php in Open
Guestbook 0.5 allows remote attackers to inject arbitrary web script
or HTML via the title parameter.
|
| CVE-2006-3289 |
Cross-site scripting (XSS) vulnerability in the login page of the HTTP
interface for the Cisco Wireless Control System (WCS) for Linux and
Windows before 3.2(51) allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors involving a "malicious URL".
|
| CVE-2006-3284 |
Cross-site scripting (XSS) vulnerability in Dating Agent PRO 4.7.1
allows remote attackers to inject arbitrary web script or HTML via the
login parameter in (1) webmaster/index.php and (2) search.php.
|
| CVE-2006-3279 |
Cross-site scripting (XSS) vulnerability in aeDating 4.1 allows remote
attackers to inject arbitrary web script or HTML via the (1) Sex
parameter in index.php, (2) ProfileType parameter in join_form.php,
and (3) Email parameter in forgot.php.
|
| CVE-2006-3278 |
Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the (1) next_template, (2) start, (3) curr_menu_id, and (4) arid
parameters in psoft/servlet/resadmin/psoft.hsphere.CP when using the
mailman/massmail.html template_name.
|
| CVE-2006-3273 |
Cross-site scripting (XSS) vulnerability in menu.php in Some Chess 1.5
rc1 allows remote attackers to inject arbitrary web script or HTML via
the user parameter ("New Name" field).
|
| CVE-2006-3265 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Qdig before 1.2.9.3, when register_globals is enabled, allow remote
attackers to inject arbitrary web script or HTML via the (1)
pre_gallery or (2) post_gallery parameters.
|
| CVE-2006-3264 |
Cross-site scripting (XSS) vulnerability in mclient.cgi in Namo
DeepSearch 4.5 allows remote attackers to inject arbitrary web script
or HTML via the p parameter.
|
| CVE-2006-3261 |
Cross-site scripting (XSS) vulnerability in Trend Micro Control
Manager (TMCM) 3.5 allows remote attackers to inject arbitrary web
script or HTML via the username field on the login page, which is not
properly sanitized before being displayed in the error log.
|
| CVE-2006-3260 |
Cross-site scripting (XSS) vulnerability in index.php in vlbook 1.02
allows remote attackers to inject arbitrary web script or HTML via the
message parameter.
|
| CVE-2006-3259 |
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) ep parameter to search.php and the (2) subject parameter in
comment.php (aka the Subject field when posting a comment).
|
| CVE-2006-3258 |
Multiple cross-site scripting (XSS) vulnerabilities in index.html in
BNBT TrinEdit and EasyTracker 7.7r3.2004.10.27 and earlier allow
remote attackers to inject arbitrary web script or HTML via the (1)
filter or (2) sort parameters.
|
| CVE-2006-3257 |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.7.7
allow remote attackers to inject arbitrary HTML or web script via
unspecified attack vectors, possibly including (1)
calendar/myagenda.php, (2) document/document.php, (3)
phpbb/newtopic.php, (4) tracking/userLog.php, and (5) wiki/page.php.
|
| CVE-2006-3253 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in member.php in vBulletin
3.5.x allows remote attackers to inject arbitrary web script or HTML
via the u parameter. NOTE: the vendor has disputed this report,
stating that they have been unable to replicate the issue and that
"the userid parameter is run through our filtering system as an
unsigned integer."
|
| CVE-2006-3247 |
Multiple cross-site scripting (XSS) vulnerabilities in show.php in
GL-SH Deaf Forum 6.4.3 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) search, (2) page, and (3)
action parameters. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-3246 |
Cross-site scripting (XSS) vulnerability in show.php in GL-SH Deaf
Forum 6.4.3 and earlier allows remote attackers to inject arbitrary
web script or HTML via the sort parameter.
|
| CVE-2006-3245 |
Multiple cross-site scripting (XSS) vulnerabilities in activatemember
in mvnForum 1.0 GA and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) member and (2) activatecode
parameters.
|
| CVE-2006-3241 |
Cross-site scripting (XSS) vulnerability in messages.php in XennoBB
1.0.5 and earlier allows remote attackers to inject arbitrary web
script or HTML via the tid parameter.
|
| CVE-2006-3240 |
Cross-site scripting (XSS) vulnerability in classes/ui.class.php in
dotProject 2.0.3 and earlier allows remote attackers to inject
arbitrary web script or HTML via the login parameter.
|
| CVE-2006-3237 |
Cross-site scripting (XSS) vulnerability in index.php in Enterprise
Groupware System (EGS) 1.2.4 and earlier allows remote attackers to
inject arbitrary web script or HTML via the module parameter.
|
| CVE-2006-3235 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
FineShop 3.0 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) promocja, (2) wysw, or (3) id_produc
parameters.
|
| CVE-2006-3233 |
Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in
Open WebMail (OWM) 2.52, and other versions released before
06/18/2006, allows remote attackers to inject arbitrary web script or
HTML via the from field. NOTE: some third party sources have
mentioned the "to" and "from" fields, although CVE analysis shows that
these are associated with the previous version, a different
executable, and a different CVE.
|
| CVE-2006-3230 |
Cross-site scripting (XSS) vulnerability in index.tmpl in Azureus
Tracker 2.4.0.2 and earlier (Java BitTorrent Client Tracker) allows
remote attackers to inject arbitrary web script or HTML via the search
parameter.
|
| CVE-2006-3229 |
Cross-site scripting (XSS) vulnerability in Open WebMail (OWM) 2.52,
and other versions released before 05/12/2006, allows remote attackers
to inject arbitrary web script or HTML via the (1) To and (2) From
fields in openwebmail-main.pl, and possibly (3) other unspecified
vectors related to "openwebmailerror calls that need to display HTML."
|
| CVE-2006-3225 |
Cross-site scripting (XSS) vulnerability in Sun ONE Application Server
7 before Update 9, Java System Application Server 7 2004Q2 before
Update 5, and Java System Application Server Enterprise Edition 8.1
2005 Q1 allows remote attackers to inject arbitrary HTML or web script
via unknown vectors.
|
| CVE-2006-3212 |
Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook
1.3 and earlier allows remote attackers to inject web script or HTML
via the (1) name, (2) email, (3) add, and (4) wName parameters. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2006-3211 |
Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook
1.3 and earlier allows remote attackers to inject Javascript code via
a javascript URI in an img bbcode tag in the comments parameter.
|
| CVE-2006-3210 |
Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when
register_globals is enabled, allows remote attackers to conduct PHP
remote file inclusion and directory traversal attacks via URLs or ".."
sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b)
admin_album.php, (c) admin_image.php, and (d) admin_util.php; and the
(2) dir_abs_admin_src parameter in admin_album.php and
admin_image.php. NOTE: this issue can be leveraged to conduct
cross-site scripting (XSS) attacks.
|
| CVE-2006-3197 |
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB)
2.1.6 and earlier allows remote attackers to inject arbitrary web
script or HTML via a POST that contains hexadecimal-encoded HTML.
|
| CVE-2006-3195 |
Cross-site scripting (XSS) vulnerability in index.php in singapore
0.10.0 and earlier allows remote attackers to inject arbitrary web
script or HTML via the template parameter.
|
| CVE-2006-3191 |
Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2
allows remote attackers to inject arbitrary web script or HTML via the
pageid parameter.
|
| CVE-2006-3189 |
Cross-site scripting (XSS) vulnerability in
administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote
attackers to inject arbitrary web script or HTML via the msg
parameter.
|
| CVE-2006-3187 |
Multiple cross-site scripting (XSS) vulnerabilities in Sharky e-shop
3.05 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) maingroup and (2) secondgroup parameters to (a)
search_prod_list.asp, and the (3) maingroup parameter to (b)
meny2.asp. NOTE: it is possible that this is resultant from SQL
injection or a forced SQL error.
|
| CVE-2006-3186 |
Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon
1.3.2 allow remote attackers to inject arbitrary web script or HTML
via the mainpath parameter to (1) data/footer.php and (2)
admin/header.php. NOTE: the provenance of this information is unknown;
the details are obtained from third party information.
|
| CVE-2006-3183 |
Cross-site scripting (XSS) vulnerability in index.php in MobeScripts
Mobile Space Community 2.0 and earlier allows remote attackers to
inject arbitrary web script or HTML via the (1) browse parameter,
which is not filtered in the resulting error message, and multiple
unspecified input fields, including those involved when (2) updating a
profile, (3) posting comments or entries in a blog, (4) uploading
files, (5) picture captions, and (6) sending a private message (PM).
|
| CVE-2006-3182 |
Directory traversal vulnerability in index.php in MobeScripts Mobile
Space Community 2.0 allows remote attackers to read arbitrary files
via a .. (dot dot) in the uid parameter in the rss page.
|
| CVE-2006-3181 |
SQL injection vulnerability in index.php in MobeScripts Mobile Space
Community 2.0 allows remote attackers to execute arbitrary SQL
commands via the browse parameter.
|
| CVE-2006-3180 |
Cross-site scripting (XSS) vulnerability in ftp_index.php in Confixx
Pro 3.0 allows remote attackers to inject arbitrary web script or HTML
via the path parameter.
|
| CVE-2006-3179 |
Cross-site scripting (XSS) vulnerability in tools_ftp_pwaendern.php in
Confixx Pro 3.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the account parameter.
|
| CVE-2006-3174 |
Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail
1.5.1 and earlier, when register_globals is enabled, allows remote
attackers to inject arbitrary HTML via the mailbox parameter.
|
| CVE-2006-3169 |
Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) msg_result and (2) rep_titre parameters in (a)
read.php; and the (3) id and (4) parent parameters and (5)
CSForum_nom, (6) CSForum_mail, and (7) CSForum_url cookie parameters
in (b) ajouter.php.
|
| CVE-2006-3166 |
Cross-site scripting (XSS) vulnerability in propview.php in Free
Realty 2.9-0.6 and earlier allows remote attackers to execute
arbitrary web script or HTML via the sort parameter.
|
| CVE-2006-3160 |
Cross-site scripting (XSS) vulnerability in fm.php in ONEdotOH Simple
File Manager (SFM) 0.24a and earlier allows remote attackers to inject
arbitrary web script or HTML via the msg parameter.
|
| CVE-2006-3157 |
Cross-site scripting (XSS) vulnerability in index.php in Thinkfactory
UltimateGoogle 1.00 and earlier allows remote attackers to inject
arbitrary web script or HTML via the REQ parameter.
|
| CVE-2006-3156 |
Cross-site scripting (XSS) vulnerability in index.cgi in Ultimate
eShop 1.0 and earlier allows remote attackers to inject arbitrary web
script or HTML via the subid parameter.
|
| CVE-2006-3155 |
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate
Auction 1.0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) item parameter in (a) emailtofriend.pl or
(b) violation.pl, (2) seller parameter in (c) vsoa.pl, (3) user
parameter in (d) userask.pl or (e) leavefeed.pl, (4) itemnum parameter
in userask.pl, (5) category parameter in (f) itemlist.pl, and the (6)
query parameter in (g) search.pl.
|
| CVE-2006-3153 |
Cross-site scripting (XSS) vulnerability in index.pl in Ultimate
Estate 1.0 and earlier allows remote attackers to inject arbitrary web
script or HTML via the cat parameter.
|
| CVE-2006-3151 |
Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD
(aka ACID) 1.2.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the menu parameter.
|
| CVE-2006-3149 |
Cross-site scripting (XSS) vulnerability in topic.php in phpMyForum
4.1.3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the highlight parameter.
|
| CVE-2006-3143 |
Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus
SchoolMAX 4.0.1 and earlier iCue and iParent applications allows
remote attackers to inject arbitrary web script or HTML via the
error_msg parameter.
|
| CVE-2006-3141 |
Cross-site scripting (XSS) vulnerability in details.cfm in Tradingeye
Shop R4 and earlier allows remote attackers to inject arbitrary web
script or HTML via the image parameter.
|
| CVE-2006-3139 |
Multiple SQL injection vulnerabilities in war.php in Virtual War
(VWar) 1.5.0 R14 and earlier allow remote attackers to execute
arbitrary SQL commands via the (1) s, (2) showgame, (3) sortorder, and
(4) sortby parameters.
|
| CVE-2006-3138 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory
10.4.5 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) PIC parameter in offers-pix.php, (2) from
parameter in cp/index.php, and (3) action parameter in
cp/admin_index.php.
|
| CVE-2006-3137 |
Cross-site scripting (XSS) vulnerability in productDetail.asp in Edge
eCommerce Shop allows remote attackers to inject arbitrary web script
or HTML via the cart_id parameter.
|
| CVE-2006-3132 |
Cross-site scripting (XSS) vulnerability in qtofm.php4 in
QTOFileManager 1.0 allows remote attackers to inject arbitrary web
script or HTML via the msg parameter, as originally reported for
index.php.
|
| CVE-2006-3131 |
Multiple cross-site scripting (XSS) vulnerabilities in Clubpage allow
remote attackers to inject arbitrary web script or HTML via the (1)
news_archive, (2) language, and (3) intranetLogin parameters in (a)
index.php; the (4) sites_id parameter in (b) sites.php; and the (5)
news_id parameter in (c) news_more.php.
|
| CVE-2006-3129 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NC
LinkList 1.2 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) cat and (2) view parameters.
|
| CVE-2006-3110 |
Cross-site scripting (XSS) vulnerability in main.php in Chipmailer
1.09 allows remote attackers to inject arbitrary web script or HTML
via the (1) name, (2) betreff, (3) mail, and (4) text parameters.
|
| CVE-2006-3109 |
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3
before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3
before 4.3(1), allows remote attackers to inject arbitrary web script
or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and
(2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657.
|
| CVE-2006-3108 |
Cross-site scripting (XSS) vulnerability in EmailArchitect Email
Server 6.1 allows remote attackers to inject arbitrary Javascript via
an HTML div tag with a carriage return between the onmouseover
attribute and its value, which bypasses the mail filter.
|
| CVE-2006-3106 |
Cross-site scripting (XSS) vulnerability in index.php in
phpMyDesktop|Arcade 1.0 allows remote attackers to inject arbitrary
web script or HTML via the subsite parameter in the subsite todo.
|
| CVE-2006-3103 |
Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows
remote attackers to inject arbitrary web script or HTML via the (1)
error parameter in users/login.php and the (2) feedback parameter in
articles/index.php.
|
| CVE-2006-3101 |
Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco
Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary
web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.
|
| CVE-2006-3095 |
Multiple cross-site scripting (XSS) vulnerabilities in iPostMX 2005
2.0 and earlier allow remote attackers to inject arbitrary web script
or HTML via the RETURNURL parameter in (1) userlogin.cfm and (2)
account.cfm.
|
| CVE-2006-3089 |
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFactures
1.0, and possibly 1.2 and earlier, allow remote attackers to inject
arbitrary web script or HTML via the (1) prefixe_dossier parameter in
(a) /inc/header.php; (2) msg parameter in (b)
/remises/ajouter_remise.php, (c) /tva/ajouter_tva.php, (d)
/stocks/ajouter.php, (e) /pays/ajouter_pays.php, (f)
/produits/ajouter_cat.php, (g) /produits/ajouter_produit.php and (h)
/produits/modifier_cat.php; (3) tire parameter in
/remises/ajouter_remise.php; (4) quantite, (5) taux and (6) date
parameter in /stocks/ajouter.php; and (7) pays and (8) prefixe
parameter in /pays/ajouter_pays.php.
|
| CVE-2006-3088 |
Cross-site scripting (XSS) vulnerability in index.php in Car
Classifieds allows remote attackers to inject arbitrary web script or
HTML via the make_id parameter. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-3087 |
Multiple cross-site scripting (XSS) vulnerabilities in EZGallery 1.5
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) pUserID, (2) aid, (3) aname, (4) uid, and (5) m
parameter in (a) common/galleries.asp; (6) aid, (7) aname, (8) uid,
(9) m, (10) gp, and (11) g parameter in (b) common/pupload.asp; and
(12) msg, (13) fn and (14) gp parameter in (c) common/upload.asp.
|
| CVE-2006-3080 |
Cross-site scripting (XSS) vulnerability in viewposts.cfm in
aXentForum II and earlier allows remote attackers to inject arbitrary
web script or HTML via the startrow parameter.
|
| CVE-2006-3079 |
Cross-site scripting (XSS) vulnerability in index.cfm in SSPwiz Plus
1.0.7 and earlier allows remote attackers to inject arbitrary web
script or HTML via the message parameter.
|
| CVE-2006-3077 |
Cross-site scripting (XSS) vulnerability in guestbook.cfm in
aXentGuestbook 1.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the startrow parameter.
|
| CVE-2006-3073 |
Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN
feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500
Series Adaptive Security Appliances (ASA), when in WebVPN clientless
mode, allow remote attackers to inject arbitrary web script or HTML
via the domain parameter in (1) dnserror.html and (2)
connecterror.html, aka bugid CSCsd81095 (VPN3k) and CSCse48193 (ASA).
NOTE: the vendor states that "WebVPN full-network-access mode" is not
affected, despite the claims by the original researcher.
|
| CVE-2006-3071 |
Cross-site scripting (XSS) vulnerability in index.php in MP3
Search/Archive 1.2 allows remote attackers to inject arbitrary web
script or HTML via the (1) keywords parameter, as used by the "search
box", and (2) res parameter.
|
| CVE-2006-3063 |
Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook
1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to
inject arbitrary web script or HTML via the (1) comment, (2) email,
(3) homepage, (4) id, (5) name, and (6) text parameters in (a)
index.php, the (7) comment, (8) email, (9) homepage, (10) number, (11)
name, and (12) text parameters in (b) admin/guestbook.php, and the
(13) email, (14) homepage, (15) icq, (16) name, and (17) text
parameters in (c) admin/edit.php.
|
| CVE-2006-3062 |
Cross-site scripting (XSS) vulnerability in index.php in myPHP
Guestbook 2.0.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via the lang parameter.
|
| CVE-2006-3061 |
Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review
allow remote attackers to inject arbitrary web script or HTML via the
(1) sort parameter in index2.php, (2) item_id parameter in report.php,
(3) search_term parameter (aka the "search box") in
search_reviews.php, (4) the profile field in usercp/profile_edit1.php,
and the (5) review field in review_form.php.
|
| CVE-2006-3060 |
Cross-site scripting (XSS) vulnerability in P.A.I.D 2.2 allows remote
attackers to inject arbitrary web script or HTML via the (1) read
parameter in index.php, (2) farea parameter in faq.php, and (3)
unspecified input fields on the "My Account" login page.
|
| CVE-2006-3052 |
Cross-site scripting (XSS) vulnerability in Event Registration allows
remote attackers to inject arbitrary web script or HTML via the (1)
event_id parameter to view-event-details.php or (2) select_events
parameter to event-registration.php. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-3051 |
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0,
and other versions before 6.0.6patch2, allows remote attackers to
inject arbitrary script code or HTML via the page parameter.
|
| CVE-2006-3050 |
Directory traversal vulnerability in detail.php in SixCMS 6.0, and
other versions before 6.0.6patch2, allows remote attackers to read
arbitrary files via a .. (dot dot) sequence and trailing null (%00)
byte in the template parameter.
|
| CVE-2006-3049 |
Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in
Mole Group Ticket Booking Script allow remote attackers to inject
arbitrary web script or HTML via the (1) name, (2) address1, (3)
address2, (4) county, (5) postcode, (6) email, (7) phone, or (8)
mobile parameters to booking2.php.
|
| CVE-2006-3048 |
SQL injection vulnerability in TikiWiki 1.9.3.2 and possibly earlier
versions allows remote attackers to execute arbitrary SQL commands via
unknown attack vectors.
|
| CVE-2006-3047 |
Cross-site scripting (XSS) vulnerability in TikiWiki 1.9.3.2 and
possibly earlier versions allows remote attackers to inject arbitrary
web script or HTML via unknown attack vectors.
|
| CVE-2006-3044 |
Cross-site scripting (XSS) vulnerability in LogiSphere 1.6.0 allows
remote attackers to inject arbitrary web script or HTML via the URL,
which is reflected in an error page.
|
| CVE-2006-3043 |
Cross-site scripting (XSS) vulnerability in search.cfm in CreaFrameXe
(CFXe) CMS 2.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the voltext_suche parameter.
|
| CVE-2006-3039 |
Cross-site scripting (XSS) vulnerability in index.php in Cescripts
Realty Home Rent allows remote attackers to inject arbitrary web
script or HTML via the sel_menu parameter. NOTE: the vendor notified
CVE on 20060823 that "All issues concerning this script and others at
cescripts.com have been addressed and fixed."
|
| CVE-2006-3038 |
Cross-site scripting (XSS) vulnerability in index.php in Cescripts
Realty Room Rent allows remote attackers to inject arbitrary web
script or HTML via the sel_menu parameter. NOTE: the vendor notified
CVE on 20060823 that "All issues concerning this script and others at
cescripts.com have been addressed and fixed."
|
| CVE-2006-3037 |
Multiple cross-site scripting (XSS) vulnerabilities in publish.php in
ST AdManager Lite allow remote attackers to inject arbitrary web
script or HTML via the (1) title, (2) description, (3) article, (4)
bio, and (5) name parameters.
|
| CVE-2006-3036 |
Multiple cross-site scripting (XSS) vulnerabilities in
35mmslidegallery 6.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) imgdir parameter in (a) index.php, and the
(2) w, (3) h, and (4) t parameters in (b) popup.php.
|
| CVE-2006-3035 |
Multiple cross-site scripting (XSS) vulnerabilities in addwords.php in
MyScrapbook 3.1 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) name and (2) comment parameters. NOTE:
the provenance of this information is unknown; the details are
obtained from third party information.
|
| CVE-2006-3034 |
MyScrapbook 3.1 allows remote attackers to obtain sensitive
information via a direct request to files in the txt-db-api directory
such as txt-db-api/sql.php, which reveals the path in an error
message.
|
| CVE-2006-3033 |
Cross-site scripting (XSS) vulnerability in MyScrapbook 3.1 allows
remote attackers to inject arbitrary web script or HTML via the input
box in singlepage.php when submitting scrapbook pages.
|
| CVE-2006-3032 |
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP
Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote
attackers to inject arbitrary web script or HTML via the (1) catname
and (2) total parameters in (a) displaypic.asp, and the (3) catname
parameter in (b) displaythumbs.asp.
|
| CVE-2006-3031 |
Multiple cross-site scripting (XSS) vulnerabilities in index.asp in
fipsCMS 4.5 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) w, (2) phcat, (3) dayid, and (4) calw
parameters.
|
| CVE-2006-3030 |
Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping
Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) ToCategory and (2) FromCategory parameters
to (a) ProductDetailsForm.asp and (3) UserName and (4) Password
parameters to (b) LogIn/VerifyUserLog.asp.
|
| CVE-2006-3029 |
Cross-site scripting (XSS) vulnerability in default.asp in ClickTech
Clickcart 6.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the cat parameter.
|
| CVE-2006-3026 |
Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery
5.0 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) gallery_id parameter in gallery.asp and (2)
parentcurrentpage parameter in view_gallery.asp.
|
| CVE-2006-3025 |
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea
Lucid Calendar 0.22 allows remote attackers to inject arbitrary web
script or HTML via unspecified parameters. NOTE: the provenance of
this information is unknown; the details are obtained from third party
information.
|
| CVE-2006-3024 |
Multiple cross-site scripting (XSS) vulnerabilities in EvGenius
Counter 3.4 and earlier allow remote attackers to inject arbitrary web
script or HTML via the page parameter in (1) monthly.php and (2)
daily.php.
|
| CVE-2006-3023 |
Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp
in Uapplication Uphotogallery 1.1 and earlier allow remote attackers
to inject arbitrary web script or HTML via the (1) s and (2) block
parameters.
|
| CVE-2006-3022 |
Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery
1.5 and earlier allows remote attackers to inject arbitrary web script
or HTML via the path parameter.
|
| CVE-2006-3021 |
Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar
i-Gallery 4.1 PLUS and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) n and (2) d parameters in (a)
login.asp and the d parameter in (b) igallery.asp.
|
| CVE-2006-3020 |
Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp
in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) image and (2) PublisedDate parameters.
|
| CVE-2006-3016 |
Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown
impact and attack vectors, related to "certain characters in session
names," including special characters that are frequently associated
with CRLF injection, SQL injection, cross-site scripting (XSS), and
HTTP response splitting vulnerabilities. NOTE: while the nature of
the vulnerability is unspecified, it is likely that this is related to
a violation of an expectation by PHP applications that the session
name is alphanumeric, as implied in the PHP manual for session_name().
|
| CVE-2006-3009 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Business
Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary
HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4)
tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter
parameters to files such as (a) publication/publication_index.php, (b)
group/group_index.php, (c) user/user_index.php, (d)
list/list_index.php, and (e) company/company_index.php.
|
| CVE-2006-3007 |
Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5
allow remote attackers to inject arbitrary HTML or web script via the
DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, and (5) ICQ.
|
| CVE-2006-3006 |
Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly
other versions before 0.50, allows remote attackers to inject
arbitrary HTML or web script via a base64-encoded file parameter.
|
| CVE-2006-3004 |
Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone
Manager allow remote attackers to inject arbitrary web script or HTML
via the (1) id parameter in player.php and (2) keyword parameter when
performing a search.
|
| CVE-2006-3003 |
details.php in Easy Ad-Manager allows remote attackers to obtain the
full installation path via an invalid mbid parameter, which leaks the
path in an error message. NOTE: this might be resultant from another
vulnerability, since this vector also produces cross-site scripting
(XSS). NOTE: on 20060829, the vendor notified CVE that this issue has
been fixed.
|
| CVE-2006-3002 |
Cross-site scripting (XSS) vulnerability in details.php in Easy
Ad-Manager allows remote attackers to inject arbitrary web script or
HTML via the mbid parameter, which is reflected in an error message.
NOTE: on 20060829, the vendor notified CVE that this issue has been
fixed.
|
| CVE-2006-3001 |
Cross-site scripting (XSS) vulnerability in search.php in OkScripts
OkMall 1.0 allow remote attackers to inject arbitrary web script or
HTML via the page parameter. NOTE: this might be resultant from
another vulnerability, since the XSS is reflected in an error message.
|
| CVE-2006-3000 |
Cross-site scripting (XSS) vulnerability in search.php in OkScripts
OkArticles 1.0 allows remote attackers to inject arbitrary web script
or HTML via the q parameter.
|
| CVE-2006-2999 |
Cross-site scripting (XSS) vulnerability in search.php in OkScripts
QuickLinks 1.1 allows remote attackers to inject arbitrary web script
or HTML via the q parameter.
|
| CVE-2006-2997 |
Cross-site scripting (XSS) vulnerability in ZMS 2.9 and earlier, when
register_globals is enabled, allows remote attackers to inject
arbitrary web script or HTML via the raw parameter in the search
field.
|
| CVE-2006-2994 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
phazizGuestbook 2.0 allow remote attackers to inject arbitrary web
script or HTML via the (1) name, (2) email, (3) url fields, and (4)
text field (content parameter).
|
| CVE-2006-2992 |
Cross-site scripting (XSS) vulnerability in display.asp in My Photo
Scrapbook 1.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the key_m parameter.
|
| CVE-2006-2991 |
Multiple cross-site scripting (XSS) vulnerabilities in Ringlink 3.2
allow remote attackers to inject arbitrary web script or HTML via a
JavaScript URI in the SRC attribute of an IMG element, and possibly
other manipulations, in the ringid parameter in (1) next.cgi, (2)
stats.cgi, or (3) list.cgi.
|
| CVE-2006-2990 |
Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft
Helpdesk 2005 and earlier allows remote attackers to inject arbitrary
web script or HTML via the username parameter.
|
| CVE-2006-2989 |
Cross-site scripting (XSS) vulnerability in listpics.asp in ASP
ListPics 4.3 and earlier allows remote attackers to inject arbitrary
web script or HTML via the info parameter.
|
| CVE-2006-2988 |
Cross-site scripting (XSS) vulnerability in dictionary.php in Chemical
Dictionary allows remote attackers to inject arbitrary web script or
HTML via the keyword parameter in a browse action.
|
| CVE-2006-2986 |
Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie
Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple
Realty Lister (vsREAL) 1.0 allow remote attackers to inject arbitrary
web script or HTML via the (1) lid parameter in index.php and the (2)
title parameter in myslideshow.php.
|
| CVE-2006-2985 |
SQL injection vulnerability in index.php in IntegraMOD 1.4.0 and
earlier allows remote attackers to execute arbitrary SQL commands via
double-encoded "'" characters in the STYLE_URL parameter.
|
| CVE-2006-2984 |
Cross-site scripting (XSS) vulnerability in index.php in IntegraMOD
1.4.0 and earlier allows remote attackers to inject arbitrary web
script or HTML via the STYLE_URL parameter. NOTE: it is possible that
this issue is resultant from SQL injection.
|
| CVE-2006-2979 |
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free
2.5.5, and possibly other distributions including Light, Standard, and
Enterprise, allow remote attackers to inject arbitrary web script or
HTML via the (1) forum_id parameter in forum.php, which is not
properly handled in block_forum_topics.php, and (2) item_id parameter
in reviews.php, which is not properly handled in block_reviews.php.
|
| CVE-2006-2975 |
Multiple cross-site scripting (XSS) vulnerabilities in
pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to
inject arbitrary web script or HTML via javascript in the SRC
attribute of IMG tags in the (1) name, (2) email, and (3) website
parameter, which bypasses XSS protection mechanisms that check for
SCRIPT tags but not IMG. NOTE: portions of this description's details
are obtained from third party information.
|
| CVE-2006-2974 |
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect
Email Server 6.1.0.5 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) errCode and (2) uid parameter
in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and
(c) /additional/regdomain_done.asp.
|
| CVE-2006-2970 |
videoPage.php in L0j1k tinyMuw 0.1.0 allows remote attackers to obtain
sensitive information via a certain id parameter, probably with an
invalid value, which reveals the path in an error message.
|
| CVE-2006-2969 |
Cross-site scripting (XSS) vulnerability in L0j1k tinyMuw 0.1.0 allow
remote attackers to inject arbitrary web script or HTML via a
javascript URI in the SRC attribute of an IMG element in the input box
in quickchat.php, and possibly other manipulations.
|
| CVE-2006-2968 |
Cross-site scripting (XSS) vulnerability in search.php in PHP Labware
LabWiki 1.0 allows remote attackers to inject arbitrary web script or
HTML via the search input box (query parameter).
|
| CVE-2006-2966 |
Cross-site scripting (XSS) vulnerability in Particle Soft Particle
Wiki 1.0.2 allows remote attackers to inject arbitrary web script or
HTML via a BR element with an extraneous IMG tag and a STYLE attribute
that contains "/**/" comment sequences, which bypasses the XSS
protection scheme.
|
| CVE-2006-2965 |
Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft
Particle Whois 1.0.3 allow remote attackers to inject arbitrary web
script or HTML via (1) the target parameter in index.php and (2) the
"input box."
|
| CVE-2006-2963 |
Cross-site scripting (XSS) vulnerability in Suchergebnisse.asp in
Cabacos Web CMS 3.8.498 and earlier allows remote attackers to inject
arbitrary web script or HTML via the suchtext parameter.
|
| CVE-2006-2957 |
Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and
earlier allows remote attackers to inject arbitrary web script or HTML
via the banurl parameter to add.php. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-2956 |
Multiple cross-site scripting (XSS) vulnerabilities in i.List 1.5 beta
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) searchword parameter to search.php or (2) siteurl
parameter to add.php.
|
| CVE-2006-2955 |
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice
7.5 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) New Category (newcategory) or (2) apage parameter
to (a) edtalbum.asp, or the (3) cat or (4) albumid parameter to (b)
album.asp.
|
| CVE-2006-2953 |
Cross-site scripting (XSS) vulnerability in default.asp in OfficeFlow
2.6 and earlier allows remote attackers to inject arbitrary web script
or HTML via the sqlType parameter.
|
| CVE-2006-2952 |
Directory traversal vulnerability in Net Portal Dynamic System (NPDS)
5.10 and earlier allows remote attackers to read arbitrary files via a
.. (dot dot) sequence and trailing null (%00) byte in the (1)
Default_Theme parameter to header.php or (2) ModPath parameter to
modules/cluster-paradise/cluster-E.php.
|
| CVE-2006-2951 |
Multiple cross-site scripting (XSS) vulnerabilities in Net Portal
Dynamic System (NPDS) 5.10 and earlier allow remote attackers to
inject arbitrary web script and HTML via the (1) Titlesitename or (2)
sitename parameter to (a) header.php, (3) nuke_url parameter to (b)
meta/meta.php, (4) forum parameter to (c) viewforum.php, (5) post_id,
(6) forum, (7) topic, or (8) arbre parameter to (d) editpost.php, or
(9) uname or (10) email parameter to (e) user.php.
|
| CVE-2006-2950 |
Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote
attackers to obtain sensitive information via a direct request to (1)
header.php, (2) contact.php, or (3) forum_extender.php, which reveals
the path in an error message.
|
| CVE-2006-2949 |
Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2
allows remote attackers to inject arbitrary web script or HTML via the
do parameter.
|
| CVE-2006-2927 |
Multiple cross-site scripting (XSS) vulnerabilities in post.asp in
CodeAvalanche FreeForum (aka CAForum) 1.0 allow remote attackers to
inject arbitrary web script or HTML via the (1) msg_subject and (2)
msg_body parameters. NOTE: The provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-2925 |
Cross-site scripting (XSS) vulnerability in the web interface in
Ingate Firewall before 4.4.1 and SIParator before 4.4.1 allows remote
attackers to inject arbitrary web script or HTML, and steal cookies,
via unspecified vectors related to "XSS exploits" in administrator
functionality.
|
| CVE-2006-2913 |
Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows
remote attackers to inject arbitrary web script or HTML via the
albumID parameter to (1) popup.php and (2) view_album.php.
|
| CVE-2006-2903 |
Cross-site scripting (XSS) vulnerability in admin.php in Particle
Links 1.2.2 allows remote attackers to inject arbitrary web script or
HTML via the username parameter.
|
| CVE-2006-2897 |
Cross-site scripting (XSS) vulnerability in FunkBoard 0.71 allows
remote attackers to inject arbitrary HTML or web script via
unspecified vectors.
|
| CVE-2006-2895 |
Cross-site scripting (XSS) vulnerability in MediaWiki 1.6.0 up to
versions before 1.6.7 allows remote attackers to inject arbitrary HTML
and web script via the edit form.
|
| CVE-2006-2892 |
Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3
allows remote attackers to inject arbitrary HTML and web script via
the message parameter in a login action.
|
| CVE-2006-2891 |
Cross-site scripting (XSS) vulnerability in admin/index.php for
Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject
arbitrary HTML or web script via the loginmessage parameter.
|
| CVE-2006-2886 |
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote
attackers to obtain the full installation path via a crafted
fDocumentId parameter, which displays the path in the resulting error
message. NOTE: this might be resultant from another vulnerability,
since this vector also produces XSS.
|
| CVE-2006-2885 |
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree
Open Source 3.0.3 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) fDocumentId parameter in
view.php and the (2) fSearchableText parameter in
/search/simpleSearch.php.
|
| CVE-2006-2883 |
Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ
1.0 allows remote attackers to inject arbitrary web script or HTML via
the q parameter.
|
| CVE-2006-2882 |
Multiple cross-site scripting (XSS) vulnerabilities submit.asp in
ASPScriptz Guest Book 2.0 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) GBOOK_UNAME, (2) GBOOK_EMAIL,
(3) GBOOK_CITY, (4) GBOOK_COU, (5) GBOOK_WWW, and (6) GBOOK_MESS form
fields.
|
| CVE-2006-2880 |
Cross-site scripting (XSS) vulnerability in the Contributed Packages
for PyBlosxom 1.2.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the Comments plugin in the (1) url
and (2) author fields.
|
| CVE-2006-2876 |
Cross-site scripting (XSS) vulnerability in cat.php in PHP Pro Publish
2.0 allows remote attackers to inject arbitrary web script or HTML via
the catname parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-2874 |
Unspecified vulnerability in OSADS Alliance Database before 1.4 has
unknown impact and attack vectors related to a "Security Leak to lock
in HTML-Code," possibly due to a cross-site scripting (XSS)
vulnerability involving comments.
|
| CVE-2006-2873 |
Cross-site scripting (XSS) vulnerability in hava.asp in Enigma Haber
4.2 allows remote attackers to inject arbitrary web script or HTML via
the il parameter. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2006-2870 |
Cross-site scripting (XSS) vulnerability in forum_search.asp in
Intelligent Solutions Inc. ASP Discussion Forum allows remote
attackers to inject arbitrary web script or HTML via the search
variable.
|
| CVE-2006-2851 |
Cross-site scripting (XSS) vulnerability in index.php in dotProject
2.0.2 and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified parameters, which are not properly
handled when the client is using Internet Explorer.
|
| CVE-2006-2850 |
Cross-site scripting (XSS) vulnerability in recentchanges.php in PHP
Labware LabWiki 1.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the help parameter.
|
| CVE-2006-2846 |
Cross-site scripting (XSS) vulnerability in Print.PHP in VisionGate
Portal System allows remote attackers to inject arbitrary web script
or HTML via unspecified parameters. NOTE: The provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-2840 |
Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2)
"url links" in PmWiki 2.1.6 and earlier allows remote attackers to
inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2006-2837 |
Cross-site scripting (XSS) vulnerability in Techno Dreams Guest Book
allows remote attackers to inject arbitrary web script or HTML via
certain comment fields in the "Sign Our GuestBook" page, probably the
x_Comments parameter to guestbookadd.asp.
|
| CVE-2006-2833 |
Cross-site scripting (XSS) vulnerability in the taxonomy module in
Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web
script or HTML via inputs that are not properly validated when the
page title is output, possibly involving the $names variable.
|
| CVE-2006-2832 |
Cross-site scripting (XSS) vulnerability in the upload module
(upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2
allows remote attackers to inject arbitrary web script or HTML via the
uploaded filename.
|
| CVE-2006-2821 |
Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts
Pro Publish allow remote attackers to inject arbitrary web script or
HTML via the (1) artid parameter in art.php and the (2) catname
parameter in cat.php.
|
| CVE-2006-2820 |
Cross-site scripting (XSS) vulnerability in HotWebScripts.com Weblog
Oggi 1.0 allows remote attackers to inject arbitrary web script or
HTML via a comment, possibly involving a javascript URI in the SRC
attribute of an IMG element.
|
| CVE-2006-2816 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
coolphp magazine allow remote attackers to inject arbitrary web script
or HTML via the (1) op and (2) nick parameters, and possibly the (3)
0000, (4) userinfo, (5) comp_der, (6) encuestas, and (7) pagina
parameters. NOTE: it is not clear whether this is a distributable
product or a site-specific vulnerability. If it is site-specific, then
it should not be included in CVE.
|
| CVE-2006-2815 |
Multiple cross-site scripting (XSS) vulnerabilities in Two Shoes
M-Factory (TSMF) SimpleBoard 1.1.0 Stable (aka com_simpleboard), as
used in Mambo and Joomla!, allow remote attackers to inject arbitrary
web script or HTML via (1) the Name field in "post ne topic" in the
Frontend, (2) the Title (aka Community-Title) field in Simpleboard
Configuration in the Backend Admin Panel, and the (3) Name (aka
Forum-Title) and (4) Name (aka Category-Title) fields in Simpleboard
Administration in the Backend Admin Panel. NOTE: some sources have
stated that the sb_authorname parameter is affected, but it is unclear
which field is related to it.
|
| CVE-2006-2812 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Dominios Europa PICRATE (aka TAL RateMyPic) 1.0 allow remote attackers
to inject arbitrary web script or HTML via a javascript URI in the SRC
attribute of an IMG element in the (1) name (aka nick), (2) email, and
(3) comment boxes; and via the (4) id parameter.
|
| CVE-2006-2810 |
Multiple cross-site scripting (XSS) vulnerabilities in Belchior
Foundry vCard 2.9 allow remote attackers to inject arbitrary web
script or HTML via the page parameter in (1) toprated.php and (2)
newcards.php. NOTE: the card_id vector is already covered by
CVE-2006-1230.
|
| CVE-2006-2809 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
ar-blog 5.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) count parameter, and possibly the (2) next, (3)
Year_the_news, and (4) mo parameters. NOTE: the year and month vectors
are already covered by CVE-2006-0333.
|
| CVE-2006-2808 |
Cross-site scripting (XSS) vulnerability in Lycos Tripod htmlGEAR
guestGEAR (aka Guest Gear) allows remote attackers to inject arbitrary
web script or HTML via a guestbook post containing a javascript URI in
the SRC attribute of the BR element after an extra "iframe" tagname
within that element, followed by a double ">", which might bypass
cleansing operations.
|
| CVE-2006-2804 |
Cross-site scripting (XSS) vulnerability in index.cfm in Goss
Intelligent Content Management (iCM) 7.0 and earlier allows remote
attackers to inject arbitrary web script or HTML via the keyword
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party sources.
|
| CVE-2006-2803 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker
1.0 allows remote attackers to inject arbitrary web script or HTML via
the (1) id parameter to index.php, (2) search field (possibly the s
parameter), or (3) comment field.
|
| CVE-2006-2800 |
Multiple cross-site scripting (XSS) vulnerabilities in Unak CMS 1.5
RC2 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) u_a or (2) u_s parameters. NOTE: this might be
resultant from SQL injection.
|
| CVE-2006-2799 |
Cross-site scripting (XSS) vulnerability in content_footer.php in
toendaCMS 0.7.0 allows remote attackers to inject arbitrary web
scripts or HTML via the print_url variable. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party sources.
|
| CVE-2006-2798 |
Multiple cross-site scripting (XSS) vulnerabilities in
phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary
web script or HTML via the (1) LoName parameter in (a) week.php and
(b) month.php and (2) AddressLink parameter in (c) event.php.
|
| CVE-2006-2796 |
Cross-site scripting (XSS) vulnerability in gallery.php in Captivate
1.0 allows remote attackers to inject arbitrary web script or HTML via
the page parameter, which is reflected in an error message.
|
| CVE-2006-2795 |
Multiple cross-site scripting (XSS) vulnerabilities in XiTi Tracking
Script 6 and 7 RC allow remote attackers to inject arbitrary web
script or HTML via (1) the xtref parameter in xiti.js and (2) an HTTP
Referer header field. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-2785 |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before
1.5.0.4 allows user-assisted remote attackers to inject arbitrary web
script or HTML by tricking a user into (1) performing a "View Image"
on a broken image in which the SRC attribute contains a Javascript
URL, or (2) selecting "Show only this frame" on a frame whose SRC
attribute contains a Javascript URL.
|
| CVE-2006-2783 |
Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode
Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to
the parser, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via a BOM sequence in the middle of a
dangerous tag such as SCRIPT.
|
| CVE-2006-2774 |
Cross-site scripting (XSS) vulnerability in search.php in QontentOne
CMS allows remote attackers to inject arbitrary web script or HTML via
the search_phrase parameter.
|
| CVE-2006-2772 |
Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps
hogstorp guestbook 2.0 allows remote attackers to inject arbitrary web
script or HTML via the (1) name, (2) email, and (3) headline
parameters. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2006-2765 |
Cross-site scripting (XSS) vulnerability in news_information.php in
Interlink Advantage allows remote attackers to inject arbitrary web
script or HTML via the flag parameter.
|
| CVE-2006-2764 |
Cross-site scripting (XSS) vulnerability in GuestbookXL 1.3 allows
remote attackers to inject arbitrary web script or HTML via a
javascript URI in an IMG tag in a comment field to (1) guestwrite.php
or (2) guestbook.php.
|
| CVE-2006-2757 |
Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows
remote attackers to inject arbitrary web script or HTML via the (1)
start parameter in (a) index.php; (2) forumID parameter in index.php,
(b) newtopic.php, and (c) reply.php; and (3) ID parameter to (d)
edit.php.
|
| CVE-2006-2755 |
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads
5.x and earlier allows remote attackers to inject arbitrary web script
or HTML via the debug parameter, as demonstrated by stealing MD5
hashes of passwords.
|
| CVE-2006-2751 |
Cross-site scripting (XSS) vulnerability in Open Searchable Image
Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject
arbitrary web scripts or HTML via the item_list parameter in
search.php.
|
| CVE-2006-2750 |
Cross-site scripting (XSS) vulnerability in the do_mysql_query
function in core.php for Open Searchable Image Catalogue (OSIC) before
0.7.0.1 allows remote attackers to inject arbitrary web scripts or
HTML via failed SQL queries, which is reflected in an error message.
|
| CVE-2006-2749 |
SQL injection vulnerability in search.php in Open Searchable Image
Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject
arbitrary SQL commands via the (1) txtCustomField and (2)
CustomFieldID array parameters.
|
| CVE-2006-2748 |
SQL injection vulnerability in the do_mysql_query function in core.php
for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows
remote attackers to inject arbitrary SQL commands via multiple
vectors, as demonstrated by the (1) type parameter in
adminfunctions.php and the (2) catalogue_id parameter in
editcatalogue.php.
|
| CVE-2006-2746 |
Multiple cross-site scripting (XSS) vulnerabilities in F@cile
Interactive Web 0.8.5 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) lang parameter in index.php,
and the (2) mytheme and (3) myskin parameters in multiple "p-themes"
index.inc.php files including (c) lowgraphic, (d) classic, (e) puzzle,
(f) simple, and (g) ciao. NOTE: vectors 2 and 3 might be resultant
from file inclusion issues.
|
| CVE-2006-2741 |
Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3
allow remote attackers to inject arbitrary web script or HTML via the
q parameter in forgot.php, which is echoed in an error message, and
other unspecified vectors.
|
| CVE-2006-2729 |
Cross-site scripting (XSS) vulnerability in superalbum/index.php in
Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web
script or HTML via the gal parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-2728 |
Cross-site scripting (XSS) vulnerability in superalbum/index.php in
Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web
script or HTML via the pic parameter.
|
| CVE-2006-2724 |
Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote
authenticated administrators to inject arbitrary HTML or web script to
other administrators via the "Admin note" feature, a different
vulnerability than CVE-2006-2227.
|
| CVE-2006-2721 |
Cross-site scripting (XSS) vulnerability in news.php in VARIOMAT
allows remote attackers to inject arbitrary HTML or web script via the
subcat parameter. NOTE: this issue might be resultant from SQL
injection.
|
| CVE-2006-2720 |
SQL injection vulnerability in news.php in VARIOMAT allows remote
attackers to execute arbitrary SQL commands via the subcat parameter.
|
| CVE-2006-2699 |
Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog
1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML
or web script via the image argument in a show action.
|
| CVE-2006-2697 |
Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0
allow remote attackers to execute arbitrary SQL commands via the (1)
startletter parameter in userview.asp and the (2) forumname parameter
in topics.asp.
|
| CVE-2006-2696 |
Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) startletter parameter in userview.asp and the (2) catid parameter
in topics.asp.
|
| CVE-2006-2689 |
Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) debut_image parameter in (a) article-album.php3, (2)
date parameter in (b) rubrique.php3, and the (3) perso and (4) aide
parameters to (c) an unknown script, probably index.php.
|
| CVE-2006-2687 |
Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC
Membership System 1.1a and earlier allows remote attackers to inject
arbitrary web script or HTML via the email address (useremail
parameter).
|
| CVE-2006-2684 |
Cross-site scripting (XSS) vulnerability in the search module in CMS
Mundo 1.0 allows remote attackers to inject arbitrary web script or
HTML via the searchstring parameter.
|
| CVE-2006-2680 |
Cross-site scripting (XSS) vulnerability in index.php in AZ Photo
Album Script Pro allows remote attackers to inject arbitrary web
script or HTML via the gazpart parameter.
|
| CVE-2006-2678 |
Multiple cross-site scripting (XSS) vulnerabilities in Pre News
Manager 1.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) id parameter to (a) index.php, and the (2) nid
parameter to (b) news_detail.php, (c) email_story.php, (d)
thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g)
send_comments.php.
|
| CVE-2006-2673 |
Cross-site scripting (XSS) vulnerability in search.html in Bulletin
Board Elite-Board (E-Board) 1.1 allows remote attackers to inject
arbitrary web script or HTML via the search box.
|
| CVE-2006-2672 |
Multiple cross-site scripting (XSS) vulnerabilities in Realty Pro One
allow remote attackers to inject arbitrary web script or HTML via the
(1) listingid parameter to (a) images.php, (b) index_other.php, or (c)
request_info.php; (2) propertyid parameter to (d) searchlookup.php,
(3) id parameter to (e) images.php, or (4) agentid parameter to (f)
request_info.php. NOTE: some of these issues might be resultant from
SQL injection.
|
| CVE-2006-2670 |
Multiple cross-site scripting (XSS) vulnerabilities in ChatPat 1.0
allow remote attackers to inject arbitrary web script or HTML via a
chat message in (1) fastchat.php and (2) fastshow.php.
|
| CVE-2006-2669 |
Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping
Mall 1.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) search parameter in search.php (the "search box"), (2) the
prodid parameter in detail.php, and the (3) cid parameter in
products.php.
|
| CVE-2006-2664 |
Cross-site scripting (XSS) vulnerability in iFdate 1.2 allows remote
attackers to inject arbitrary web script or HTML via the (1) username,
(2) password fields, or certain other input text boxes.
|
| CVE-2006-2663 |
Multiple cross-site scripting (XSS) vulnerabilities in iFlance 1.1
allow remote attackers to inject arbitrary web script or HTML via
certain inputs to (1) acc_verify.php or (2) project.php.
|
| CVE-2006-2653 |
Cross-site scripting (XSS) vulnerability in login_error.shtml for
D-Link DSA-3100 allows remote attackers to inject arbitrary HTML or
web script via an encoded uname parameter.
|
| CVE-2006-2652 |
Cross-site scripting (XSS) vulnerability in WikiNi 0.4.2 and earlier
allows remote attackers to inject arbitrary HTML and web script by
editing a Wiki page to contain the script.
|
| CVE-2006-2651 |
Cross-site scripting (XSS) vulnerability in index.php in Vacation
Rental Script 1.0 allows remote attackers to inject arbitrary web
script or HTML via the obj parameter.
|
| CVE-2006-2649 |
Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php,
(b) search_cat.php, (c) search_price.php, and (d) product_details.php
in the cosmicshop directory for CosmicShoppingCart allow remote
attackers to inject arbitrary web script or HTML via multiple
unspecified parameters, as demonstrated by the (1) query parameter in
search.php and the (2) data parameter in search_cat.php.
|
| CVE-2006-2648 |
Cross-site scripting (XSS) vulnerability in perform_search.asp for
ASPBB 0.52 and earlier allows remote attackers to inject arbitrary
HTML or web script via the search parameter.
|
| CVE-2006-2643 |
Cross-site scripting (XSS) vulnerability in index.php in Monster Top
List (MTL) 1.4 allows remote attackers to inject arbitrary web script
or HTML via the user_error_message parameter.
|
| CVE-2006-2642 |
** UNVERIFIABLE **
NOTE: this issue does not contain any verifiable or actionable
details. Cross-site scripting (XSS) vulnerability in Marco M. F. De
Santis Php-residence 0.6 and earlier allows remote attackers to inject
arbitrary web script or HTML via "any of its input." NOTE: the
original disclosure is based on vague researcher claims without vendor
acknowledgement; therefore this identifier cannot be linked with any
future identifier that identifies more specific vectors. Perhaps this
should not be included in CVE.
|
| CVE-2006-2641 |
** UNVERIFIABLE **
NOTE: this issue does not contain any verifiable or actionable
details. Cross-site scripting (XSS) vulnerability in John Frank Asset
Manager (AssetMan) 2.4a and earlier allows remote attackers to inject
arbitrary web script or HTML via "any of its input." NOTE: the
original disclosure is based on vague researcher claims without vendor
acknowledgement; therefore this identifier cannot be linked with any
future identifier that identifies more specific vectors. Perhaps this
should not be included in CVE.
|
| CVE-2006-2640 |
Cross-site scripting (XSS) vulnerability in OmegaMw7a.ASP in OMEGA
(aka Omegasoft) INterneSErvicesLosungen (INSEL) allows remote
attackers to inject arbitrary web script or HTML via the WCE
parameter.
|
| CVE-2006-2639 |
Cross-site scripting (XSS) vulnerability in the input forms in
prattmic and Master5006 PHPSimpleChoose 0.3 allows remote attackers to
inject arbitrary web script or HTML via a javascript URI in the SRC
attribute of an IMG element.
|
| CVE-2006-2637 |
Cross-site scripting (XSS) vulnerability in view.php in TuttoPhp (1)
Morris Guestbook 1, (2) Pretty Guestbook 1, and (3) Smile Guestbook 1
allows remote attackers to inject arbitrary web script or HTML via a
javascript URI in the SRC attribute of an IMG element in the pagina
parameter.
|
| CVE-2006-2635 |
Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka
Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary
web script or HTML via malformed nested HTML tags such as
"<scr<script>ipt>" in (1) offset and (2) days parameters in (a)
tiki-lastchanges.php, the (3) find and (4) offset parameters in (b)
tiki-orphan_pages.php, the (5) offset and (6) initial parameters in
(c) tiki-listpages.php, and (7) an unspecified field in (d)
tiki-remind_password.php; and allow remote authenticated users with
admin privileges to inject arbitrary web script or HTML via (8) an
unspecified field in a metatags action in (e) tiki-admin.php, the (9)
offset parameter in (f) tiki-admin_rssmodules.php, the (10) offset and
(11) max parameters in (g) tiki-syslog.php, the (12) numrows parameter
in (h) tiki-adminusers.php, (13) an unspecified field in (i)
tiki-adminusers.php, (14) an unspecified field in (j)
tiki-admin_hotwords.php, unspecified fields in (15) "Assign new
module" and (16) "Create new user module" in (k)
tiki-admin_modules.php, (17) an unspecified field in "Add
notification" in (l) tiki-admin_notifications.php, (18) the offset
parameter in (m) tiki-admin_notifications.php, the (19) Name and (20)
Dsn fields in (o) tiki-admin_dsn.php, the (21) offset parameter in (p)
tiki-admin_content_templates.php, (22) an unspecified field in "Create
new template" in (q) tiki-admin_content_templates.php, and the (23)
offset parameter in (r) tiki-admin_chat.php.
|
| CVE-2006-2634 |
Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under
(LDU) in Neocrome Seditio 102 allows remote attackers to inject
arbitrary web script or HTML via an HTTP Referer field.
|
| CVE-2006-2632 |
Cross-site scripting (XSS) vulnerability in Andrew Godwin ByteHoard
2.1 and earlier allows remote authenticated users to inject arbitrary
web script or HTML via file descriptions.
|
| CVE-2006-2618 |
Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host
Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow
remote attackers to inject arbitrary web script or HTML via the "write
a review" box. NOTE: since user reviews do not require administrator
privileges, and an auto-approve mechanism exists, this issue is a
vulnerability.
|
| CVE-2006-2611 |
Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in
the variable handler in MediaWiki 1.6.x before r14349 allows remote
attackers to inject arbitrary Javascript via unspecified vectors,
possibly involving the usage of the | (pipe) character.
|
| CVE-2006-2610 |
Cross-site scripting (XSS) vulnerability in view.php in phpRaid 2.9.5
allows remote attackers to inject arbitrary web script or HTML via the
(1) URL query string and the (2) Sort parameter.
|
| CVE-2006-2606 |
Cross-site scripting (XSS) vulnerability in Chatty, possibly 1.0.2 and
other versions, allows remote attackers to inject arbitrary web script
or HTML via the username.
|
| CVE-2006-2605 |
Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
chatbox, probably involving the ctext parameter to send.php.
|
| CVE-2006-2586 |
Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier
allows remote attackers to inject arbitrary HTML or web script via the
HTTP_REFERER header in an HTTP request.
|
| CVE-2006-2584 |
Multiple cross-site scripting (XSS) vulnerabilities in post.php in
SkyeBox 1.2.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) name or (2) message parameters. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information, although it was likely prompted by a vague
announcement from a researcher who incorrectly referred to the product
as "SkyeShoutbox."
|
| CVE-2006-2581 |
Cross-site scripting (XSS) vulnerability in Wiki content in RWiki
2.1.0pre1 through 2.1.0 allows remote attackers to inject arbitrary
web script or HTML via unknown attack vectors.
|
| CVE-2006-2572 |
Cross-site scripting (XSS) vulnerability in index.php in DGBook 1.0
allows remote attackers to inject arbitrary web script or HTML via the
(1) name, (2) homepage, (3) email, and (4) address parameters.
|
| CVE-2006-2571 |
Cross-site scripting (XSS) vulnerability in search.html in Alkacon
OpenCms 6.0.0, 6.0.2, and 6.0.3 allows remote attackers to inject
arbitrary web script or HTML via the query parameter in a search
action.
|
| CVE-2006-2567 |
Cross-site scripting (XSS) vulnerability in submit_article.php in
Alstrasoft Article Manager Pro 1.6 allows remote attackers to inject
arbitrary web script or HTML when submitting an article, as
demonstrated using a javascript URI in a Cascading Style Sheets (CSS)
property of a STYLE attribute of an element.
|
| CVE-2006-2564 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
AlstraSoft E-Friends allow remote attackers to inject arbitrary web
script or HTML by (1) posting a blog, (2) posting a listing, (3)
posting an event, (4) adding comments, or (5) sending a message.
|
| CVE-2006-2558 |
Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier
allows remote attackers to inject arbitrary HTML or web script via the
User-Agent (useragent) header in an HTTP request, which is not
filtered when the log files are viewed.
|
| CVE-2006-2556 |
Cross-site scripting (XSS) vulnerability in Florian Amrhein NewsPortal
before 0.37, and possibly TR Newsportal (TRanx rebuilded), allows
remote attackers to inject arbitrary web script or HTML via unknown
vectors.
|
| CVE-2006-2553 |
Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl
1.0 allows remote attackers to inject arbitrary HTML or web script via
the dcid parameter to dc.php. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information. This issue appears to be independent from a different
issue that involves the same vector.
|
| CVE-2006-2545 |
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites
1.1 allow remote attackers to inject arbitrary web script or HTML via
the (1) id parameter in stats.php and (2) unspecified inputs in
lostid.php, probably the searchthis parameter. NOTE: one or more of
these vectors might be resultant from SQL injection.
|
| CVE-2006-2536 |
Cross-site scripting (XSS) vulnerability in Destiney Links Script
2.1.2 allows remote attackers to inject arbitrary web script or HTML
via the (1) "Search" (term parameter in index.php) and (2) "Add a
Site" (add.php) fields.
|
| CVE-2006-2533 |
Cross-site scripting (XSS) vulnerability in (1) addWeblog.php and (2)
leaveComments.php in Destiney Rated Images Script 0.5.0 does not
properly filter all vulnerable HTML tags, which allows remote
attackers to inject arbitrary web script or HTML via Javascript in a
DIV tag.
|
| CVE-2006-2532 |
stats.php in Destiney Rated Images Script 0.5.0 allows remote
attackers to obtain the installation path via an invalid s parameter,
which displays the path in an error message. NOTE: this issue was
originally claimed to be SQL injection, but CVE analysis shows that
the problem is related to an invalid value that prevents some
variables from being set.
|
| CVE-2006-2524 |
Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors when processing the user date format.
|
| CVE-2006-2518 |
Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows
remote attackers to inject arbitrary web script or HTML via the
BL[be_cnt_plainhtml] parameter to include/inc_tmpl/content/cnt6.inc.php.
|
| CVE-2006-2515 |
Cross-site scripting (XSS) vulnerability in index.php in Hiox
Guestbook 3.1 allows remote attackers to inject arbitrary web script
or HTML via the input forms for signing the guestbook.
|
| CVE-2006-2510 |
Cross-site scripting (XSS) vulnerability in the URL submission form in
YourFreeWorld.com Short Url & Url Tracker Script allows remote
attackers to inject arbitrary web script or HTML via an unspecified
form for submitting URLs.
|
| CVE-2006-2506 |
Multiple cross-site scripting (XSS) vulnerabilities in search.php in
Sphider allow remote attackers to inject arbitrary web script or HTML
via (1) the PATH_INFO and (2) the category parameter.
|
| CVE-2006-2501 |
Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9
and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE
Application Server 7 Platform and Standard Edition Update 6 and
earlier, and Java System Application Server 7 2004Q2 Standard and
Enterprise Edition Update 2 and earlier, allows remote attackers to
inject arbitrary web script or HTML via unknown attack vectors,
possibly involving error messages.
|
| CVE-2006-2500 |
Cross-site scripting (XSS) vulnerability in add_news.asp in
CodeAvalanche News (CANews) 1.2 allows remote attackers to inject
arbitrary web script or HTML via the Headline field. NOTE: if this
issue is limited to administrators, and if it is expected behavior for
administrators to be able to generate HTML, then this is not a
vulnerability.
|
| CVE-2006-2497 |
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) action parameter to default.asp or (2) get parameter to
profile.asp.
|
| CVE-2006-2491 |
Cross-site scripting (XSS) vulnerability in (1) index.php and (2)
bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote
attackers to inject arbitrary web script or HTML via the query string,
which is not properly filtered when it is accessed using the
$_SERVER["PHP_SELF"] variable.
|
| CVE-2006-2490 |
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP
Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before
2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to
inject arbitrary web script or HTML via URL-encoded values in (1) the
query string to help/help, (2) the get_image_info_abspath parameter to
control/eventplayer, and (3) the source_ip parameter to events.tar.
|
| CVE-2006-2488 |
Multiple cross-site scripting (XSS) vulnerabilities in Spymac WebOS
(WOS) 5.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) del_folder, (2) nick, or (3) action parameters to (a)
notes/index.php, (4) curr parameter to (b) ipod/get_ipod.php, and in
(c) login.php.
|
| CVE-2006-2484 |
Cross-site scripting (XSS) vulnerability in index.html in IceWarp
WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary
web script or HTML via the PHPSESSID parameter.
|
| CVE-2006-2477 |
Cross-site scripting (XSS) vulnerability in the administrative
interface Bitrix Site Manager 4.1.x allows remote attackers to inject
arbitrary web script or HTML via unspecified inputs.
|
| CVE-2006-2473 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78
allows remote attackers to inject arbitrary web script or HTML via the
p parameter. NOTE: this issue has been disputed by the vendor and a
third party who is affiliated with the product. The vendor states
"You cannot insert code in a wikipage or via URL parameters as they
are all escaped before usage, so nothing can be compromised at other
sites."
|
| CVE-2006-2431 |
Cross-site scripting (XSS) vulnerability in the 500 Internal Server
Error page on the SOAP port (8880/tcp) in IBM WebSphere Application
Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to
6.0.2.7, allows remote attackers to inject arbitrary web script or
HTML via the URI, which is contained in a FAULTACTOR element on this
page. NOTE: some sources have reported the element as "faultfactor,"
but this is likely erroneous.
|
| CVE-2006-2425 |
Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in
PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers
to inject arbitrary web script or HTML via the (1) f, (2) d, and (3)
ref parameters, and the (4) "MAKE DIR" and (5) "Full file name"
fields.
|
| CVE-2006-2423 |
Cross-site scripting (XSS) vulnerability in ftplogin/index.php in
Confixx 3.1.2 allows remote attackers to inject arbitrary web script
or HTML via the login parameter.
|
| CVE-2006-2420 |
Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows
remote attackers to conduct cross-site scripting (XSS) attacks via a
title element with HTML encoded sequences such as ">", which are
automatically decoded by some RSS readers. NOTE: this issue is not in
Bugzilla itself, but rather due to design or documentation
inconsistencies within RSS, or implementation vulnerabilities in RSS
readers. While this issue normally would not be included in CVE, it
is being identified since the Bugzilla developers have addressed it.
|
| CVE-2006-2419 |
Cross-site scripting (XSS) vulnerability in index.php in Directory
Listing Script allows remote attackers to inject arbitrary web script
or HTML via the dir parameter.
|
| CVE-2006-2418 |
Cross-site scripting (XSS) vulnerabilities in certain versions of
phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary
web script or HTML via the db parameter in unknown scripts.
|
| CVE-2006-2417 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before
2.8.0.4 allows remote attackers to inject arbitrary web script or HTML
via the theme parameter in unknown scripts. NOTE: the lang parameter
is already covered by CVE-2006-2031.
|
| CVE-2006-2415 |
Multiple cross-site scripting (XSS) vulnerabilities in FlexChat 2.0
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) username and (2) CFTOKEN parameter in (a) index.cfm
and (3) CFTOKEN and (4) CFID parameter in (b) chat.cfm.
|
| CVE-2006-2397 |
Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) rep parameter to (a) index.php or (b) diapo.php or (2)
image parameter to (c) affich.php. NOTE: item 1a might be resultant
from directory traversal.
|
| CVE-2006-2396 |
Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote
attackers to inject arbitrary web script via the browse parameter.
|
| CVE-2006-2394 |
Cross-site scripting (XSS) vulnerability in chat.php in PHP Live
Helper allows remote attackers to inject arbitrary web script or HTML
via the PHPSESSID parameter.
|
| CVE-2006-2390 |
Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows
remote attackers to inject arbitrary web script or HTML via the vname
parameter in the comments functionality.
|
| CVE-2006-2368 |
Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka
Clanpage System) 1.1 allows remote attackers to inject arbitrary web
script or HTML via the page parameter.
|
| CVE-2006-2367 |
Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka
Clanpage System) 1.0 and 1.1 allows remote attackers to inject
arbitrary web script or HTML via the func parameter in a search
function.
|
| CVE-2006-2365 |
Cross-site scripting (XSS) vulnerability in a_login.php in Vizra
allows remote attackers to inject arbitrary web script or HTML via the
message parameter.
|
| CVE-2006-2364 |
Cross-site scripting (XSS) vulnerability in the validation feature in
Macromedia ColdFusion 5 and earlier allows remote attackers to inject
arbitrary web script or HTML via a "_required" field when the
associated normal field is missing or empty, which is not sanitized
before being presented in an error message.
|
| CVE-2006-2360 |
SQL injection vulnerability in charts.php in the Chart mod for phpBB
allows remote attackers to execute arbitrary SQL commands via the id
parameter.
|
| CVE-2006-2359 |
Cross-site scripting (XSS) vulnerability in charts.php in the Chart
mod for phpBB allows remote attackers to inject arbitrary web script
or HTML via the id parameter. NOTE: this issue might be resultant
from SQL injection.
|
| CVE-2006-2358 |
Multiple cross-site scripting (XSS) vulnerabilities in various scripts
in Web-Labs CMS allow remote attackers to inject arbitrary web script
or HTML via (1) the search parameter and (2) unspecified fields
related to e-mail alerts. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-2352 |
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch
WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow
remote attackers to inject arbitrary web script or HTML via unknown
vectors in (1) NmConsole/Tools.asp and (2)
NmConsole/DeviceSelection.asp. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-2351 |
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch
WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow
remote attackers to inject arbitrary web script or HTML via the (1)
sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp
or (3) sHostname parameter to (b) NmConsole/ToolResults.asp.
|
| CVE-2006-2349 |
E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to
upload or modify arbitrary files, and execute arbitrary code, via a
direct request to (1) common/html_editor/image_browser.upload.html,
(2) common/html_editor/image_browser.html, or (3)
common/html_editor/html_editor.html. NOTE: this can also be used for
cross-site scripting (XSS) attacks by uploading cascading style sheet
(.CSS) files.
|
| CVE-2006-2348 |
Cross-site scripting (XSS) vulnerability in form_grupo.html in
E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to
inject arbitrary web script or HTML via the id parameter. NOTE: this
issue might be resultant from SQL injection.
|
| CVE-2006-2345 |
Cross-site scripting (XSS) vulnerability in inc/elementz.php in
AliPAGER 1.5 allows remote attackers to inject arbitrary web script or
HTML via the ubild parameter. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information. NOTE: this issue might be resultant from SQL injection.
|
| CVE-2006-2343 |
Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine
OpManager 6.0 allows remote attackers to inject arbitrary web script
or HTML via the searchTerm parameter. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-2340 |
Cross-site scripting (XSS) vulnerability in PassMasterFlex and
PassMasterFlexPlus (PassMasterFlex+) 1.2 and earlier allows remote
attackers to inject arbitrary web script or HTML via the (1) username,
(2) password, or (3) User-Agent HTTP header in the Hack Log.
|
| CVE-2006-2325 |
Cross-site scripting (XSS) vulnerability in index.php in
OnlyScript.info Online Universal Payment System Script allows remote
attackers to inject arbitrary web script or HTML via the read
parameter. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information. Also, this
issue might be resultant from directory traversal.
|
| CVE-2006-2321 |
Multiple cross-site scripting (XSS) vulnerabilities in Ideal Science
Ideal BB 1.5.4a and earlier allow remote attackers to inject arbitrary
web script or HTML via unknown vectors. NOTE: due to lack of details
from the researcher, it is not clear whether this overlaps
CVE-2004-2207.
|
| CVE-2006-2311 |
Cross-site scripting (XSS) vulnerability in BlueDragon Server and
Server JX 6.2.1.286 for Windows allows remote attackers to inject
arbitrary web script or HTML via the filename in a request to a (1)
.cfm or (2) .cfml file, which reflects the result in the default error
page.
|
| CVE-2006-2307 |
Cross-site scripting (XSS) vulnerability in Website Baker CMS before
2.6.4 allows remote attackers to inject arbitrary web script or HTML
via a user display name.
|
| CVE-2006-2306 |
Cross-site scripting (XSS) vulnerability in moreinfo.asp in
EPublisherPro allows remote attackers to inject arbitrary web script
or HTML via the title parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-2305 |
Multiple cross-site scripting (XSS) vulnerabilities in Jadu CMS allow
remote attackers to inject arbitrary web script or HTML via the (1)
forename, (2) surname, (3) reg_email, (4) email_conf, (5) company, (6)
city, (7) postcode, or (8) telephone parameters to
site/scripts/register.php. NOTE: the provenance of this information is
unknown; the details are obtained from third party information.
|
| CVE-2006-2294 |
Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows
remote attackers to inject arbitrary web script or HTML via the pfad
parameter in (1) index.php and (2) galerie.php. NOTE: this issue
might be resultant from directory traversal.
|
| CVE-2006-2291 |
Cross-site scripting (XSS) vulnerability in calendar_new.asp in
IA-Calendar allows remote attackers to inject arbitrary web script or
HTML via the TypeName1 parameter. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-2290 |
Multiple cross-site scripting (XSS) vulnerabilities in kommentar.php
in 2005-Comments-Script allow remote attackers to inject arbitrary web
script or HTML via the (1) id, (2) email, and (3) url parameter.
|
| CVE-2006-2287 |
Multiple cross-site scripting (XSS) vulnerabilities in Vision Source
0.6 and earlier allow remote attackers to inject arbitrary web script
or HTML via the fields in a user's profile.
|
| CVE-2006-2282 |
Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
javascript URI in the URL of an avatar, possibly related to the avatar
parameter in register.php.
|
| CVE-2006-2269 |
Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3
and earlier allows remote attackers to inject arbitrary web script or
HTML via a JavaScript event in a BBCode img tag.
|
| CVE-2006-2262 |
Cross-site scripting (XSS) vulnerability in index.php in singapore
0.9.7 allows remote attackers to inject arbitrary web script or HTML
via the image parameter.
|
| CVE-2006-2260 |
Cross-site scripting (XSS) vulnerability in the project module
(project.module) in Drupal 4.5 and 4.6 allows remote attackers to
inject arbitrary web script or HTML via unknown attack vectors.
|
| CVE-2006-2258 |
Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule
1.0 allows remote attackers to inject arbitrary web script or HTML via
the Error parameter.
|
| CVE-2006-2257 |
Cross-site scripting (XSS) vulnerability in index.php in easyEvent 1.2
allows remote attackers to inject arbitrary web script or HTML via the
curr_year parameter.
|
| CVE-2006-2252 |
Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0
allows remote attackers to inject arbitrary web script or HTML via the
q parameter.
|
| CVE-2006-2249 |
Multiple cross-site scripting (XSS) vulnerabilities in search.php in
CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers
to inject arbitrary web script or HTML via the (1) user, (2) story, or
(3) title parameters.
|
| CVE-2006-2246 |
Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition
allows remote attackers to inject arbitrary web script or HTML via
text fields when adding a blog entry.
|
| CVE-2006-2243 |
Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News
Portal allow remote attackers to inject arbitrary web script or HTML
via the ID parameter to (1) comentarii.php or (2) view.php. NOTE:
this issue might be resultant from SQL injection.
|
| CVE-2006-2234 |
Multiple cross-site scripting (XSS) vulnerabilities in TyroCMS beta
1.0 allow remote attackers to inject arbitrary web script or HTML via
(1) a javascript URI in an img BBCode tag, or a JavaScript event in a
(2) url BBCode tag or (3) color BBCode tag.
|
| CVE-2006-2232 |
Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook
20060211 allows remote attackers to inject arbitrary web script or
HTML via the Comments field when signing the guestbook.
|
| CVE-2006-2231 |
Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in
Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers
to inject arbitrary web script or HTML via the (1) mail, (2) site, (3)
city, (4) state, (5) country, and possibly (6) name fields, which are
viewed via viewguest.cgi.
|
| CVE-2006-2228 |
Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora)
4.2.0 allows remote attackers to inject arbitrary web script or HTML
via a post with a BBCode tag that contains a JavaScript event name
followed by whitespace before the '=' (equals) character, which
bypasses a restrictive regular expression that attempts to remove
onmouseover and other events.
|
| CVE-2006-2227 |
Cross-site scripting (XSS) vulnerability in misc.php in PunBB 1.2.11
allows remote attackers to inject arbitrary web script or HTML via the
req_message parameter, because the value of the redirect_url parameter
is not sanitized.
|
| CVE-2006-2211 |
Absolute path traversal vulnerability in index.php in 321soft
PhP-Gallery 0.9 allows remote attackers to browse arbitrary
directories via the path parameter.
|
| CVE-2006-2210 |
Cross-site scripting (XSS) vulnerability in index.php in 321soft
PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script
or HTML via the path parameter. NOTE: this issue might be resultant
from the directory traversal vulnerability.
|
| CVE-2006-2208 |
Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php
in MyNews 1.6.2 allow remote attackers to inject arbitrary web script
or HTML via the (1) hash and (2) page parameters.
|
| CVE-2006-2195 |
Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before
3.1.1 allows remote attackers to inject arbitrary web script or HTML
via (1) templates/problem/problem.inc and (2) test.php.
|
| CVE-2006-2190 |
Cross-site scripting (XSS) vulnerability in ow-shared.pl in
OpenWebMail (OWM) 2.51 and earlier allows remote attackers to inject
arbitrary web script or HTML via the sessionid parameter in (1)
openwebmail-send.pl, (2) openwebmail-advsearch.pl, (3)
openwebmail-folder.pl, (4) openwebmail-prefs.pl, (5)
openwebmail-abook.pl, (6) openwebmail-read.pl, (7) openwebmail-cal.pl,
and (8) openwebmail-webdisk.pl. NOTE: the openwebmail-main.pl vector
is already covered by CVE-2005-2863.
|
| CVE-2006-2188 |
Multiple cross-site scripting (XSS) vulnerabilities in CMScout 1.10
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the Body field of a private message (PM), (2) BBCode, or
(3) a forum post.
|
| CVE-2006-2187 |
Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1
beta and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) a parameter in i.php, and the (2) album and (3)
image parameters in index.php.
|
| CVE-2006-2184 |
Cross-site scripting (XSS) vulnerability in search.php in PHPKB
Knowledge Base allows remote attackers to inject arbitrary web script
or HTML via the searchkeyword parameter. NOTE: the issue was
originally disputed by the vendor, but on 20060519, the vendor
notified CVE that "We have fixed all the mentioned issues and now the
search section of PHPKB script is free from any XSS issues."
|
| CVE-2006-2181 |
Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow
parameter to showpic.php.
|
| CVE-2006-2178 |
Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild
allow remote attackers to inject arbitrary web script or HTML via the
(1) SessionID parameter to login.asp, (2) ProductIndex parameter to
browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading
parameter to result.asp. NOTE: vectors 1 and 2 might be resultant
from SQL injection.
|
| CVE-2006-2177 |
Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0
allows remote attackers to inject arbitrary web script or HTML via the
cat parameter.
|
| CVE-2006-2176 |
Multiple cross-site scripting (XSS) vulnerabilities in links.php in
PHP Linkliste 1.0b allow remote attackers to inject arbitrary web
script or HTML via the (1) new_input, (2) new_url, or (3) new_name
parameter.
|
| CVE-2006-2174 |
Multiple cross-site scripting (XSS) vulnerabilities in
admin/server_day_stats.php in Virtual Hosting Control System (VHCS)
allow remote attackers to inject arbitrary web script or HTML via the
(1) day, (2) month, or (3) year parameter.
|
| CVE-2006-2167 |
Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0,
possibly in register.php, allows remote attackers to inject arbitrary
web script or HTML by setting the username field to contain JavaScript
in the SRC attribute of an IMG element.
|
| CVE-2006-2165 |
Multiple cross-site scripting (XSS) vulnerabilities in Avactis
Shopping Cart 0.1.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) category_id parameter in (a)
store_special_offers.php and (b) store.php and (2) prod_id parameter
in (c) product_info.php. NOTE: this issue might be resultant from SQL
injection.
|
| CVE-2006-2163 |
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart
3.33 and earlier allows remote attackers to inject arbitrary web
script or HTML via the setbackurl parameter.
|
| CVE-2006-2160 |
Cross-site scripting (XSS) vulnerability in Russcom Network Loginphp
(Russcom.Loginphp) allows remote attackers to inject arbitrary web
script or HTML via the username field when registering.
|
| CVE-2006-2153 |
Cross-site scripting (XSS) vulnerability in HTM_PASSWD in DirectAdmin
Hosting Management allows remote attackers to inject arbitrary web
script or HTML via the domain parameter.
|
| CVE-2006-2146 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
HB-NS 1.1.6 allow remote attackers to inject arbitrary web script or
HTML via the (1) poster_name, (2) poster_email, (3) poster_homepage,
or (4) message parameter.
|
| CVE-2006-2143 |
Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB
1.0.16 allow remote attackers to inject arbitrary web script or HTML
via Javascript events such as "onmouseover" in the (1) color, (2)
size, or (3) url bbcode tags.
|
| CVE-2006-2141 |
Cross-site scripting (XSS) vulnerability in popup_image in
Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote
attackers to inject arbitrary web script or HTML via the pos argument.
|
| CVE-2006-2140 |
Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0
and earlier allow remote attackers to inject arbitrary web script via
the (1) referral parameter to signup.php or (2) id parameter to
members.php.
|
| CVE-2006-2138 |
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29
allows remote attackers to inject arbitrary web script or HTML via the
sessionid parameter.
|
| CVE-2006-2128 |
Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote
attackers to execute arbitrary SQL commands via the (1) email and (2)
password parameter to (a) admin/login.php, (3) find_str parameter to
(b) search.php, or (4) artid parameter to (c) art.php, or (5) catid
parameter to (d) cat.php.
|
| CVE-2006-2124 |
Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id,
and (6) action parameters in index.php.
|
| CVE-2006-2117 |
Cross-site scripting (XSS) vulnerability in Thyme 1.3 allows remote
attackers to inject arbitrary web script or HTML via the search page.
|
| CVE-2006-2109 |
Cross-site scripting (XSS) vulnerability in the parse_query_str
function in include/print.php in JSBoard 2.0.10 and 2.0.11, and
possibly other versions before 2.0.12, allows remote attackers to
inject arbitrary web script or HTML via parameters that are set as
global variables within the program, as demonstrated using the table
parameter to login.php.
|
| CVE-2006-2106 |
Cross-site scripting (XSS) vulnerability in Edgewall Software Trac
0.9.4 and earlier allows remote attackers to inject arbitrary web
script or HTML via unknown attack vectors related to a "wiki macro."
|
| CVE-2006-2104 |
Multiple cross-site scripting (XSS) vulnerabilities in Kamgaing Email
System (kmail) 2.3 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) d parameter to main.php,
ordner parameter to (2) main.php, or (3) webdisk.php, (4) draft
parameter to compose.php, or (5) m, or (6) y parameter to
calendar.php.
|
| CVE-2006-2090 |
Multiple SQL injection vulnerabilities in misc.php in MySmartBB 1.1.x
allow remote attackers to execute arbitrary SQL commands via the (1)
id and (2) username parameters.
|
| CVE-2006-2089 |
Multiple cross-site scripting (XSS) vulnerabilities in misc.php in
MySmartBB 1.1.x allow remote attackers to inject arbitrary web script
or HTML via the (1) id and (2) username parameters.
|
| CVE-2006-2088 |
Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open
Bulletin Board (OpenBB) 1.0.6 allow remote attackers to inject
arbitrary web script or HTML via (1) the FID parameter in board.php
and (2) the TID parameter in read.php. NOTE: the SQL injection issues
are already covered by CVE-2005-1612 (read.php) and CVE-2005-2566
(board.php).
|
| CVE-2006-2084 |
Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3
Pro and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) month and (2) year parameters in (a) index.php,
and the (3) mod parameter in (b) admin.php.
|
| CVE-2006-2080 |
SQL injection vulnerability in portfolio_photo_popup.php in Verosky
Media Instant Photo Gallery 1.0.2 allows remote attackers to execute
arbitrary SQL commands via the id parameter, which is not cleansed
before calling the count_click function in
includes/functions/fns_std.php. NOTE: this issue could produce
resultant XSS.
|
| CVE-2006-2079 |
Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky
Media Instant Photo Gallery, possibly before 1.0.2, allows remote
attackers to inject arbitrary web script or HTML via the cat_id
parameter.
|
| CVE-2006-2070 |
Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0
and earlier allows remote attackers to inject arbitrary web script or
HTML via the member parameter in a viewpro action.
|
| CVE-2006-2066 |
Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in
MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and
earlier, allow remote attackers to inject arbitrary web script or HTML
via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.
|
| CVE-2006-2063 |
Multiple cross-site scripting (XSS) vulnerabilities in Leadhound Full
and LITE 2.1, and probably the Network Version "Full Version", allow
remote attackers to inject arbitrary web script or HTML via the login
parameter in (1) agent_affil.pl, (2) agent_help.pl, (3) agent_faq.pl,
(4) agent_help_insert.pl, (5) sign_out.pl, (6) members.pl, (7)
modify_agent_1.pl, (8) modify_agent_2.pl, (9) modify_agent.pl, (10)
agent_links.pl, (11) agent_stats_pending_leads.pl, (12)
agent_logoff.pl, (13) agent_rev_det.pl, (14) agent_subaffiliates.pl,
(15) agent_stats_pending_leads.pl, (16) agent_transactions.pl, (17)
agent_payment_history.pl, (18) agent_summary.pl, (19)
agent_camp_all.pl, (20) agent_camp_new.pl, (21) agent_camp_notsub.pl,
(22) agent_campaign.pl, (23) agent_camp_expired.pl, (24)
agent_stats_det.pl, (25) agent_stats.pl, (26) agent_camp_det.pl, (27)
agent_camp_sub.pl, (28) agent_affil_list.pl, and (29)
agent_affil_code.pl; the logged parameter in (30) agent_faq.pl, (31)
agent_help_insert.pl, (32) members.pl, (33) modify_agent_1.pl, (34)
modify_agent_2.pl, (35) modify_agent.pl, (36) agent_links.pl, (37)
agent_subaffiliates.pl, (38) agent_stats_pending_leads.pl, (39)
agent_transactions.pl, (40) agent_summary.pl, (41) agent_camp_all.pl,
(42) agent_camp_new.pl, (43) agent_camp_notsub.pl, (44)
agent_campaign.pl, (45) agent_camp_expired.pl, (46) agent_stats.pl,
(47) agent_camp_det.pl, (48) agent_camp_sub.pl, (49)
agent_affil_list.pl, and (50) agent_affil_code.pl; the camp_id
parameter in (51) agent_links.pl, (52) agent_subaffiliates.pl, and
(53) agent_camp_det.pl; the (54) banner parameter in agent_links.pl;
the offset parameter in (55) agent_links.pl, (56)
agent_subaffiliates.pl, (57) agent_transactions.pl, and (58)
agent_summary.pl; the date parameter in (59) agent_subaffiliates.pl,
(60) agent_transactions.pl, and (61) agent_summary.pl; the dates
parameter in (62) agent_rev_det.pl and (63) agent_stats_det.pl; the
(64) page parameter in agent_camp_det.pl; the (65) agent_id parameter
in agent_commission_statement.pl; and the (66) lost password field in
lost_pwd.pl.
|
| CVE-2006-2052 |
Cross-site scripting (XSS) vulnerability in Verosky Media Instant
Photo Gallery allows remote attackers to inject arbitrary web script
or HTML via the member parameter in a viewpro action in member.php.
NOTE: the original report may be inaccurate, since the "viewpro"
string does not appear in the source code for version 1.0.2 of the
product.
|
| CVE-2006-2051 |
Multiple cross-site scripting (XSS) vulnerabilities in
myadmin/index.php in NextAge Shopping Cart allow remote attackers to
inject arbitrary web script or HTML via the (1) username and (2)
password parameters.
|
| CVE-2006-2049 |
Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts
DCForumLite 3.0 allows remote attackers to inject arbitrary web script
or HTML via the az parameter.
|
| CVE-2006-2048 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Edwin van Wijk phpWebFTP 2.3 allow remote attackers to inject
arbitrary web script or HTML via the (1) port, (2) server, and (3)
user parameters. NOTE: it is possible that the affected version is
actually 3.2.
|
| CVE-2006-2037 |
Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0
Beta 2.84 allows remote attackers to inject arbitrary web script or
HTML via the navpath parameter.
|
| CVE-2006-2031 |
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin
2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to
inject arbitrary web script or HTML via the lang parameter.
|
| CVE-2006-2028 |
Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy
Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject
arbitrary web script or HTML via the imagedir parameter. NOTE: this
issue might be resultant from directory traversal.
|
| CVE-2006-2016 |
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin
0.9.8 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) dn parameter in (a) compare_form.php, (b)
copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e)
delete_form.php; (2) scope parameter in (f) search.php; and (3)
Container DN, (4) Machine Name, and (5) UID Number fields in (g)
template_engine.php.
|
| CVE-2006-2015 |
Cross-site scripting (XSS) vulnerability in SL_site 1.0 allows remote
attackers to inject arbitrary web script or HTML via the recherche
parameter in recherche.php. NOTE: other XSS vectors, as reported in
the original disclosure, are resultant from other primary
vulnerabilities that have separate CVE names.
|
| CVE-2006-2014 |
Directory traversal vulnerability in gallerie.php in SL_site 1.0
allows remote attackers to list images in arbitrary directories via
".." sequences in the rep parameter, which is used to construct a
directory name in admin/config.inc.php. NOTE: this issue could be
used to produce resultant XSS from an error message.
|
| CVE-2006-2013 |
SQL injection vulnerability in page.php in SL_site 1.0 allows remote
attackers to execute arbitrary SQL commands via the id_page parameter.
NOTE: this issue could be used to produce resultant XSS from an error
message.
|
| CVE-2006-2011 |
Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7
and earlier allows remote attackers to inject arbitrary web script or
HTML via the nickname, probably involving the user_name parameter in
register.php.
|
| CVE-2006-2003 |
Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community
Architect Guestbook allows remote attackers to inject arbitrary web
script or HTML by signing the guestbook, which is displayed by
fsguestbook.html. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-2001 |
Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery
1.1 allows remote attackers to inject arbitrary web script or HTML via
the p parameter. NOTE: this is a different vulnerability than the
directory traversal vector.
|
| CVE-2006-2000 |
Cross-site scripting (XSS) vulnerability in /lms/a2z.jsp in logMethods
0.9 allows remote attackers to inject arbitrary web script or HTML via
the kwd parameter.
|
| CVE-2006-1980 |
Cross-site scripting (XSS) vulnerability in W2B Online Banking allows
remote attackers to inject arbitrary web script or HTML via the (1)
query string, (2) SID parameter, or (3) ilang parameter.
|
| CVE-2006-1979 |
Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web
MWGuest 2.1.0 allows remote attackers to inject arbitrary web script
or HTML via the homepage parameter.
|
| CVE-2006-1977 |
Cross-site scripting (XSS) vulnerability in FlexBB 0.5.7 BETA and
earlier allows remote attackers to inject arbitrary web script or HTML
via the (1) name and (2) message parameters.
|
| CVE-2006-1976 |
Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer
Request Board (PRB) Beta 1 before 20060320 allows remote attackers to
inject arbitrary web script or HTML via the Request field.
|
| CVE-2006-1975 |
Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in
PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web
script or HTML via the Kommentar field.
|
| CVE-2006-1972 |
Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut
EasyGallery allows remote attackers to inject arbitrary web script or
HTML via the ordner parameter.
|
| CVE-2006-1971 |
Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM
ContentBoxX allows remote attackers to inject arbitrary web script or
HTML via the action parameter.
|
| CVE-2006-1970 |
Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in
KCScripts Classifieds, distributed individually and as part of Portal
Pack 6.0 and earlier, allows remote attackers to inject arbitrary web
script or HTML via the cat_id parameter.
|
| CVE-2006-1969 |
Cross-site scripting (XSS) vulnerability in search/search.cgi in an
unspecified KCScripts script, probably Search Engine or Site Search,
distributed individually and as part of Portal Pack 6.0 and earlier,
allows remote attackers to inject arbitrary web script or HTML via the
q parameter.
|
| CVE-2006-1968 |
Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in
KCScripts News Publisher, distributed individually and as part of
Portal Pack 6.0 and earlier, allows remote attackers to inject
arbitrary web script or HTML via the sort_order parameter.
|
| CVE-2006-1967 |
Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in
KCScripts Calendar, distributed individually and as part of Portal
Pack 6.0 and earlier, allows remote attackers to inject arbitrary web
script or HTML via the sort_order parameter.
|
| CVE-2006-1965 |
Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net
Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4)
room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7)
username parameter in (b) imessage.cgi; the (8) password parameter in
(c) login.cgi; and the (9) cat_id parameter in (d) viewcat.cgi.
|
| CVE-2006-1960 |
Cross-site scripting (XSS) vulnerability in the appliance web user
interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and
WLSE Express before 2.13 allows remote attackers to inject arbitrary
web script or HTML, possibly via the displayMsg parameter to
archiveApplyDisplay.jsp, aka bug ID CSCsc01095.
|
| CVE-2006-1950 |
Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in
PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) aff and (2) cat parameters.
|
| CVE-2006-1946 |
Multiple cross-site scripting (XSS) vulnerabilities in Visale 1.0 and
earlier allow remote attackers to inject arbitrary web script or HTML
via (1) the keyval parameter in pbpgst.cgi, (2) the catsubno parameter
in pblscg.cgi, and (3) the listno parameter in pblsmb.cgi.
|
| CVE-2006-1945 |
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5
and earlier allows remote attackers to inject arbitrary web script or
HTML via the config parameter. NOTE: this might be the same core
issue as CVE-2005-2732.
|
| CVE-2006-1944 |
Multiple cross-site scripting (XSS) vulnerabilities in SibSoft
CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary
web script or HTML via (1) the list_id parameter in mailadmin.cgi and
(2) the form_id parameter in templates.cgi.
|
| CVE-2006-1943 |
Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts
IntelliLink Pro 5.06 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) url parameter in
addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgotpass
parameters in edit.cgi.
|
| CVE-2006-1925 |
Directory traversal vulnerability in the editnews module
(inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote
attackers to read or modify files via the source parameter in the (1)
editnews or (2) doeditnews action. NOTE: this can also produce
resultant XSS when the target file does not exist.
|
| CVE-2006-1923 |
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before
1.1.1 allow remote attackers to inject arbitrary web script or HTML
via (1) RSS/RSS.php and (2) possibly other vectors.
|
| CVE-2006-1918 |
Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5
allow remote attackers to inject arbitrary web script or HTML via the
menuid parameter to (1) index.php or (2) forum.php, or the (3)
reporeid_print parameter to print.php.
|
| CVE-2006-1916 |
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in
DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) ulocation or (2) uhobbies parameters.
|
| CVE-2006-1913 |
Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax
Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject
arbitrary web script or HTML via the page parameter.
|
| CVE-2006-1912 |
MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL
variable in (1) global.php and (2) inc/init.php, which allows remote
attackers to initialize arbitrary variables that are processed by an
@extract command, which could then be leveraged to conduct cross-site
scripting (XSS) or SQL injection attacks.
|
| CVE-2006-1911 |
Cross-site scripting (XSS) vulnerability in MyBB (MyBulletinBoard) 1.1
allows remote attackers to inject arbitrary web script or HTML via the
attachment content disposition in an HTML attachment.
|
| CVE-2006-1906 |
Cross-site scripting (XSS) vulnerability in index.php in jjgan852
phpLister 0.4.1 allows remote attackers to inject arbitrary web script
or HTML via the page parameter.
|
| CVE-2006-1904 |
Cross-site scripting (XSS) vulnerability in index.php in AnimeGenesis
Gallery allows remote attackers to inject arbitrary web script or HTML
via the cat parameter.
|
| CVE-2006-1903 |
Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila
allow remote attackers to inject arbitrary web script or HTML (1) via
the referer parameter in sendMail, and via attributes of (2) the A
element and certain other HTML elements in web pages edited with the
editInBrowser module. NOTE: the msgReader$1 mode attack vector is
already covered by CVE-2006-1769.
|
| CVE-2006-1899 |
Multiple cross-site scripting (XSS) vulnerabilities in dev Neuron Blog
1.1 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) name and (2) website parameters.
|
| CVE-2006-1898 |
Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper
Tiny PHP Forum (TPF) 3.6 allow remote attackers to inject arbitrary
web script or HTML via (1) the uname parameter in a view action in
profile.php and (2) a login name. NOTE: the "Access to hash password"
issue is already covered by CVE-2006-0103.
|
| CVE-2006-1894 |
Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived
from PunBB, allows remote attackers to inject arbitrary web script or
HTML via a substitution cipher of the email tag, which is transformed
when the application's e-mail address obfuscator reverses the
transformation. NOTE: it is not clear whether this is a site-specific
issue; however, the claimed codebase relationship with PunBB might be
relevant.
|
| CVE-2006-1893 |
Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2
allows remote attackers to inject arbitrary web script or HTML via the
id parameter.
|
| CVE-2006-1891 |
Cross-site scripting (XSS) vulnerability in Martin Scheffler betaboard
0.1 allows remote attackers to inject arbitrary web script or HTML via
a user's profile, possibly using the FormVal_profile parameter. NOTE:
it is not clear whether this is a distributable product or a
site-specific vulnerability. If it is site-specific, then it should
not be included in CVE.
|
| CVE-2006-1890 |
Multiple PHP remote file inclusion vulnerabilities in myWebland
myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a
URL in the myevent_path parameter in (1) event.php and (2)
initialize.php. NOTE: vector 2 was later reported to affect 1.4 as
well.
|
| CVE-2006-1889 |
Cross-site scripting (XSS) vulnerability in the search action handler
in index.php in Nils Asmussen (aka SCRIPTSOLUTION) Boardsolution 1.12
and earlier allows remote attackers to inject arbitrary web script or
HTML via the "Search for" item (keyword parameter).
|
| CVE-2006-1888 |
phpGraphy 0.9.11 and earlier allows remote attackers to bypass
authentication and gain administrator privileges via a direct request
to index.php with the editwelcome parameter set to 1, which can then
be used to modify the main page to inject arbitrary HTML and web
script. NOTE: XSS attacks are resultant from this issue, since normal
functionality allows the admin to modify pages.
|
| CVE-2006-1878 |
Cross-site scripting (XSS) vulnerability in index.php in phpFaber
TopSites allows remote attackers to inject arbitrary web script or
HTML via the page parameter.
|
| CVE-2006-1854 |
** DISPUTED **
Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager
2.0 and earlier allow remote attackers to inject arbitrary web script
or HTML during a login action via the (1) Account Name and (2)
Username field. NOTE: the vendor has disputed this vulnerability,
saying that "it does not exist currently in the Bluepay 2.0 product,"
and older versions might not have been affected either. As of
20060512, CVE has not formally investigated this dispute.
|
| CVE-2006-1850 |
Multiple cross-site scripting (XSS) vulnerabilities in xFlow 5.46.11
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) level, (2) position, (3) id, and (4) action
parameters to members_only/index.cgi, and the (5) page parameter to
customer_area/index.cgi.
|
| CVE-2006-1848 |
Multiple cross-site scripting (XSS) vulnerabilities in stats_view.php
in LinPHA 1.1.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) date_from, (2) date_to, and (3) date parameter.
|
| CVE-2006-1846 |
Cross-site scripting (XSS) vulnerability in the Your_Account module in
PHP-Nuke 7.8 might allows remote attackers to inject arbitrary HTML
and web script via the ublock parameter, which is saved in the user's
personal menu. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information. In
addition, it is unclear whether this issue is a vulnerability, since
it is related to the user's personal menu, which presumably is not
modifiable by others.
|
| CVE-2006-1843 |
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK
1.1 allows remote attackers to inject arbitrary web script or HTML via
the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-1842 |
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK
1.1 allows remote attackers to inject arbitrary web script or HTML via
the (1) NAME and (2) COMMENTS parameters.
|
| CVE-2006-1841 |
Cross-site scripting (XSS) vulnerability in search.php in boastMachine
(bMachine) 2.7, and possibly other versions before 2.9b, allows remote
attackers to inject arbitrary web script or HTML via the key
parameter, as used by the search field.
|
| CVE-2006-1835 |
Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix
allows remote attackers to inject arbitrary web script or HTML via the
ycyear parameter.
|
| CVE-2006-1826 |
Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery
3.1.4 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) gallery_id parameter in view.php, (2)
keyword parameter in search.php, and (3) image_id parameter in
image.php. NOTE: it is possible that vectors 1 and 3 are resultant
from SQL injection.
|
| CVE-2006-1825 |
Cross-site scripting (XSS) vulnerability in index.php in phpLinks
2.1.3.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via the term parameter.
|
| CVE-2006-1824 |
Multiple cross-site scripting (XSS) vulnerabilities in
PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject
arbitrary web script or HTML via the (1) Name, (2) Website, and (3)
Comment parameter.
|
| CVE-2006-1822 |
Cross-site scripting (XSS) vulnerability in search.php in FarsiNews
2.5.3 Pro and earlier allows remote attackers to inject arbitrary web
script or HTML via the selected_search_arch parameter.
|
| CVE-2006-1820 |
Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1
allows remote attackers to inject arbitrary web script or HTML via the
id parameter. NOTE: this might be resultant from the directory
traversal vulnerability.
|
| CVE-2006-1818 |
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS
1.0 allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors, possibly including the (1) first_name and (2)
last_name parameter in myaccounts.php. NOTE: portions of these
details were obtained from third party sources instead of the original
disclosure.
|
| CVE-2006-1817 |
SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0,
with magic_quotes_gpc disabled, allows remote attackers to execute
arbitrary SQL commands via the (1) authusername and possibly the (2)
authpassword cookie.
|
| CVE-2006-1815 |
Multiple cross-site scripting (XSS) vulnerabilities in register.php in
Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject
arbitrary web script or HTML via the (1) newuser_realname and (2)
newuser_icq parameters, a different vector than CVE-2006-1768. NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2006-1811 |
Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow
remote attackers to execute arbitrary SQL commands via the (1) id, (2)
forumid, or (3) threadid parameter to index.php; the (4) ICQ, (5) AIM,
(6) MSN, (7) Google Talk, (8) Website Name, (9) Website Address, (10)
Email Address, (11) Location, (12) Signature, and (13) Sub-Titles
fields in the user profile; or (14) flexbb_password field in a cookie.
|
| CVE-2006-1810 |
Multiple cross-site scripting (XSS) vulnerabilities in FlexBB 0.5.5
BETA allow remote attackers to inject arbitrary web script or HTML via
the (1) ICQ, (2) AIM, (3) MSN, (4) Google Talk, (5) Website Name, (6)
Website Address, (7) Email Address, (8) Location, (9) Signature, and
(10) Sub-Titles fields in the user profile.
|
| CVE-2006-1808 |
Cross-site scripting (XSS) vulnerability in index.php in Lifetype
1.0.3 allows remote attackers to inject arbitrary web script or HTML
via the show parameter in a Template operation.
|
| CVE-2006-1807 |
Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3
and earlier allow remote attackers to execute arbitrary SQL commands
via the (1) start parameter in a search action or (2) type parameter
in a top action.
|
| CVE-2006-1806 |
Cross-site scripting (XSS) vulnerability in index.php in Musicbox
2.3.3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the term parameter in a search action.
|
| CVE-2006-1803 |
Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin
2.7.0-pl1 allows remote attackers to inject arbitrary web script or
HTML via the sql_query parameter.
|
| CVE-2006-1802 |
Cross-site scripting (XSS) vulnerability in index.php in
TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary
web script or HTML via the twg_album parameter.
|
| CVE-2006-1801 |
Cross-site scripting (XSS) vulnerability in planetsearchplus.php in
planetSearch+ allows remote attackers to inject arbitrary web script
or HTML via the search_exp parameter.
|
| CVE-2006-1796 |
Cross-site scripting (XSS) vulnerability in the paging links
functionality in template-functions-links.php in Wordpress 1.5.2, and
possibly other versions before 2.0.1, allows remote attackers to
inject arbitrary web script or HTML to Internet Explorer users via the
request URI ($_SERVER['REQUEST_URI']).
|
| CVE-2006-1795 |
Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI
Network Enterprise @1 Table Publisher 2006-03-23 allows remote
attackers to inject arbitrary web script or HTML via the Title of
Table field.
|
| CVE-2006-1791 |
Directory traversal vulnerability in acc.php in QuickBlogger 1.4
allows remote attackers to read or include arbitrary local files via
the request parameter. NOTE: this issue can also produce resultant
XSS when the associated include statement fails.
|
| CVE-2006-1786 |
Cross-site scripting (XSS) vulnerability in Adobe Document Server for
Reader Extensions 6.0 allows remote attackers to inject arbitrary web
script or HTML via (1) the actionID parameter in ads-readerext and (2)
the op parameter in AlterCast. NOTE: it is not clear whether the
vendor advisory addresses this issue.
|
| CVE-2006-1783 |
Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote
attackers to inject arbitrary web script or HTML via the URI.
|
| CVE-2006-1779 |
Cross-site scripting (XSS) vulnerability in login.php in Jeremy
Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the btag parameter.
|
| CVE-2006-1775 |
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19
allow remote attackers to inject arbitrary web script or HTML via the
(1) Site Description field in (a) admin_board.php, the (2) Group name
and (3) Group description fields in (b) admin_groups.php and (c)
groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the
(5) Rank Title field in (e) admin_ranks.php. NOTE: the
profile.php/Current password vector is already covered by
CVE-2006-1603.
|
| CVE-2006-1769 |
Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila
9.5 and earlier allow remote attackers to inject arbitrary web script
or HTML via (1) the mode parameter in msgReader$1 and (2) the end of
the URI in viewDepartment$.
|
| CVE-2006-1768 |
Multiple cross-site scripting (XSS) vulnerabilities in register.php in
Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject
arbitrary web script or HTML via the (1) newuser_name, (2)
newuser_email, and (3) newuser_hp parameters in the faction=register
mode in index.php.
|
| CVE-2006-1765 |
Cross-site scripting (XSS) vulnerability in index.php in JBook 1.3
allows remote attackers to inject arbitrary web script or HTML via the
page parameter.
|
| CVE-2006-1762 |
Directory traversal vulnerability in index.php in blur6ex 0.3.452
allows remote attackers to include arbitrary files via the shard
parameter. NOTE: this issue can be exploited to produce resultant XSS
when the parameter has XSS manipulations, and path disclosure with
other invalid values.
|
| CVE-2006-1761 |
Cross-site scripting vulnerability in index.php in blur6ex 0.3.452
allows remote attackers to inject arbitrary web script or HTML via the
errormsg parameter, which is not sanitized in the error message.
NOTE: the vector in the shard parameter is not XSS and has been
assigned a separate name.
|
| CVE-2006-1760 |
Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow
remote attackers to inject arbitrary web script or HTML via the page
parameter in (1) Classic.view/thumbnail.php, (2)
Classic.view/gallery.php, (3) Classic.view/detail.php, or (4)
Orange.view/detail.php; or (5) the name parameter in
Orange.view/slideshow.php.
|
| CVE-2006-1759 |
Cross-site scripting (XSS) vulnerability in allgemein_transfer.php in
SWSoft Confixx 3.1.2 allows remote attackers to inject arbitrary web
script or HTML via the jahr parameter.
|
| CVE-2006-1757 |
Cross-site scripting (XSS) vulnerability in index.php in Vegadns 0.99
allows remote attackers to inject arbitrary web script or HTML via the
message parameter.
|
| CVE-2006-1752 |
Multiple cross-site scripting (XSS) vulnerabilities in the backend in
MvBlog before 1.6 allow remote attackers to inject arbitrary web
script or HTML via the (1) name or (2) body fields in a comment.
|
| CVE-2006-1750 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Autogallery 0.41 allow remote attackers to inject arbitrary web script
or HTML via the (1) pic or (2) show parameters.
|
| CVE-2006-1748 |
Cross-site scripting (XSS) vulnerability in XMB Forum 1.9.5 allows
remote attackers to inject arbitrary web script or HTML by uploading a
Flash (.SWF) video that contains a getURL function call, which causes
the video to be rendered without disabling ActionScript.
|
| CVE-2006-1746 |
Directory traversal vulnerability in PHPList 2.10.2 and earlier allows
remote attackers to include arbitrary local files via the (1)
GLOBALS[database_module] or (2) GLOBALS[language_module] parameters,
which overwrite the underlying $GLOBALS variable.
|
| CVE-2006-1745 |
Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3
allows remote attackers to inject arbitrary web script or HTML via the
error parameter. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2006-1732 |
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x
before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and
SeaMonkey before 1.0 allows remote attackers to bypass same-origin
protections and conduct cross-site scripting (XSS) attacks via
unspecified vectors involving the window.controllers array.
|
| CVE-2006-1731 |
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8,
Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the
Object class prototype instead of the global window object when (1)
.valueOf.call or (2) .valueOf.apply are called without any arguments,
which allows remote attackers to conduct cross-site scripting (XSS)
attacks.
|
| CVE-2006-1722 |
Cross-site scripting (XSS) vulnerability in suche.htm in ShopXS 4.0
allows remote attackers to inject arbitrary web script or HTML via the
Suchstring1 (aka search) parameter.
|
| CVE-2006-1720 |
Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson
3.0 allows remote attackers to inject arbitrary web script or HTML via
the Word parameter. NOTE: it is possible that this issue is resultant
from SQL injection.
|
| CVE-2006-1717 |
Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka
MyBulletinBoard) 1.10, when configured to permit new threads by
unregistered users, allows remote attackers to inject arbitrary web
script or HTML via the username.
|
| CVE-2006-1716 |
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in
MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject
arbitrary web script or HTML via a JavaScript event in a BBCode img
tag. NOTE: the email vector is already covered by CVE-2006-1625,
although it might stem from the same core issue.
|
| CVE-2006-1713 |
Cross-site scripting (XSS) vulnerability in index.php in Christoph
Roeder phpMyForum 4.0 allows remote attackers to inject arbitrary web
script or HTML via the page parameter.
|
| CVE-2006-1712 |
Cross-site scripting (XSS) vulnerability in the private archive script
(private.py) in GNU Mailman 2.1.7 allows remote attackers to inject
arbitrary web script or HTML via the action argument.
|
| CVE-2006-1709 |
Cross-site scripting (XSS) vulnerability in shop_main.cgi in
interaktiv.shop 5 allows remote attackers to inject arbitrary web
script or HTML via the (1) pn and (2) sbeg parameters.
|
| CVE-2006-1701 |
Cross-site scripting (XSS) vulnerability in the Pages module in
Shadowed Portal allows remote attackers to inject arbitrary web script
or HTML via the page parameter to load.php.
|
| CVE-2006-1699 |
Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner
Generator 3.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the banner parameter in view mode.
|
| CVE-2006-1698 |
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook
2.3.1 allows remote attackers to execute arbitrary web script or HTML
via the (1) url, (2) city, (3) state, or (4) country parameters.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information, although it is likely
that they are the result of post-disclosure analysis.
|
| CVE-2006-1697 |
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook
2.3.1 allows remote attackers to execute arbitrary web script or HTML
via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting
a message.
|
| CVE-2006-1696 |
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3
allows remote attackers to inject arbitrary web script or HTML via
unknown attack vectors.
|
| CVE-2006-1691 |
SQL injection vulnerability in MWNewsletter 1.0.0b allows remote
attackers to execute arbitrary SQL commands via the user_name
parameter to unsubscribe.php.
|
| CVE-2006-1690 |
Cross-site scripting (XSS) vulnerability in subscribe.php in
MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web
script or HTML via the user_name parameter.
|
| CVE-2006-1687 |
Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0
PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject
arbitrary web script or HTML via the message parameter, probably
involving the basket functionality.
|
| CVE-2006-1682 |
Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft
Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the deptname parameter, possibly involving the
webpshop/ department.wml script.
|
| CVE-2006-1681 |
Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and
earlier allows remote attackers to inject arbitrary web script or HTML
via a malformed request that generates an HTTP 400 error, which is not
properly handled when the error message is generated.
|
| CVE-2006-1679 |
Cross-site scripting (XSS) vulnerability in modules/online.php in
Jupiter CMS 1.1.5 allows remote attackers to inject arbitrary web
script or HTML via the layout parameter to index.php.
|
| CVE-2006-1678 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
before 2.8.0.3 allow remote attackers to inject arbitrary web script
or HTML via unknown vectors in unspecified scripts in the themes
directory.
|
| CVE-2006-1675 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery
1.4.1 allow remote attackers to inject arbitrary web script or HTML
via the (1) cat, (2) num, and (3) search parameters to (a)
category.php, and the (4) slideshow, (5) show_metadata, and (6) start
parameters to (b) picture.php, a different vulnerability than
CVE-2006-1674.
|
| CVE-2006-1674 |
Cross-site scripting (XSS) vulnerability in search.php in
PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web
script or HTML via the id parameter, a different vulnerability than
CVE-2006-1675.
|
| CVE-2006-1673 |
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard
vBug Tracker 3.5.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the sortorder parameter.
|
| CVE-2006-1665 |
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal
2.0.1 stable allow remote attackers to inject arbitrary web script or
HTML via the (1) adminJump and (2) forum_middle parameters in (a)
forum.php, and the (3) form parameter in (b) members.php, (c) pm.php,
and (d) mail.php.
|
| CVE-2006-1661 |
Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) areaID parameter in area.View.action, (2) time parameter
in planning.View.action, and (3) userID parameter in user.View.action.
|
| CVE-2006-1660 |
Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz
Image Gallery allows remote attackers to inject arbitrary web script
or HTML via msg parameter. NOTE: the provenance of this information is
unknown; the details are obtained from third party information.
|
| CVE-2006-1658 |
Direct static code injection vulnerability in ticker.db.php in Chucky
A. Ivey N.T. 1.1.0 allows remote administrators to insert arbitrary
PHP code into the config file, which is included other N.T. scripts.
|
| CVE-2006-1657 |
Cross-site scripting (XSS) vulnerability in index.php in Chucky
A. Ivey N.T. 1.1.0 allows remote attackers to inject arbitrary web
script or HTML via the username parameter, which is not filtered when
the administrator views the "Login Log" page.
|
| CVE-2006-1645 |
Cross-site scripting (XSS) vulnerability in Anton Vlasov and Rostislav
Gaitkuloff ReloadCMS 1.2.5 and earlier allows remote attackers to
inject arbitrary web script or HTML and gain leverage to execute
arbitrary PHP code via the User-Agent HTTP header, which is displayed
by admin/modules/general/statistic.php in the administration panel.
|
| CVE-2006-1642 |
Cross-site scripting (XSS) vulnerability in Interact 2.1.1 allows
remote attackers to inject arbitrary web script or HTML via (1) the
search_terms parameter to (a) search.php, and (2) the first_name, (3)
last_name, (4) email, (5) password, and (6) confirm_password
parameters to (b) userinput.php. NOTE: the provenance of this
information is unknown; the details are obtained from third party. In
addition, the lack of precision in the third party descriptions makes
it unclear whether the named vectors are correct.
|
| CVE-2006-1641 |
Multiple SQL injection vulnerabilities in CzarNews 1.14 allow remote
attackers to execute arbitrary SQL commands via the (1) usern or (2)
passw parameters to (a) cn_auth.php, (3) s parameter to (b) news.php,
or (4) a parameter to (c) dpost.php.
|
| CVE-2006-1640 |
Cross-site scripting (XSS) vulnerability in news.php in CzarNews 1.14
allows remote attackers to inject arbitrary web script or HTML via the
email parameter.
|
| CVE-2006-1638 |
Multiple SQL injection vulnerabilities in aWebBB 1.2 allow remote
attackers to execute arbitrary SQL commands via the (1) Username parameter
to (a) accounts.php, (b) changep.php, (c) editac.php, (d)
feedback.php, (e) fpass.php, (f) login.php, (g) post.php, (h)
reply.php, or (i) reply_log.php; (2) p parameter to (j) dpost.php; (3)
c parameter to (k) list.php or (l) ndis.php; or (12) q parameter to
(m) search.php.
|
| CVE-2006-1637 |
Multiple cross-site scripting (XSS) vulnerabilities in aWebBB 1.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) tname or (2) fpost parameters to (a) post.php; (3) fullname, (4)
emailadd, (5) country, (6) sig, or (7) otherav parameters to (b)
editac.php; or (8) fullname, (9) emailadd, or (10) country parameters
to (c) register.php.
|
| CVE-2006-1634 |
Cross-site scripting (XSS) vulnerability in index.php in LucidCMS
2.0.0 RC4 allows remote attackers to inject arbitrary web script or
HTML via the command parameter.
|
| CVE-2006-1625 |
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in
MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject
arbitrary web script or HTML via a JavaScript event in a BBCode email
tag, as demonstrated using the onmousemove event.
|
| CVE-2006-1623 |
Unspecified vulnerability in main.php in an unspecified "file created
by Andries Bruinsma," possibly a FleXiBle Development (FXB)
application, allows remote attackers to include and execute arbitrary
PHP code. NOTE: this disclosure is extremely vague and has very
little information about the specific vulnerability type. In
addition, there is little public information on the named product.
Finally, an XSS vector is implied in the subject line, but because
there is no other information and evidence of a cut-and-paste error,
it will not be assigned a separate CVE identifier unless additional
information is provided.
|
| CVE-2006-1622 |
Cross-site scripting (XSS) vulnerability in PHPSelect linksubmit
allows remote attackers to inject arbitrary web script or HTML via (1)
the description parameter to linklist.php and possibly other vectors
involving (2) index.php and (3) linksubmit.php.
|
| CVE-2006-1617 |
Multiple cross-site scripting (XSS) vulnerabilities in Advanced Poll
2.02 allow remote attackers to inject arbitrary web script or HTML via
the (1) id parameter to comments.php or (2) poll_id parameter to
page.php. NOTE: it is possible that this issue is resultant from
CVE-2006-1616.
|
| CVE-2006-1613 |
Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote
attackers to execute arbitrary SQL commands via the (1) user123
variable in (a) login.php or (b) fpass.php; or (2) cid parameter to
(c) visview.php.
|
| CVE-2006-1612 |
Multiple cross-site scripting (XSS) vulnerabilities in visview.php in
aWebNews 1.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) yname, (2) emailadd, (3) subject, and (4) comment
parameters.
|
| CVE-2006-1603 |
Cross-site scripting (XSS) vulnerability in profile.php in phpBB
2.0.19 allows remote attackers to inject arbitrary web script or HTML
via the cur_password parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-1595 |
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in
Claroline 1.7.4 and earlier allows remote attackers to read arbitrary
files via ".." sequences in the file parameter in a rqEditHtml
command.
|
| CVE-2006-1590 |
Cross-site scripting (XSS) vulnerability in the PrintFreshPage
function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and
(2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows
remote attackers to inject arbitrary web script or HTML via the (a)
back parameter to base_graph_main.php, (b) netmask parameter to
base_stat_ipaddr.php, or (c) submit parameter to base_qry_alert.php
within BASE, or (d) query string to acid_main.php in ACID, which
causes the request URI ($_SERVER['REQUEST_URI']) to be inserted into a
refresh operation.
|
| CVE-2006-1583 |
Cross-site scripting (XSS) vulnerability in index.php in Warcraft III
Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary
web script or HTML via the page parameter. NOTE: post-disclosure
analysis by CVE suggests that the "page" parameter is not used in this
product, and "id" might be the affected parameter.
|
| CVE-2006-1582 |
Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg
0.2 allows remote attackers to inject arbitrary web script or HTML via
the _path parameter. NOTE: this might be resultant from the directory
traversal issue.
|
| CVE-2006-1580 |
Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1
and other versions allow remote attackers to inject arbitrary web
script or HTML via the (1) msg parameter in query.jsp and (2) entryId
parameter in edit.jsp.
|
| CVE-2006-1577 |
Multiple cross-site scripting (XSS) vulnerabilities in
view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1)
start_day, (2) start_year, and (3) start_month parameters.
|
| CVE-2006-1576 |
Direct static code injection vulnerability in QLnews 1.2 allows remote
authenticated administrators to execute arbitrary PHP code by
modifying config.php.
|
| CVE-2006-1575 |
Multiple cross-site scripting (XSS) vulnerabilities in news.php in
QLnews 1.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) autorx and (2) newsx parameters.
|
| CVE-2006-1574 |
Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web,
World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for
Scheduler, allows remote attackers to inject arbitrary web script or
HTML via unknown attack vectors.
|
| CVE-2006-1570 |
Cross-site scripting (XSS) vulnerability in Esqlanelapse 2.0 and 2.2
allows remote attackers to inject arbitrary web script or HTML via
unknown attack vectors.
|
| CVE-2006-1569 |
Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote
attackers to execute arbitrary SQL commands via the (1) username or
(2) password parameters to (a) login.php or (b) register.php; or (3) u
parameter to (c) profile.php.
|
| CVE-2006-1568 |
Multiple cross-site scripting (XSS) vulnerabilities in register.php in
RedCMS 0.1 allow remote attackers to inject arbitrary web script or
HTML via the (1) email, (2) location, or (3) website parameters.
|
| CVE-2006-1567 |
Cross-site scripting (XSS) vulnerability in searchresults.asp in
SiteSearch Indexer 3.5 and earlier allows remote attackers to inject
arbitrary web script or HTML via the searchField parameter.
|
| CVE-2006-1562 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allow remote
attackers to inject arbitrary web script or HTML via the (1) autor,
(2) www, (3) temat, and (4) tresc parameters.
|
| CVE-2006-1558 |
Cross-site scripting (XSS) vulnerability in search.php in PHP Script
Index allows remote attackers to inject arbitrary web script or HTML
via the search parameter.
|
| CVE-2006-1556 |
Multiple cross-site scripting (XSS) vulnerabilities in
view_caricatier.php in AL-Caricatier 2.5 allow remote attackers to
inject arbitrary web script or HTML via the (1) CatName, (2)
CaricatierID, or (3) CatID parameter.
|
| CVE-2006-1554 |
Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows
remote attackers to inject arbitrary web script or HTML via the name
parameter while adding a comment.
|
| CVE-2006-1548 |
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction
and possibly (2) DispatchAction and (3) ActionDispatcher in Apache
Software Foundation (ASF) Struts before 1.2.9 allows remote attackers
to inject arbitrary web script or HTML via the parameter name, which
is not filtered in the resulting error message.
|
| CVE-2006-1544 |
Multiple cross-site scripting (XSS) vulnerabilities in news.php in
vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to
inject arbitrary web script or HTML via the (1) autorkomentarza and
(2) tresckomentarza parameters.
|
| CVE-2006-1536 |
Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts
0.93.1 beta and earlier allow remote attackers to execute arbitrary
SQL commands via the (1) motclef and (2) nbr_line_view parameters in
(a) carnet.php, and the (3) id_contact parameter in (b)
contact_view.php.
|
| CVE-2006-1535 |
Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net
PhxContacts 0.93.1 beta and earlier allows remote attackers to inject
arbitrary web script or HTML via the m parameter.
|
| CVE-2006-1532 |
Cross-site scripting (XSS) vulnerability in search.php in PHP
Classifieds 6.18, 6.20, and possibly other versions, allows remote
attackers to inject arbitrary web script or HTML via the searchword
parameter.
|
| CVE-2006-1508 |
Multiple cross-site scripting (XSS) vulnerabilities in MH Software
Connect Daily Web Calendar Software 3.2.9 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1)
calendar_id, (2) style_sheet, and (3) start parameters in (a)
ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b)
ViewSearch.html; the (6) calendar_id and (7) approved parameters in
(c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html;
and the (9) week parameter in (e) ViewWeek.html.
|
| CVE-2006-1507 |
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows
remote attackers to inject arbitrary web script or HTML via the error
parameter to include.php, possibly due to a problem in
login/login.php.
|
| CVE-2006-1504 |
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0
(aka Arab Dynamic Portal or ADP) stable allow remote attackers to
inject arbitrary web script or HTML via the title parameter in (1)
online.php and (2) download.php.
|
| CVE-2006-1498 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and
1.4.15 allows remote attackers to inject arbitrary web script or HTML
via crafted encoded links.
|
| CVE-2006-1496 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
ViHor Design allow remote attackers to inject arbitrary web script or
HTML via (1) a remote URL in the page parameter, which is processed by
an fopen call, or (2) HTML or script in the page parameter, which is
returned to the client in an error message for the failed fopen call.
|
| CVE-2006-1493 |
Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP
allows remote attackers to inject arbitrary web script or HTML via the
chemin parameter. NOTE: it is possible that this issue is resultant
from CVE-2006-1492.
|
| CVE-2006-1487 |
Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio
2.50.2 allows remote attackers to inject arbitrary web script or HTML
via unspecified parameters to the KnowledgeBase search module.
|
| CVE-2006-1486 |
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in
realestateZONE 4.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state
parameters.
|
| CVE-2006-1482 |
Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1
allows remote attackers to inject arbitrary web script or HTML via the
page parameter.
|
| CVE-2006-1479 |
Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey
gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject
arbitrary web script or HTML via the Description field in (1)
newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title
field in (4) newProject.php, (5) newList.php, (6) newWaitingOn.php,
(7) newChecklist.php, (8) newContext.php, and (9) newGoal.php; the
(10) Category Name field in newCategory.php; the (11) listTitle field
in listReport.php; the (12) projectName field in projectReport.php;
and the (13) checklistTitle field in checklistReport.php.
|
| CVE-2006-1474 |
Cross-site scripting (XSS) vulnerability in the "failed" functionality
in Raindance Web Conferencing Pro allows remote attackers to inject
arbitrary web script or HTML via the browser parameter.
|
| CVE-2006-1438 |
Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP
Knowledgebase (aphpkb) 0.57 allow remote attackers to inject arbitrary
web script or HTML via the (1) keyword_list parameter to (a)
index.php; (2) title, (3) article, (4) author, and (5) keywords
parameters to (b) submit_article.php; and (6) Question, (7) Name, and
(8) Email parameters to (c) submit_question.php.
|
| CVE-2006-1436 |
Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event
Publisher allow remote attackers to inject arbitrary web script or
HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and
(5) Public Remarks fields to (a) eventpublisher_admin.htm and (b)
eventpublisher_usersubmit.htm.
|
| CVE-2006-1435 |
Cross-site scripting (XSS) vulnerability in genmessage.php in
Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows
remote attackers to inject arbitrary web script or HTML via the
Message Field (message parameter).
|
| CVE-2006-1434 |
Cross-site scripting (XSS) vulnerability in inscription.php in
Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary
web script or HTML via the Comment Field (COMMENTAIRE parameter).
|
| CVE-2006-1431 |
Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE
couponZONE 4.2 allows remote attackers to inject arbitrary web script
or HTML via URL-encoded (1) srchfor and (2) srchby parameters.
|
| CVE-2006-1430 |
Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS
(formerly DRZES) 3.3.4 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) dedicatedPlanID parameter to
dedicated_order.php, (2) sharedPlanID parameter to shared_order.php,
(3) plan_id parameter to customers/server_management.php, and (4)
email field to customers/forgotpass.php.
|
| CVE-2006-1429 |
Cross-site scripting (XSS) vulnerability in accountlogon.cfm in
classifiedZONE 1.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the rtn parameter.
|
| CVE-2006-1428 |
Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2
and earlier allow remote attackers to inject arbitrary web script or
HTML via the fs parameter to (1) mod.php or (2) mod_print.php.
|
| CVE-2006-1427 |
Multiple cross-site scripting (XSS) vulnerabilities in WebAPP
0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) action, (2) id, (3) num, (4) board, (5)
cat, (6) real, (7) viewcat, (8) img, or (9) curcatname parameter in
cgi-bin/index.cgi, or (10) vsSD parameter in /mods/calendar/index.cgi.
|
| CVE-2006-1425 |
Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily
1.4.1 allows remote attackers to inject arbitrary web script or HTML
via the name parameter.
|
| CVE-2006-1418 |
Cross-site scripting (XSS) vulnerability in default.asp in Caloris
Planitia E-School Management System 1.0 and earlier allows remote
attackers to inject arbitrary web script or HTML via the msg
parameter.
|
| CVE-2006-1417 |
Multiple cross-site scripting (XSS) vulnerabilities in Caloris
Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow
remote attackers to inject arbitrary web script or HTML via the (1)
exam parameter in prequiz.asp or (2) msg parameter in student.asp.
|
| CVE-2006-1416 |
Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute
FAQ Manager .NET 4.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified search module parameters,
possibly the question parameter.
|
| CVE-2006-1415 |
Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB
2.42EC SP 3 and earlier allows remote attackers to inject arbitrary
web script or HTML via the em parameter.
|
| CVE-2006-1414 |
Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in
Toast Forums 1.6 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) author, (2) subject, (3)
message, or (4) dayprune parameter.
|
| CVE-2006-1413 |
Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro
1.5 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) adid or (2) aname parameter in (a)
common/email.asp, (b) users/users_search.asp, or (c)
users/users_profiles.asp; (3) page parameter in (d)
users/users_calendar.asp; (4) usid parameter in (e)
users/users_mgallery.asp; or (5) m parameter in (f)
users/users_search.asp.
|
| CVE-2006-1411 |
Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE
2.0 and earlier allows remote attackers to inject arbitrary web script
or HTML via (1) the shownew parameter in gallery.asp and (2)
unspecified search module parameters.
|
| CVE-2006-1410 |
Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute
Live Support XE 2.0 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) Screen name or (2) Session
Topic field.
|
| CVE-2006-1407 |
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web
Hosting Control Panel 3.2.10 and earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) txtDomainName
parameter to domains.asp or (2) SearchText or (3) UserLevel parameters
to default.asp.
|
| CVE-2006-1406 |
Multiple cross-site scripting (XSS) vulnerabilities in wbadmlog.aspx
in uniForum 4.0 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) txtuser or (2) txtpassword parameters.
|
| CVE-2006-1405 |
Cross-site scripting (XSS) vulnerability in search.aspx in
SweetSuite.NET Content Management System (ssCMS) 2.1.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
keywords parameter.
|
| CVE-2006-1404 |
Multiple cross-site scripting (XSS) vulnerabilities in bol.cgi in
BlankOL 1.0 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) file or (2) function parameter.
|
| CVE-2006-1401 |
Multiple cross-site scripting (XSS) vulnerabilities in search.php in
Calendar Express 2.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) allwords or (2) oneword parameter. NOTE:
the provenance of this information is unknown; the details are
obtained from third party information.
|
| CVE-2006-1400 |
Cross-site scripting (XSS) vulnerability in
MyTasks/PersonalTaskEdit.asp in Metisware Instructor 1.3 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
Task parameter.
|
| CVE-2006-1399 |
Cross-site scripting (XSS) vulnerability in searchresult.php in
Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary
web script or HTML via the search_term parameter. NOTE: the provenance
of this information is unknown; the details are obtained from third
party information.
|
| CVE-2006-1398 |
Cross-site scripting (XSS) vulnerability in guestbook.php in G-Book
1.0 allows remote attackers to inject arbitrary web script or HTML via
the g_message parameter.
|
| CVE-2006-1397 |
Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew
and (b) phpPgAds before 2.0.8 allow remote attackers to inject
arbitrary web script or HTML via the (1) certain parameters to the
banner delivery module, which is not properly handled in the
administrator interface, or (2) certain parameters to the login form.
|
| CVE-2006-1396 |
Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL
Based Message Board allow remote attackers to inject arbitrary web
script or HTML via unknown vectors. NOTE: the provenance of this
information is unknown; the details are obtained from third party
information.
|
| CVE-2006-1394 |
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft
IIS ISAPI filter (aka application server module) in University of
Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before
3.3.0a allow remote attackers to inject arbitrary web script or HTML
via unspecified attack vectors.
|
| CVE-2006-1393 |
Multiple cross-site scripting (XSS) vulnerabilities in the
mod_pubcookie Apache application server module in University of
Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and
3.3 before 3.3.0a allow remote attackers to inject arbitrary web
script or HTML via unspecified attack vectors.
|
| CVE-2006-1392 |
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in
the login server in University of Washington Pubcookie 3.0.0, 3.1.0,
3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers
to inject arbitrary web script or HTML via unspecified inputs.
|
| CVE-2006-1384 |
Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the
web console in IBM Tivoli Business Systems Manager (TBSM) before
3.1.0.1 allows remote attackers to inject arbitrary web script or HTML
via the skin parameter.
|
| CVE-2006-1377 |
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog
0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary
web script or HTML via the i parameter.
|
| CVE-2006-1373 |
Cross-site scripting (XSS) vulnerability in status_image.php in PHP
Live! 3.0 allows remote attackers to inject arbitrary web script or
HTML via the base_url parameter.
|
| CVE-2006-1369 |
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB)
2.1.5 and earlier before 20060308 allows remote attackers to inject
arbitrary web script or HTML via a Private Message (PM) in certain
circumstances.
|
| CVE-2006-1361 |
Cross-site scripting (XSS) vulnerability in OSWiki before 0.3.1 allows
remote attackers to inject arbitrary web script or HTML via the
username field to (1) list.rhtml or (2) show.rhtml.
|
| CVE-2006-1360 |
Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow
remote attackers to execute arbitrary SQL commands via the (1) id, (2)
type, or (3) show parameter to (a) index.php; or the (4) message1 or
(5) message parameter to (b) cart.php.
|
| CVE-2006-1357 |
Cross-site scripting (XSS) vulnerability in my.support.php3 in F5
Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject
arbitrary web script or HTML via the s parameter.
|
| CVE-2006-1349 |
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3
Beta 2 allow remote attackers to inject arbitrary web script or HTML
via the (1) id and (2) type and (3) show parameters in a top action in
(a) index.php; and the (4) message1 parameter in (b) cart.php.
|
| CVE-2006-1348 |
Cross-site scripting (XSS) vulnerability in index.php in Greg
Neustaetter gCards 1.45 and earlier allows remote attackers to inject
arbitrary web script or HTML via the lang[*][file] parameter, which is
injected into an error message. NOTE: this issue might be resultant
from CVE-2006-1346.
|
| CVE-2006-1344 |
Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as
used in Managed PKI (MPKI) 6.0, allows remote attackers to inject
arbitrary web script or HTML via a javascript URI in the VHTML_FILE
parameter.
|
| CVE-2006-1336 |
Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0
and possibly other versions before 2.0 allows remote attackers to
inject arbitrary web script or HTML via the (1) year, (2) month, (3)
next, and (4) prev parameters.
|
| CVE-2006-1331 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Noah's Classifieds 1.3 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) method or (2) list parameter.
|
| CVE-2006-1326 |
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power
Board 2.0.4 allow remote attackers to inject arbitrary web script or
HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and
(5) s parameters in the Search action to index.php; (6) st parameter
to index.php with showtopics set to 1; (7) m, (8) y, and (9) d
parameters in a calendar action; (10) t parameter in a Print action;
(11) MID parameter in a Mail action; (12) HID parameter in a Help
action; (13) active parameter in a search action; (14) sort_order,
(15) max_results, or (16) sort_key parameter in a Members action.
|
| CVE-2006-1325 |
Cross-site scripting (XSS) vulnerability in Streber 0.055 allows
remote attackers to inject arbitrary web script or HTML via unknown
attack vectors.
|
| CVE-2006-1324 |
Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php
in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject
arbitrary web script or HTML via the errormsg parameter when a SQL
error is generated.
|
| CVE-2006-1321 |
Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6
allows remote attackers to inject arbitrary web script or HTML via the
(1) url, (2) title, or (3) author name in a crawled page, which is not
properly sanitized in the tooltips of a report.
|
| CVE-2006-1295 |
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP
1.8.2-g allows remote attackers to inject arbitrary web script or HTML
via the recherche parameter.
|
| CVE-2006-1293 |
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS
1.0.8 and earlier allows remote attackers to inject arbitrary web
script or HTML via the query string (PHP_SELF).
|
| CVE-2006-1290 |
Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway
Captive Portal 0.1 and 0.1.1 allow remote attackers to inject
arbitrary web script or HTML via the (1) ipAddress, (2) act, (3)
username, and (4) unspecified other parameters in (a) authuser.php;
and the (5) username and (6) unspecified other parameters in (b)
userstatistics.php.
|
| CVE-2006-1287 |
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB)
2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal
cookies and probably conduct other activities when the victim is using
Internet Explorer.
|
| CVE-2006-1282 |
CRLF injection vulnerability in inc/function.php in MyBulletinBoard
(MyBB) 1.04 allows remote attackers to conduct cross-site scripting
(XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in
the Referrer HTTP header field, possibly when redirecting to other web
pages.
|
| CVE-2006-1281 |
Cross-site scripting (XSS) vulnerability in member.php in
MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject
arbitrary web script or HTML via the url parameter, a different
vulnerability than CVE-2006-1272. NOTE: 1.10 was later reported to be
vulnerable.
|
| CVE-2006-1278 |
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote
attackers to execute arbitrary SQL commands via the id parameter to
(1) functions.php and (2) user.php in the libs directory, (3) edit.php
and (4) delete.php in control/files/, (5) edit.php and (6) delete.php
in control/users/, (7) edit.php, (8) access.php, and (9) in
control/folders/, (10) access.php and (11) delete.php in
control/groups/, (12) confirm.php, and (13) download.php; (14) the
email parameter in password.php, and (15) the id parameter in
folder.php. NOTE: it was later reported that vectors 12 and 13 also
affect @1 File Store PRO 3.2.
|
| CVE-2006-1277 |
Cross-site scripting (XSS) vulnerability in signup.php in @1 File
Store 2006.03.07 allows remote attackers to inject arbitrary web
script or HTML via the (1) real_name, (2) email, and (3) login
parameters.
|
| CVE-2006-1272 |
Multiple cross-site scripting (XSS) vulnerabilities in member.php in
MyBulletin Board (MyBB) 1.0.3 allow remote attackers to inject
arbitrary web script or HTML via the (1) aim, (2) yahoo, (3) msn, or
(4) website field.
|
| CVE-2006-1270 |
Multiple cross-site scripting (XSS) vulnerabilities in zones.php in
Inprotect 0.21 allow remote attackers to inject arbitrary web script
or HTML via the (1) Name or (2) Description field. NOTE: the
provenance of this information is unknown; the details are obtained
from third party information.
|
| CVE-2006-1266 |
Cross-site scripting (XSS) vulnerability in Service_Requests.asp in
VPMi Enterprise 3.3 allows remote attackers to inject arbitrary web
script or HTML via the Request_Name_Display parameter.
|
| CVE-2006-1265 |
SQL injection vulnerability in discussion.class.php in xhawk.net
discussion 2.0 beta2 allows remote attackers to execute arbitrary SQL
commands via the view parameter.
|
| CVE-2006-1264 |
Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0
beta2 allows remote attackers to inject arbitrary web script or HTML
via a Javascript URI in a BBCode img tag.
|
| CVE-2006-1263 |
Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in
WordPress before 2.0.2 allow remote attackers to inject arbitrary web
script or HTML via unknown attack vectors.
|
| CVE-2006-1261 |
Multiple cross-site scripting (XSS) vulnerabilities in ASPPortal 3.00
allow remote attackers to inject arbitrary web script or HTML via
unknown attack vectors.
|
| CVE-2006-1258 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows
remote attackers to inject arbitrary web script or HTML via the
set_theme parameter.
|
| CVE-2006-1256 |
Cross-site scripting (XSS) vulnerability in guestbook.php in Soren
Boysen (SkullSplitter) PHP Guestbook 2.6 allows remote attackers to
inject arbitrary web script or HTML via the url parameter.
|
| CVE-2006-1239 |
Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in
Gemini 2.0 allows remote attackers to inject arbitrary web script or
HTML via the rtcDescription$RadEditor1 field. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-1235 |
Directory traversal vulnerability in admin/deleteuser.php in HitHost
1.0.0 might allow remote attackers to delete directories (possibly
only empty directories) via the $deleteuser variable. NOTE: the
initial disclosure for this issue indicated that the researcher was
unable to prove this issue; however, this might have been due to
certain behaviors of rmdir.
|
| CVE-2006-1233 |
Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow
remote attackers to inject arbitrary web script or HTML via the (1)
ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php,
or (3) ArtID parameter to wmcomments.php.
|
| CVE-2006-1230 |
Multiple cross-site scripting (XSS) vulnerabilities in create.php in
vCard 2.x allow remote attackers to inject arbitrary web script or
HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4)
card_color parameter. NOTE: the card_id vector was later reported to
affect vCard 2.9, and the uploaded vector for 2.6.
|
| CVE-2006-1226 |
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8
and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web
script or HTML via unknown attack vectors.
|
| CVE-2006-1223 |
Cross-site scripting (XSS) vulnerability in Jupiter Content Manager
1.1.5 and earlier allows remote attackers to inject arbitrary web
script or HTML via a Javascript URI in the image BBcode tag.
|
| CVE-2006-1222 |
Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1
pl7 allows allow remote attackers to inject arbitrary web script or
HTML via the (1) memo box title, (2) user email, and (3) homepage
fields.
|
| CVE-2006-1216 |
Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x
allows remote attackers to inject arbitrary web script or HTML via the
id parameter.
|
| CVE-2006-1215 |
Cross-site scripting (XSS) vulnerability in misc.php in Woltlab
Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary
web script or HTML via the percent parameter. NOTE: this issue has
been disputed in a followup post, although the original disclosure
might be related to reflected XSS.
|
| CVE-2006-1205 |
Multiple cross-site scripting (XSS) vulnerabilities in myWebland
myBloggie 2.1.3 beta and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) confirmredirect and (2)
post_id parameters in (a) delcomment.php, as reachable when
mode=delcom from index.php; and the (3) del and (4) message parameters
in (b) upload.php, the (5) errormsg parameter in (c) addcat.php, (d)
edituser.php, (e) adduser.php, and (f) editcat.php, the (6)
trackback_url parameter in (g) add.php, (7) id parameter in (h)
deluser.php, (8) cat_id parameter in (i) delcat.php, and (9) post_id
parameter in (j) del.php, as reachable from admin.php.
|
| CVE-2006-1204 |
Multiple cross-site scripting (XSS) vulnerabilities in txtForum
1.0.4-dev and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) prev, (2) next, and (3) rand5 parameters in
(a) index.php; the (4) r_username and (5) r_loc parameters in (b)
new_topic.php; the (6) r_num, (7) r_family_name, (8) r_icq, (9)
r_yahoo, (10) r_aim, (11) r_homepage, (12) r_interests, (13) r_about,
(14) selected1, (15) selected0, (16) signature_selected1, (17)
signature_selected0, (18) smile_selected1, (19) smile_selected0, (20)
ubb_selected1, and (21) ubb_selected0 parameters in (c) profile.php;
the (22) quote and (23) tid parameters in (d) reply.php; and the (24)
tid, (25) sticked, and (26) mid parameters in (e) view_topic.php.
|
| CVE-2006-1202 |
Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) mess and (2) user parameters in messanger.php,
possibly requiring a URL encoded value.
|
| CVE-2006-1200 |
Direct static code injection vulnerability in add_link.txt in daverave
Link Bank allows remote attackers to execute arbitrary PHP code via
the url_name parameter, which is not sanitized before being stored in
links.txt, which is later used in an include statement.
|
| CVE-2006-1199 |
Cross-site scripting (XSS) vulnerability in iframe.php in daverave
Link Bank allows remote attackers to inject arbitrary web script or
HTML via the site parameter.
|
| CVE-2006-1196 |
Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) from and (2) help parameters to (a) index.php; (3) action, (4)
page, (5) debug, (6) help, (7) username, or (8) password parameters to
(b) login.php; the (7) help parameter to (c) pageindex.php; or (8)
help parameter to (d) recentchanges.php.
|
| CVE-2006-1193 |
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server
2000 SP1 through SP3, when running Outlook Web Access (OWA), allows
user-assisted remote attackers to inject arbitrary HTML or web script
via unknown vectors related to "HTML parsing."
|
| CVE-2006-1165 |
Cross-site scripting (XSS) vulnerability in the mediamanager module in
DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary
web script or HTML via unknown attack vectors relating to "handling
EXIF data."
|
| CVE-2006-1163 |
Cross-site scripting (XSS) vulnerability in Nodez 4.6.1.1 allows
remote attackers to inject arbitrary web script or HTML via the op
parameter. NOTE: it is possible that this issue is resultant from the
directory traversal vulnerability.
|
| CVE-2006-1160 |
Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS)
Web Server 3.2 allows remote attackers to inject arbitrary web script
or HTML via the Description field in creating a folder or uploading a
file.
|
| CVE-2006-1157 |
Cross-site scripting (XSS) vulnerability in Vz Scripts ADP Forum 2.0.3
and earlier allows remote attackers to inject arbitrary web script or
HTML via the Subject field (possibly messaggio parameter) when posting
a new message in post.php.
|
| CVE-2006-1155 |
Cross-site scripting (XSS) vulnerability in manas tungare Site
Membership Script before 8 March, 2006 allows remote attackers to
inject arbitrary web script or HTML via the Error parameter in (1)
login.asp and (2) default.asp.
|
| CVE-2006-1144 |
Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows
remote attackers to inject arbitrary web script or HTML via (1) the
user parameter in deleteuser.php and (2) the hits parameter in
viewuser.php.
|
| CVE-2006-1143 |
Cross-site scripting (XSS) vulnerability in FTPoed Blog Engine 1.1
allows remote attackers to inject arbitrary web script or HTML via the
comment_body parameter, as used by the comment field, when posting a
comment.
|
| CVE-2006-1135 |
Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) keyword parameter to search.php or (2) username parameter to
comments_do.php.
|
| CVE-2006-1133 |
Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11
allow remote attackers to inject arbitrary web script or HTML via the
UserID parameter to (1) comment.php or (2) contact.php. NOTE: the
profile.php/UserName vector is already covered by CVE-2005-2441.
|
| CVE-2006-1132 |
SQL injection vulnerability in show.php in vbzoom 1.11 allow remote
attackers to execute arbitrary SQL commands via the MainID parameter.
NOTE: the SubjectID vector is already covered by CVE-2005-4729.
|
| CVE-2006-1131 |
Cross-site scripting (XSS) vulnerability in read.php in bitweaver CMS
1.2.1 allows remote attackers to inject arbitrary web script or HTML
via the comment_title parameter.
|
| CVE-2006-1130 |
Cross-site scripting (XSS) vulnerability in EKINboard 1.0.3 allows
remote attackers to inject arbitrary web script or HTML via a
Javascript URI in a BBCode img tag.
|
| CVE-2006-1129 |
SQL injection vulnerability in config.php in EKINboard 1.0.3 allows
remote attackers to execute arbitrary SQL commands and bypass
authentication via the username cookie.
|
| CVE-2006-1127 |
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2
allows remote attackers to inject arbitrary web script or HTML via the
X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly
handled when adding a comment to an album.
|
| CVE-2006-1122 |
Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog
1.0.3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the msg parameter.
|
| CVE-2006-1121 |
Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows
remote attackers to inject arbitrary web script or HTML via the query
string to index.php.
|
| CVE-2006-1120 |
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal
6.1.1 and earlier, with register_globals enabled, allow remote
attackers to inject arbitrary web script or HTML via the (1) its_url
parameter in the documents page and (2) url parameter in the
send_write page of (a) index.php; (3) subject, and (4) images
parameters to (b) calendar.php; (5) bid, (6) replying_msg, (7)
subject, (8) body, and (9) mid parameters to (c) forums.php; (10)
subject and (11) message parameters to (d) inbox.php; (12)
subject_color and (13) email parameters to (e) lostpassword.php; and
the (14) c_name, (15) content_inicial, and (16) cid parameters to (f)
mycontents.php. NOTE: the calendar.php/day vector is already subsumed
by CVE-2006-0220, and the calendar.php/month, calendar.php/year, and
search.php/q parameters for calendar.php are already subsumed by
CVE-2004-2511.
|
| CVE-2006-1110 |
Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows
remote attackers to inject arbitrary web script or HTML via the
message body in a new message.
|
| CVE-2006-1108 |
SQL injection vulnerability in news.php in NMDeluxe before 1.0.1
allows remote attackers to execute arbitrary SQL commands via the id
parameter.
|
| CVE-2006-1107 |
Cross-site scripting (XSS) vulnerability in news.php in NMDeluxe
before 1.0.1 allows remote attackers to inject arbitrary web script or
HTML via the nick parameter.
|
| CVE-2006-1106 |
Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the (1) message, (2) name, (3) url, and (4) email parameters when
commenting on a post. NOTE: the vendor has disputed some issues from
the original disclosure, but due to the vagueness of the dispute, it
is not clear whether the vendor is disputing this particular issue.
|
| CVE-2006-1097 |
Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD
2.7 and earlier for Woltlab Burning Board allow remote attackers to
inject arbitrary web script or HTML via the fileid parameter to (1)
info_db.php or (2) database.php.
|
| CVE-2006-1096 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce
allows remote attackers to inject arbitrary web script or HTML via the
action parameter. NOTE: the vendor has disputed this issue in a
comment on the researcher's blog, but research by CVE suggests that
this might be a legitimate problem.
|
| CVE-2006-1089 |
Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10
allows remote attackers to inject arbitrary web script or HTML via the
URL, which is not properly handled when the PHP_SELF variable is used
to handle a pun_page tag.
|
| CVE-2006-1082 |
Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript
2.0 and earlier allow remote attackers to inject arbitrary web script
or HTML via (1) the gamename parameter in tellafriend.php, (2) the
login_status parameter in loginbox.php, (3) the submissionstatus
parameter in index.php, the (4) cell_title_background_color and (5)
browse_cat_name parameters in browse.php, the (6) gamefile parameter
in displaygame.php, and (7) possibly other parameters in unspecified
PHP scripts.
|
| CVE-2006-1080 |
Cross-site scripting (XSS) vulnerability in login.php in Game-Panel
2.6.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via the message parameter, possibly requiring a URL
encoded value.
|
| CVE-2006-1077 |
Multiple cross-site scripting (XSS) vulnerabilities in the commentary
in Evo-Dev evoBlog allow remote attackers to inject arbitrary web
script or HTML via (1) the name parameter and (2) other unspecified
parameters.
|
| CVE-2006-1072 |
Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via a blog post.
|
| CVE-2006-1071 |
Cross-site scripting (XSS) vulnerability in index.php in DVguestbook
1.2.2 allows remote attackers to inject arbitrary web script or HTML
via the page parameter.
|
| CVE-2006-1070 |
Cross-site scripting (XSS) vulnerability in dv_gbook.php in
DVguestbook 1.0 allows remote attackers to inject arbitrary web script
or HTML via the f parameter.
|
| CVE-2006-1064 |
Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and
earlier allow remote attackers to inject arbitrary web script or HTML
via unknown attack vectors.
|
| CVE-2006-1042 |
Multiple SQL injection vulnerabilities in Gregarius 0.5.2 allow remote
attackers to execute arbitrary SQL commands via the (1) folder
parameter to feed.php or (2) rss_query parameter to search.php.
|
| CVE-2006-1041 |
Multiple cross-site scripting (XSS) vulnerabilities in Gregarius 0.5.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) rss_query parameter to search.php or (2) tag parameter to
tags.php.
|
| CVE-2006-1040 |
Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3
allows remote attackers to inject arbitrary web script or HTML via the
email field, which is injected in profile.php but not sanitized in
sendmsg.php.
|
| CVE-2006-1034 |
Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning
Board (wBB) allow remote attackers to inject arbitrary web script or
HTML via (1) the username parameter to galerie_index.php and possibly
(2) galerie_onfly.php. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
The second vector might not be XSS.
|
| CVE-2006-1033 |
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS
before 9.0.6.1 allow remote attackers to inject arbitrary web script
or HTML via (1) uname, (2) error, (3) profile or (4) the username
filed parameter to the (a) Your_Account module, (5) catid, (6) sid,
(7) Story Text or (8) Extended text text fields in the (b) News
module, (9) month, (10) year or (11) sa parameter to the (c)
Stories_Archive module, (12) show, (13) cid, (14) ratetype, or (15)
orderby parameter to the (d) Web_Links module, (16) op, or (17) pollid
parameter to the (e) Surveys module, (18) c parameter to the (f)
Downloads module, (19) meta, or (20) album parameter to the (g)
coppermine module, or the search box in the (21) Search, (22)
Stories_Archive, (23) Downloads, and (24) Topics module.
|
| CVE-2006-1029 |
The cross-site scripting (XSS) countermeasures in
class.inputfilter.php in Joomla! 1.0.7 allow remote attackers to cause
a denial of service via a crafted mosmsg parameter to index.php with a
malformed sequence of multiple tags, as demonstrated using
"<<>AAA<><>", possibly due to nested or empty tags.
|
| CVE-2006-1025 |
Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft
StoreBot 2002 Standard allows remote attackers to inject arbitrary web
script or HTML via the ShipMethod parameter. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-1021 |
Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe
Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows
remote attackers to inject arbitrary web script or HTML via the kuladi
parameter ($kul_adi variable).
|
| CVE-2006-1019 |
Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1
allows remote attackers to inject arbitrary web script or HTML via a
BBCode url tag when using the show_post function. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information, some of which reference a source
URL that appears to be for an unrelated issue.
|
| CVE-2006-1008 |
Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and
1.2 allow remote attackers to inject arbitrary web script or HTML via
the (1) dir and (2) page_id parameter to (a) index.php and (3) userid
parameter to (b) mailto.php. NOTE: it is possible that issues 1 and 2
are resultant from SQL injection.
|
| CVE-2006-1007 |
Multiple SQL injection vulnerabilities in N8cms 1.1 and 1.2 allow
remote attackers to execute arbitrary SQL commands via the (1) dir and
(2) page_id parameter to index.php.
|
| CVE-2006-1004 |
Cross-site scripting (XSS) vulnerability in agencyprofile.asp in
Parodia 6.2 and earlier allows remote attackers to inject arbitrary
web script or HTML via the AG_ID parameter. NOTE: the provenance of
this information is unknown; the details are obtained from third party
information.
|
| CVE-2006-0996 |
Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP
5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script
or HTML via long array variables, including (1) a large number of
dimensions or (2) long values, which prevents HTML tags from being
removed.
|
| CVE-2006-0985 |
Multiple cross-site scripting (XSS) vulnerabilities in the "post
comment" functionality of WordPress 2.0.1 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1) name, (2)
website, and (3) comment parameters.
|
| CVE-2006-0984 |
Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo
2.2.178 allows remote attackers to inject arbitrary web script or HTML
via the gTopNombre parameter.
|
| CVE-2006-0983 |
Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4
allows remote attackers to inject arbitrary web script or HTML via the
page parameter.
|
| CVE-2006-0980 |
Multiple cross-site scripting (XSS) vulnerabilities in Jay Eckles CGI
Calendar 2.7 allow remote attackers to inject arbitrary web script or
HTML via the year parameter in (1) index.cgi and (2) viewday.cgi.
|
| CVE-2006-0978 |
Multiple cross-site scripting (XSS) vulnerabilities in the View
Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro
1.8.8.5 allow remote attackers to inject arbitrary web script or HTML
via (1) the Subject header, (2) the From header, and (3) certain other
unspecified headers.
|
| CVE-2006-0974 |
Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe
bttlxeForum 2.0 allows remote attackers to inject arbitrary web script
or HTML via the err_txt parameter.
|
| CVE-2006-0958 |
Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft
freeForum before 1.2.1 allows remote attackers to inject arbitrary web
script or HTML via the (1) name and (2) subject parameters.
|
| CVE-2006-0957 |
Direct static code injection vulnerability in func.inc.php in
ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute
arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP
headers, which are stored in Data/flood.db.php.
|
| CVE-2006-0947 |
Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote
attackers to create users that cannot be deleted via scripting code in
the "31" parameter in a NewUser function, which is not filtered by the
modem when creating the account, but cannot be deleted by the
administrator, possibly due to cleansing that occurs in the
administrator interface.
|
| CVE-2006-0946 |
Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems
running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary
web script or HTML via the name parameter to the LocalNetwork page.
|
| CVE-2006-0941 |
Multiple cross-site scripting (XSS) vulnerabilities in post.php in
ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script
or HTML via certain variables when posting new messages.
|
| CVE-2006-0940 |
Multiple direct static code injection vulnerabilities in
savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute
arbitrary PHP code via variables that are written to settings.php.
|
| CVE-2006-0938 |
Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the RefererURL parameter.
|
| CVE-2006-0934 |
Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2
allows remote attackers to inject arbitrary web script or HTML via the
message field in the Contact Form.
|
| CVE-2006-0933 |
Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote
attackers to inject arbitrary web script or HTML via a javascript URI
in a url XCode tag in a posted message. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-0927 |
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA
JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB)
2.x allow remote attackers to inject arbitrary web script or HTML via
the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b)
jgs_galerie_scroll.php, and the (2) katid parameter in (c)
jgs_galerie_slideshow.php.
|
| CVE-2006-0924 |
Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10
allows remote attackers to inject arbitrary web script or HTML via the
Calendar Text field when a new event is added. NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-0923 |
Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN)
1.88 and earlier allow remote attackers to inject arbitrary web script
or HTML via (1) the letter parameter in reviews.php and (2) the
dcategory parameter in download.php.
|
| CVE-2006-0896 |
Cross-site scripting (XSS) vulnerability in Sources/Register.php in
Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject
arbitrary web script or HTML via the X-Forwarded-For HTTP header
field.
|
| CVE-2006-0894 |
Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail
1.0 allow remote attackers to inject arbitrary web script or HTML via
(1) the html_error_occurred parameter in error.php, (2)
html_filter_select parameter in filter_prefs.php, (3) html_no_mail
parameter in no_mail.php, the (4) page_line, (5) prev, and (6) next
parameters in html_bottom_table.php, and the (7)
_SESSION['nocc_theme'] parameter in footer.php.
|
| CVE-2006-0889 |
Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows
remote attackers to inject arbitrary web script or HTML via the
EventText parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-0886 |
Cross-site scripting (XSS) vulnerability in register.php in DEV web
management system 1.5 allows remote attackers to inject arbitrary web
script or HTML via the "City/Region" field (mesto variable). NOTE:
the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2006-0885 |
Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews
1.4.1 allows remote attackers to inject arbitrary web script or HTML
via the show parameter.
|
| CVE-2006-0880 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web
script or HTML via the (1) inf parameter; or, when register_globals is
enabled, the (2) upperTemplate and (3) lowerTemplate parameters.
|
| CVE-2006-0877 |
Cross-site scripting vulnerability in Easy Forum 2.5 allows remote
attackers to inject arbitrary web script or HTML via the image
variable.
|
| CVE-2006-0861 |
Michael Salzer Guestbox 0.6, and other versoins before 0.8, allows
remote attackers to obtain the source IP addresses of guestbook
entries via a direct request to /gb/gblog.
|
| CVE-2006-0860 |
Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer
Guestbox 0.6, and other versions before 0.8, allow remote attackers to
inject arbitrary web script or HTML via (1) HTML tags that follow a
"http://" string, which bypasses a regular expression check, and (2)
other unspecified attack vectors.
|
| CVE-2006-0859 |
Michael Salzer Guestbox 0.6, and other versions before 0.8, allows
remote attackers to post an admin comment to a guestbook entry via a
certain modified form, possibly related to the nummer parameter.
|
| CVE-2006-0857 |
Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107
0.7.2 allows remote attackers to inject arbitrary HTML or web script
via a Chatbox, as demonstrated using a SCRIPT element.
|
| CVE-2006-0846 |
Multiple cross-site scripting (XSS) vulnerabilities in Leif M.
Wright's Blog 3.5 allow remote attackers to inject arbitrary web
script or HTML via the (1) Referer and (2) User-Agent HTTP headers,
which are stored in a log file and not sanitized when the
administrator views the "Log" page, possibly using the ViewCommentsLog
function.
|
| CVE-2006-0842 |
Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows
remote attackers to inject arbitrary web script or HTML via a modified
javascript: string in the SRC attribute of an IMG element in an e-mail
message, as demonstrated by "java	script:." NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-0841 |
Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4)
reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8)
show_status, (9) show_resolution, (10) show_build, (11) show_profile,
(12) show_priority, (13) highlight_changed, (14) relationship_type,
and (15) relationship_bug parameters in (a) view_all_set.php; the (16)
sort parameter in (b) manage_user_page.php; the (17) view_type
parameter in (c) view_filters_page.php; and the (18) title parameter
in (d) proj_doc_delete.php. NOTE: item 17 might be subsumed by
CVE-2005-4522.
|
| CVE-2006-0833 |
Multiple cross-site scripting (XSS) vulnerabilities in Barracuda
Directory 1.1 allow remote attackers to inject arbitrary web script or
HTML via unspecified vectors to the (1) Add URL and (2) Suggest
Category module. NOTE: the provenance of this information is unknown;
portions of the details are obtained from third party information.
|
| CVE-2006-0829 |
Cross-site scripting vulnerability in E-Blah Platinum 9.7 allows
remote attackers to inject arbitrary web script or HTML via the
referer (HTTP_REFERER), which is not sanitized when the log file is
viewed by the administrator using "Click Log".
|
| CVE-2006-0820 |
Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2
allows remote attackers to inject arbitrary web script or HTML via
unspecified error messages.
|
| CVE-2006-0811 |
Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board
0.9 allows remote attackers to inject arbitrary web script or HTML via
unspecified parameters involved with the registration form.
|
| CVE-2006-0810 |
Unspecified vulnerability in config.php in Skate Board 0.9 allows
remote authenticated administrators to execute arbitrary PHP code by
causing certain variables in config.php to be modified, possibly due
to XSS or direct static code injection.
|
| CVE-2006-0806 |
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as
used in multiple packages such as phpESP, allow remote attackers to
inject arbitrary web script or HTML via (1) the next_page parameter in
adodb-pager.inc.php and (2) other unspecified vectors related to
PHP_SELF.
|
| CVE-2006-0802 |
Cross-site scripting (XSS) vulnerability in the NS-Languages module
for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled,
allows remote attackers to inject arbitrary web script or HTML via the
language parameter in a missing or translation operation.
|
| CVE-2006-0800 |
Interpretation conflict in PostNuke 0.761 and earlier allows remote
attackers to conduct cross-site scripting (XSS) attacks via HTML tags
with a trailing "<" character, which is interpreted as a ">" character
by some web browsers but bypasses the blacklist protection in (1) the
pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput
function in pnAntiCracker.php, and (3) the htmltext parameter in an
edituser operation to user.php.
|
| CVE-2006-0796 |
Cross-site scripting (XSS) vulnerability in default.php in Clever Copy
3.0 allows remote attackers to inject arbitrary web script or HTML via
the Subject field when sending private messages (privatemessages.php).
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
|
| CVE-2006-0792 |
Cross-site scripting (XSS) vulnerability in preferences.personal.php
in V-webmail 1.6.2 allows remote attackers to inject arbitrary web
script or HTML via the newid parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-0783 |
Cross-site scripting (XSS) vulnerability in page.php in in Siteframe
Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject
arbitrary web script or HTML via the comment_text parameter to
the user comment page (/edit/Comment).
|
| CVE-2006-0780 |
Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in
PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) name and (2) email parameters.
|
| CVE-2006-0779 |
Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums
1.9.3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the username parameter, as demonstrated using a
URL-encoded iframe tag.
|
| CVE-2006-0776 |
Cross-site scripting (XSS) vulnerability in guestex.pl in Teca Scripts
Guestex 1.0 allows remote attackers to inject arbitrary web script or
HTML via the url parameter.
|
| CVE-2006-0773 |
Cross-site scripting (XSS) vulnerability in Hitachi Business Logic -
Container 02-03 through 03-00-/B on Windows, and 03-00 through
03-00-/B on Linux, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors in the extended receiving box
function.
|
| CVE-2006-0770 |
Cross-site scripting (XSS) vulnerability in calendar.php in
MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject
arbitrary web script or HTML via a URL that is not sanitized before
being returned as a link in "advanced details". NOTE: the provenance
of this information is unknown; the details are obtained solely from
third party information.
|
| CVE-2006-0763 |
Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in
cPanel allows remote attackers to inject arbitrary web script or HTML
via a URL encoded value in the fwd parameter.
|
| CVE-2006-0758 |
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3
and earlier allow remote attackers to inject arbitrary web script or
HTML via a URL encoded expression in the query string in (1) index.php
and (2) possibly certain other scripts, which is not properly cleansed
when accessed from the $_SERVER['PHP_SELF'] variable.
|
| CVE-2006-0735 |
Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom
HTML::BBCode 1.04 and earlier, as used in products such as My Blog
before 1.65, allows remote attackers to inject arbitrary Javascript via
a javascript URI in an (1) img or (2) url BBcode tag.
|
| CVE-2006-0733 |
** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress
2.0.0 allows remote attackers to inject arbitrary web script or HTML
via scriptable attributes such as (1) onfocus and (2) onblur in the
"author's website" field. NOTE: followup comments to the researcher's
web log suggest that this issue is only exploitable by the same user
who injects the XSS, so this might not be a vulnerability.
|
| CVE-2006-0726 |
Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke
Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web
script or HTML via a URI that is generated when creating a list of
online users.
|
| CVE-2006-0716 |
SQL injection vulnerability in index.php in sNews 1.3 allows remote
attackers to execute arbitrary SQL commands via the (1) category and
(2) id parameters.
|
| CVE-2006-0715 |
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote
attackers to inject arbitrary web script or HTML via the comment
field.
|
| CVE-2006-0706 |
Cross-site scripting vulnerability in eintrag.php in Gästebuch
(Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary
web script or HTML via the URL, which is used in the homepage
parameter.
|
| CVE-2006-0703 |
Unspecified vulnerability in index.php in imageVue 16.1 has unknown
impact, probably a cross-site scripting (XSS) vulnerability involving
the query string that is not quoted when inserted into style and body
tags, as demonstrated using a bgcol parameter.
|
| CVE-2006-0699 |
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki
1.5, and possibly 1.5.1 and other versions, allows remote attackers to
inject arbitrary web script or HTML via the query parameter.
|
| CVE-2006-0689 |
Cross-site scripting (XSS) vulnerability in the Registration Form in
TTS Time Tracking Software 3.0 allows remote attackers to inject
arbitrary web script or HTML via the UserName parameter.
|
| CVE-2006-0683 |
Cross-site scripting (XSS) vulnerability in Virtual Hosting Control
System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote
attackers to inject arbitrary web script or HTML via the username,
which is recorded in a log file but not properly handled when the
administrator uses the admin log utility to read the log file.
|
| CVE-2006-0682 |
Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system
in e107 before 0.7.2 allow remote attackers to inject arbitrary web
script or HTML via unknown attack vectors.
|
| CVE-2006-0676 |
Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0
to 7.8 allows remote attackers to inject arbitrary web script or HTML
via the pagetitle parameter.
|
| CVE-2006-0675 |
Cross-site scripting (XSS) vulnerability in search.php in Siteframe
5.0.1 allows remote attackers to inject arbitrary web script or HTML
via the q parameter.
|
| CVE-2006-0664 |
Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in
Mantis before 1.0 allows remote attackers to inject arbitrary web
script or HTML via unknown attack vectors. NOTE: the provenance of
this information is unknown; the details are obtained solely from
third party information. An original vendor bug report is referenced,
but not accessible to the general public.
|
| CVE-2006-0663 |
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino
iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary
web script or HTML via (1) an email subject; (2) an encoded javascript
URI, as demonstrated using "java script:"; or (3) when the Domino
Web Access ActiveX control is not installed, via an email attachment
filename.
|
| CVE-2006-0662 |
Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client
6.5.4 allows remote attackers to inject arbitrary web script or HTML
via email with attached html files, which are directly rendered in the
browser.
|
| CVE-2006-0661 |
Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21
and SmE Blog Host allows remote attackers to inject arbitrary web
script or HTML via the BBcode url tag.
|
| CVE-2006-0657 |
Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event
Calendar 1.5 allows remote authenticated users to inject arbitrary web
script or HTML, and corrupt data, via the (1) username and (2)
password parameters, which are not sanitized before being written to
users.php. NOTE: while this issue was originally reported as XSS, the
primary issue might be direct static code injection with resultant
XSS.
|
| CVE-2006-0655 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
link_edited.php and (2) link_added.php in Hinton Design phpht Topsites
1.3 allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-0650 |
Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the
CPAINT library before 2.0.3, as used in multiple scripts, allows
remote attackers to inject arbitrary web script or HTML via the
cpaint_response_type parameter, which is displayed in a resulting
error message, as demonstrated using a hex-encoded IFRAME tag.
|
| CVE-2006-0649 |
Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-0643 |
Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web
Conferencing 4.1.0.755 allows remote authenticated users to inject
arbitrary web script or HTML via the topic name of a conference.
|
| CVE-2006-0639 |
Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka
MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the
table prefix to inject arbitrary web script or HTML via a URL encoded
value of the keywords parameter, as demonstrated by %3Cscript%3E.
|
| CVE-2006-0627 |
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0, 2.0a, and
3.0 allows remote attackers to inject arbitrary web script or HTML via
the (1) Referer or (2) X-Forwarded-For headers in an HTTP request,
which are not properly handled when the administrator accesses Site
Stats.
|
| CVE-2006-0609 |
Cross-site scripting (XSS) vulnerability in add.php in Hinton Design
phphd 1.0 allows remote attackers to inject arbitrary web script or
HTML via unknown vectors.
|
| CVE-2006-0606 |
SQL injection vulnerability in Unknown Domain Shoutbox 2005.07.21
allows remote attackers to execute arbitrary SQL commands via unknown
attack vectors.
|
| CVE-2006-0605 |
Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain
Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web
script or HTML, possibly via the (1) Handle or (2) Message fields.
|
| CVE-2006-0593 |
Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304
allows remote attackers to inject arbitrary web script or HTML via the
(1) shout_name field in shoutbox_panel.php and the (2) comments field
in comments_include.php.
|
| CVE-2006-0574 |
Cross-site scripting (XSS) vulnerability in mime/handle.html in cPanel
10 allows remote attackers to inject arbitrary web script or HTML via
the (1) file extension or (2) mime-type.
|
| CVE-2006-0573 |
Multiple cross-site scripting (XSS) vulnerabilies in cPanel 10 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) email parameter to (a) editquota.html or (b)
dodelpop.html; (2) showtree parameter to (c) diskusage.html; or the
(3) mon, (4) year, (5) target, or (6) domain parameter to (d)
stats/detailbw.html.
|
| CVE-2006-0571 |
Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0
allow remote attackers to inject arbitrary web script or HTML via
unknown attack vectors in the administrative interface.
|
| CVE-2006-0569 |
Cross-site scripting (XSS) vulnerability in user_class.php in Papoo
2.1.4 and earlier allows remote attackers to inject arbitrary web
script or HTML via the username field during the registration of a new
account. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information.
|
| CVE-2006-0568 |
Cross-site scripting (XSS) vulnerability in throw.main in Outblaze
allows remote attackers to inject arbitrary web script or HTML via the
file parameter.
|
| CVE-2006-0563 |
SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c
allows remote attackers to execute arbitrary SQL commands via the
entryid parameter in a comment_add action.
|
| CVE-2006-0562 |
Cross-site scripting (XSS) vulnerability in problem.php in PluggedOut
Blog 1.9.9c allows remote attackers to inject arbitrary web script or
HTML via the data parameter.
|
| CVE-2006-0541 |
Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla
Guestbook 1.0 beta allow remote attackers to inject arbitrary web
script or HTML via unknown vectors related to "posting new messages."
|
| CVE-2006-0540 |
Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook
1.0 beta allow remote attackers to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2006-0536 |
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27
allows remote attackers to inject arbitrary web script or HTML via the
sort parameter. NOTE: some sources say that the affected parameter is
"date," but the demonstration URL shows that it is "sort".
|
| CVE-2006-0535 |
Multiple cross-site scripting (XSS) vulnerabilities in Community
Server allow remote attackers to inject arbitrary web script or HTML
via unknown attack vectors. NOTE: this candidate does not contain any
actionable or distinguishing information. Perhaps it should not be
included in CVE. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2006-0534 |
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in
CyberShop Ultimate E-commerce allow remote attackers to inject
arbitrary web script or HTML via the (1) ortak or (2) kat parameter.
|
| CVE-2006-0533 |
Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel
allows remote attackers to inject arbitrary web script or HTML via the
numdays parameter.
|
| CVE-2006-0532 |
Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker
Shop allows remote attackers to inject arbitrary web script or HTML
via a strSok parameter containing a javascript: URI in an IMG SRC
attribute.
|
| CVE-2006-0524 |
Cross-site scripting (XSS) vulnerability in ashnews.php in Derek
Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web
script or HTML via the id parameter.
|
| CVE-2006-0521 |
Cross-site scripting (XSS) vulnerability in results.php in BrowserCRM
allows remote attackers to inject arbitrary web script or HTML via
certain manipulations of the query parameter, as demonstrated using an
IMG SRC tag.
|
| CVE-2006-0518 |
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e
and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers
to inject arbitrary web script or HTML via the lang parameter.
|
| CVE-2006-0509 |
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in
Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject
arbitrary web script or HTML via (1) the contact_search parameter and
(2) unspecified url fields.
|
| CVE-2006-0508 |
Easy CMS stores the images directory under the web document root with
insufficient access control and browsing enabled, which allows remote
attackers to list and possibly read images that are stored in that
directory.
|
| CVE-2006-0507 |
Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow
remote attackers to inject arbitrary web script or HTML via (1)
unknown attack vectors in the administrative interface and (2) input
fields of the contact form.
|
| CVE-2006-0506 |
Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN
1.7 allows remote attackers to inject arbitrary web script or HTML via
the letter parameter.
|
| CVE-2006-0501 |
Cross-site scripting (XSS) vulnerability in MyCO Guestbook 1.0 allows
remote attackers to inject arbitrary web script or HTML via the Name
field, when registering a user.
|
| CVE-2006-0499 |
Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0
module for phpBB allows remote attackers to inject arbitrary web
script or HTML via the url parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-0498 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before
1.4 allow remote attackers to inject arbitrary web script or HTML via
unknown attack vectors.
|
| CVE-2006-0496 |
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and
possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and
Netscape 8.1 and possibly earlier, allows remote attackers to inject
arbitrary web script or HTML via the -moz-binding (Cascading Style
Sheets) CSS property, which does not require that the style sheet have
the same origin as the web page, as demonstrated by the compromise of
a large number of LiveJournal accounts.
|
| CVE-2006-0495 |
Cross-site scripting (XSS) vulnerability in the Add Thread to
Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02
allows remote attackers to inject arbitrary web script or HTML via an
HTTP Referer header ($url variable).
|
| CVE-2006-0493 |
Cross-site scripting (XSS) vulnerability in MG2 (formerly known as
Minigal) 0.5.1 allows remote attackers to inject arbitrary web script
or HTML via the Name field in a comment associated with a picture.
|
| CVE-2006-0480 |
Cross-site scripting (XSS) vulnerability in the Articles module in
sPaiz-Nuke allows remote attackers to inject arbitrary web script or
HTML via the query parameter in the search file.
|
| CVE-2006-0479 |
pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled,
allows remote attackers to bypass protection mechanisms that
deregister global variables by setting both a GPC variable and a
GLOBALS[] variable with the same name, which causes PmWiki to unset
the GLOBALS[] variable but not the GPC variable, which creates
resultant vulnerabilities such as remote file inclusion and cross-site
scripting (XSS).
|
| CVE-2006-0473 |
Cross-site scripting (XSS) vulnerability in the bbcode function in
weblog.php in my little homepage my little weblog, as last modified in
April 2004, allows remote attackers to inject arbitrary Javascript via
a javascript URI in BBcode link tags.
|
| CVE-2006-0472 |
Cross-site scripting (XSS) vulnerability in guestbook.php in my little
homepage my little guestbook, as last modified in March 2004, allows
remote attackers to inject arbitrary Javascript via a javascript URI
in BBcode link tags.
|
| CVE-2006-0471 |
Cross-site scripting (XSS) vulnerability in the bbcode function in
functions.php in my little homepage my little forum, as last modified
in June 2005, allows remote attackers to inject arbitrary Javascript
via a javascript URI in BBcode link tags.
|
| CVE-2006-0470 |
Cross-site scripting (XSS) vulnerability in search.php in
MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject
arbitrary web script or HTML via the (1) sortby and (2) sortordr
parameters, which are not properly handled in a redirection.
|
| CVE-2006-0469 |
Cross-site scripting (XSS) vulnerability in UebiMiau 2.7.9, and
possibly earlier versions, allows remote attackers to inject arbitrary
web script or HTML via a javascript: URI in the SRC attribute of an
IMG tag.
|
| CVE-2006-0466 |
Cross-site scripting (XSS) vulnerability in search.asp in Goldstag
Content Management System allows remote attackers to inject arbitrary
web script or HTML via the text parameter.
|
| CVE-2006-0465 |
Cross-site scripting (XSS) vulnerability in risultati_ricerca.php in
active121 Site Manager allows remote attackers to inject arbitrary web
script or HTML via the cerca parameter.
|
| CVE-2006-0463 |
Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows
remote attackers to inject arbitrary web script or HTML via the (1)
goto_id parameter to index.php or (2) page parameter to news_full.php.
|
| CVE-2006-0461 |
Cross-site scripting (XSS) vulnerability in core.input.php in
ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web
script or HTML via HTTP_REFERER (referer).
|
| CVE-2006-0444 |
SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW)
1.23.1 allows remote attackers to execute arbitrary SQL commands via
the (1) par parameter in the post function on the forum page and
possibly the (2) poll_id parameter on the poll page. NOTE: the
poll_id vector can also allow resultant cross-site scripting (XSS)
from an unquoted error message for invalid SQL syntax.
|
| CVE-2006-0443 |
Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog
1.0 allows remote attackers to inject arbitrary web script or HTML via
the (1) realname and (2) comment parameters, or (3) via a javascript
URI in the url parameter, when adding a comment.
|
| CVE-2006-0442 |
Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in
MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary
web script or HTML via the (1) notepad parameter in a notepad action
and (2) signature parameter in an editsig action. NOTE: These are
different attack vectors, and probably a different vulnerability, than
CVE-2006-0218 and CVE-2006-0219.
|
| CVE-2006-0438 |
Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when
Link to off-site Avatar or bbcode (IMG) are enabled, allows remote
attackers to perform unauthorized actions as a logged in user via a
link or IMG tag in a user profile, as demonstrated using links to (1)
admin/admin_users.php and (2) modcp.php.
|
| CVE-2006-0437 |
Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB
2.0.19 allows remote attackers to inject arbitrary web script or HTML
via Javascript events such as "onmouseover" in the (1) smile_url or
(2) smile_emotion parameters, which bypasses a check for "<" and ">"
characters.
|
| CVE-2006-0415 |
Cross-site scripting (XSS) vulnerability in index.php in SleeperChat
0.3f and earlier allows remote attackers to inject arbitrary web
script or HTML via the pseudo parameter.
|
| CVE-2006-0409 |
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost
Photoblog 1.4.3 allows remote attackers to inject arbitrary web script
or HTML via the "Add Comment" field in a comment popup.
|
| CVE-2006-0407 |
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin
Board (AZbb) 1.1.00 and earlier allows remote attackers to inject
arbitrary web script or HTML via the (1) nickname parameter and (2) an
iframe tag in the topic parameter. NOTE: the original disclosure
specified the name parameter, but a correction was later provided.
NOTE: followup posts have both disputed and confirmed the original
claim.
|
| CVE-2006-0389 |
Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS)
in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute
arbitrary JavaScript via unspecified vectors involving RSS feeds.
|
| CVE-2006-0378 |
Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager
allows remote attackers to inject arbitrary web script or HTML via the
product_id parameter, as originally demonstrated for a custom
mp3players_details.php program. NOTE: the name of the affected
program might be installation-dependent, but it has been identified as
"product_details.php" by some sources.
|
| CVE-2006-0373 |
Cross-site scripting (XSS) vulnerability in register.aspx in Douran
FollowWeb allows remote attackers to inject arbitrary web script or
HTML via unknown attack vectors. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-0366 |
Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW)
allows remote attackers to inject arbitrary web script or HTML via a
javascript URI in a BBCode img tag.
|
| CVE-2006-0365 |
Cross-site scripting (XSS) vulnerability in XMB (aka extreme message
board) allows remote attackers to inject arbitrary web script or HTML
via JavaScript in the SRC attribute of an IMG element.
|
| CVE-2006-0364 |
Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB)
allows remote attackers to inject arbitrary web script or HTML via a
signature containing a JavaScript URI in the SRC attribute of an IMG
element, in which the URI uses SGML numeric character references
without trailing semicolons, as demonstrated by
"javascript".
|
| CVE-2006-0361 |
Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5
Blog 8.01 allows remote attackers to inject arbitrary web script or
HTML via a javascript URI in an <a> tag in the comment parameter,
which strips most tags but not <a>.
|
| CVE-2006-0350 |
Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote
attackers to inject arbitrary web script or HTML via the message field
to topic.php.
|
| CVE-2006-0349 |
SQL injection vulnerability in eggblog 2.0 allows remote attackers to
execute arbitrary SQL commands via the id parameter to blog.php.
|
| CVE-2006-0346 |
Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows
remote attackers to inject arbitrary web script or HTML via a website
field in a new comment to view.php, which is not properly handled in
the comment function in functions.php.
|
| CVE-2006-0345 |
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote
attackers to execute arbitrary SQL commands via the search parameter
to search.php. NOTE: the id/viewprofile.php issue is already covered
by CVE-2005-4058.
|
| CVE-2006-0341 |
Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe
MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject
arbitrary web script or HTML via the query string.
|
| CVE-2006-0334 |
Cross-site scripting (XSS) vulnerability in search.php in My Amazon
Store Manager 1.0 allows remote attackers to inject arbitrary web
script or HTML via the Keywords parameter. NOTE: some sources claim
that the affected parameter is "q", but the only public archive of the
original researcher notification shows an XSS manipulation in
"Keywords".
|
| CVE-2006-0333 |
Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote
attackers to inject arbitrary web script or HTML via the (1) month or
(2) year parameter to index.php.
|
| CVE-2006-0330 |
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2
allows remote attackers to inject arbitrary web script or HTML via
unknown attack vectors, possibly involving the user name (fullname).
|
| CVE-2006-0317 |
Cross-site scripting (XSS) vulnerability in rkrt_stats.php in
RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject
arbitrary web script or HTML via a query string value as a GET, which
is stored in the $QUERY_STRING variable. NOTE: the provenance of this
information is unknown; portions of the details are obtained from
third party information.
|
| CVE-2006-0315 |
index.php in EZDatabase before 2.1.2 does not properly cleanse the p
parameter before constructing and including a .php filename, which
allows remote attackers to conduct directory traversal attacks, and
produces resultant cross-site scripting (XSS) and path disclosure.
|
| CVE-2006-0310 |
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows
remote attackers to inject arbitrary Javascript via a javascript URI
in the BBcode url tag.
|
| CVE-2006-0254 |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo
1.0 allow remote attackers to inject arbitrary web script or HTML via
the (1) time parameter to cal2.jsp and (2) any invalid parameter,
which causes an XSS when the log file is viewed by the Web-Access-Log
viewer.
|
| CVE-2006-0251 |
Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic
2.711 allows remote attackers to inject arbitrary web script or HTML
via the (1) _duration, (2) file, and (3) cmd parameters.
|
| CVE-2006-0247 |
Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula
Anyboard 9.9 and earlier allows remote attackers to inject arbitrary
web script or HTML via the tK parameter in a find command.
|
| CVE-2006-0246 |
Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download
Tracker 1.06 allows remote attackers to inject arbitrary web script or
HTML via the ID parameter.
|
| CVE-2006-0245 |
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart
3.0.7-pl1 allow remote attackers to inject arbitrary web script or
HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7)
catId parameters in index.php; and the (8) username field in a login
action in index.php. NOTE: the cart.php/redir and index.php/searchStr
vectors are already covered by CVE-2005-3152.
|
| CVE-2006-0243 |
Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote
attackers to inject arbitrary web script or HTML via the text
parameter, which is used by the "Search Site" field. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2006-0241 |
Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows
remote attackers to inject arbitrary web script or HTML via the Name
field.
|
| CVE-2006-0240 |
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote
attackers to execute arbitrary SQL commands via the month parameter in
an archives view operation and possibly certain other parameters in
unspecified scripts.
|
| CVE-2006-0239 |
Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1
allow remote attackers to inject arbitrary web script or HTML via (1)
a comment to comments.asp and (2) possibly certain other fields in
unspecified scripts.
|
| CVE-2006-0237 |
Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce
allows remote attackers to inject arbitrary web script or HTML via the
(1) cat and (2) subcat parameters. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-0233 |
Cross-site scripting (XSS) vulnerability in functions.php in microBlog
2.0 RC-10 allows remote attackers to inject arbitrary web script and
HTML via a javascript: URI in a [url] BBcode tag.
|
| CVE-2006-0222 |
Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft
Template Seller Pro allows remote attackers to inject arbitrary web
script or HTML via the tempid parameter.
|
| CVE-2006-0220 |
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3
through 6.1.1 allow remote attackers to inject arbitrary web script or
HTML via (1) the day parameter in calendar.php and (2) the input form
in search.php. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information. It is
possible that this issue is resultant from an SQL injection problem in
CVE-2005-4227.3 and CVE-2005-4227.13.
|
| CVE-2006-0217 |
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate
Auction 3.67 allow remote attackers to inject arbitrary web script or
HTML via the (1) item parameter in item.pl and (2) category parameter
in itemlist.pl, which reflects the XSS in an error message. NOTE: the
affected version might be wrong since the current version as of
20060116 is 3.6.1.
|
| CVE-2006-0215 |
Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz
Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject
arbitrary web script or HTML via the cpage parameter. NOTE: this
issue might be resultant from CVE-2006-0216.
|
| CVE-2006-0211 |
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm
Hosting Control Panel 3.2.8 and earlier allows remote attackers to
inject arbitrary web script or HTML via the txtEmailAddress parameter.
|
| CVE-2006-0210 |
Cross-site scripting (XSS) vulnerability in index.php in Interspire
TrackPoint NX before 0.1 allows remote attackers to inject arbitrary
web script or HTML via the username parameter when using the Login
page.
|
| CVE-2006-0208 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and
5.1.1, when display_errors and html_errors are on, allow remote
attackers to inject arbitrary web script or HTML via inputs to PHP
applications that are not filtered when they are included in the
resulting error message.
|
| CVE-2006-0205 |
Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote
attackers to (1) execute arbitrary SQL commands and bypass
authentication via the password field in the login action to index.php
(involving v_login.php and s_user.php) and (2) have other unknown
impact via certain other fields in unspecified scripts.
|
| CVE-2006-0204 |
Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17
allow remote attackers to inject arbitrary web script or HTML via (1)
the "Course name" field in index.php when the frm parameter has the
value "mine" and (2) possibly certain other fields in unspecified
scripts.
|
| CVE-2006-0198 |
Cross-site scripting (XSS) vulnerability in a certain module, possibly
poll or Pool, for XOOPS allows remote attackers to inject arbitrary
web script or HTML via JavaScript in the SRC attribute of an IMG
element in a comment.
|
| CVE-2006-0195 |
Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0
to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS)
attacks via style sheet specifiers with invalid (1) "/*" and "*/"
comments, or (2) a newline in a "url" specifier, which is processed by
certain web browsers including Internet Explorer.
|
| CVE-2006-0194 |
Cross-site scripting (XSS) vulnerability in default.asp in FogBugz
4.029, and other versions before 4.0.33, allows remote attackers to
inject arbitrary web script or HTML via the dest parameter in the
pgLogon page.
|
| CVE-2006-0193 |
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel
(psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the login parameter in a login action.
|
| CVE-2006-0188 |
webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to
inject arbitrary web pages into the right frame via a URL in the
right_frame parameter. NOTE: this has been called a cross-site
scripting (XSS) issue, but it is different than what is normally
identified as XSS.
|
| CVE-2006-0180 |
Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2
allows remote attackers to inject arbitrary web script or HTML via the
Title field on the "Adding New Event" page, and possibly other vectors,
involving iframe tags.
|
| CVE-2006-0175 |
Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz
Forums 6.34 allows remote attackers to inject arbitrary web script or
HTML via the search parameter.
|
| CVE-2006-0172 |
Cross-site scripting (XSS) vulnerability in the file manager utility
in Hummingbird Collaboration (aka Hummingbird Enterprise
Collaboration) 5.21 and earlier allows remote attackers to inject
arbitrary web script or HTML in an uploaded page, which is published
without a check for hostile scripting.
|
| CVE-2006-0168 |
Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows
remote attackers to inject arbitrary web script or HTML via the
description field on the "Create New todo" page.
|
| CVE-2006-0167 |
SQL injection vulnerability in MyPhPim 01.05 allows remote attackers
to execute arbitrary SQL commands via the (1) cal_id parameter in
calendar.php3 and the (2) password field on the login page.
|
| CVE-2006-0165 |
Cross-site scripting (XSS) vulnerability in the DataForm Entries
functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote
attackers to inject arbitrary Javascript via the (1) url and (2) name
field of the default email form.
|
| CVE-2006-0156 |
Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows
remote attackers to inject arbitrary Javascript via the javascript URI
in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.
|
| CVE-2006-0155 |
Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and
2.2.1 allows remote attackers to inject arbitrary Javascript via a new
message with a url bbcode tag containing a javascript URI.
|
| CVE-2006-0154 |
SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1
allows remote attackers to execute arbitrary SQL commands via the
ForumID parameter.
|
| CVE-2006-0153 |
427BB 2.2 and 2.2.1 verifies authentication credentials based on the
username, authenticated, and usertype cookies, which allows remote
attackers to bypass authentication by using a valid username and
usertype and setting the authenticated cookie.
|
| CVE-2006-0152 |
Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the needle parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2006-0149 |
Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with
html_enable on (the default), allows remote attackers to inject
arbitrary web script or HTML via the message field.
|
| CVE-2006-0142 |
Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda
1.9.3.4 and earlier allows remote attackers to inject arbitrary web
script or HTML via the s parameter. NOTE: the provenance of this
information is unknown; the details are obtained solely from third
party information.
|
| CVE-2006-0140 |
Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16
Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary
web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode
tags.
|
| CVE-2006-0136 |
Multiple cross-site scripting (XSS) vulnerabilities in the guestbook
module in modules.php in Phanatic Softwares Chimera Web Portal System
0.2 allow remote attackers to inject arbitrary web script or HTML via
the (1) comment_poster, (2) comment_poster_email, (3)
comment_poster_homepage, and (4) comment_text parameters.
|
| CVE-2006-0134 |
Cross-site scripting (XSS) vulnerability in register.php in
TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary
web script or HTML via the www parameter.
|
| CVE-2006-0124 |
Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum
1.0b allows remote attackers to inject arbitrary web script or HTML via
the titulo parameter, which is used by the "Topic name" field.
|
| CVE-2006-0122 |
Cross-site scripting (XSS) vulnerability in Public/Index.asp in
Aquifer CMS allows remote attackers to inject arbitrary web script or
HTML via the Keyword parameter.
|
| CVE-2006-0112 |
Cross-site scripting (XSS) vulnerability in index.php in Enhanced
Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web
script or HTML via the dir parameter.
|
| CVE-2006-0110 |
Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus
2.10 allows remote attackers to inject arbitrary web script via the
email parameter.
|
| CVE-2006-0109 |
Cross-site scripting vulnerability in category.php in Modular Merchant
Shopping Cart allows remote attackers to inject arbitrary web script
or HTML via the cat parameter.
|
| CVE-2006-0102 |
Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and
earlier allows remote attackers to inject arbitrary web script via a
javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter
to action.php.
|
| CVE-2006-0101 |
Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1
Beta 20051202 and earlier allow remote attackers to inject arbitrary
web script or HTML via the (1) p and (2) keyword parameters in (a)
index.php and (b) search.php.
|
| CVE-2006-0093 |
Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP
allows remote attackers to inject arbitrary web script or HTML via the
cat parameter.
|
| CVE-2006-0091 |
Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange
0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote
attackers to inject arbitrary web script or HTML via e-mail
attachments, which are rendered inline.
|
| CVE-2006-0084 |
Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).
|
| CVE-2006-0080 |
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and
possibly earlier versions, allows remote attackers to inject arbitrary
web script or HTML via the title of an event, which is not properly
filtered by (1) calendar.php and (2) reminder.php.
|
| CVE-2006-0078 |
Multiple cross-site scripting (XSS) vulnerabilities in B-net Software
1.0 allow remote attackers to inject arbitrary web script or HTML via
the (1) name and (2) shout variables to (a) shout.php, or the (3)
title and (4) message variables to (b) guestbook.php.
|
| CVE-2006-0073 |
Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware
3.10.5 and Professional 3.10.4 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors in a URL, which
is not properly sanitized from the resulting error message. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2006-0070 |
** DISPUTED **
Drupal allows remote attackers to conduct cross-site scripting (XSS)
attacks via an IMG tag with an unusual encoded Javascript function
name, as demonstrated using variations of the alert() function. NOTE:
a followup by the vendor suggests that the issue does not exist in
4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML"
would not filter HTML by design, perhaps this should not be included
in CVE.
|
| CVE-2006-0069 |
Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk
Guestbook 1.4 and earlier allows remote attackers to inject arbitrary
web script or HTML via the homepage parameter.
|
| CVE-2006-0063 |
Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when
"Allowed HTML tags" is enabled, allows remote attackers to inject
arbitrary web script or HTML via a permitted HTML tag with ' (single
quote) characters and active attributes such as onmouseover, a variant
of CVE-2005-4357.
|
| CVE-2006-0032 |
Cross-site scripting (XSS) vulnerability in the Indexing Service in
Microsoft Windows 2000, XP, and Server 2003, when the Encoding option
is set to Auto Select, allows remote attackers to inject arbitrary web
script or HTML via a UTF-7 encoded URL, which is injected into an
error message whose charset is set to UTF-7.
|
| CVE-2006-0015 |
Cross-site scripting (XSS) vulnerability in
_vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server
Extensions 2002 and SharePoint Team Services allows remote attackers
to inject arbitrary web script or HTML, then leverage the attack to
execute arbitrary programs or create new accounts, via the (1)
operation, (2) command, and (3) name parameters.
|
| CVE-2005-4879 |
Multiple cross-site scripting (XSS) vulnerabilities in
jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers
to inject arbitrary web script or HTML via the (1) gmt_ofs and (2)
language parameters. NOTE: the page parameter is already covered by
CVE-2006-1913. NOTE: it was later reported that 3.50 is also
affected.
|
| CVE-2005-4878 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
acid_qry_main.php in Analysis Console for Intrusion Databases (ACID)
0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security
Engine (BASE) 1.2, and unspecified other console scripts in these
products, allow remote attackers to inject arbitrary web script or
HTML via the sig[1] parameter and possibly other parameters, a
different vulnerability than CVE-2007-6156.
|
| CVE-2005-4877 |
Cross-site scripting (XSS) vulnerability in the login form (login.jsp)
of the admin console in Openfire (formerly Wildfire) 2.3.0 Beta 2
allows remote attackers to inject arbitrary web script or HTML via
Javascript events in the username parameter, a different vulnerability
than CVE-2005-4876.
|
| CVE-2005-4876 |
Cross-site scripting (XSS) vulnerability in the login form (login.jsp)
of the admin console in Openfire (formerly Wildfire) 2.2.2, and
possibly other versions before 2.3.0 Beta 2, allows remote attackers
to inject arbitrary web script or HTML via the username parameter, a
different vulnerability than CVE-2005-4877.
|
| CVE-2005-4858 |
Multiple cross-site scripting (XSS) vulnerabilities in mimic2.cgi in
mimicboard2 (Mimic2) 086 and earlier allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters associated
with the (1) name, (2) title, and (3) comment sections, as
demonstrated by referencing a remote document through the SRC
attribute of an IFRAME element.
|
| CVE-2005-4855 |
Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5,
3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does
not restrict Image datatype uploads to image content types, which
allows remote authenticated users to upload certain types of files, as
demonstrated by .js files, which may enable cross-site scripting (XSS)
attacks or other attacks.
|
| CVE-2005-4838 |
Multiple cross-site scripting (XSS) vulnerabilities in the example web
applications for Jakarta Tomcat 5.5.6 and earlier allow remote
attackers to inject arbitrary web script or HTML via (1)
el/functions.jsp, (2) el/implicit-objects.jsp, and (3)
jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in
a request to snp/snoop.jsp. NOTE: other XSS issues in the manager
were simultaneously reported, but these require admin access and do
not cross privilege boundaries.
|
| CVE-2005-4831 |
viewcvs in ViewCVS 0.9.2 allows remote attackers to set the
Content-Type header to arbitrary values via the content-type
parameter, which can be leveraged for cross-site scripting (XSS) and
other attacks, as demonstrated using (1) "text/html", or (2)
"image/jpeg" with an image that is rendered as HTML by Internet
Explorer, a different vulnerability than CVE-2004-1062. NOTE: it was
later reported that 0.9.4 is also affected.
|
| CVE-2005-4819 |
Cross-site scripting (XSS) vulnerability in Lotus Domino versions
before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2005-4801 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Yet
Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote
attackers to perform unauthorized actions as a logged-in user, as
demonstrated by tricking the administrator to access a web page that
performs a mod_info action in modify_gallery.php.
|
| CVE-2005-4800 |
Direct static code injection vulnerability in Yet Another PHP Image
Gallery (YaPIG) 0.95b and earlier allows remote authenticated
administrators to inject arbitrary PHP code via the TestGallery
parameter in a mod_info action to modify_gallery.php, which inserts
the code into guid_info.php. NOTE: this issue is easier to exploit
due to a separate CSRF vulnerability.
|
| CVE-2005-4799 |
Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP
Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to
inject arbitrary web script or HTML via (1) the Homepage field (aka
the Website field) in an "image-related comment" and (2) the img_size
field in view.php. NOTE: due to lack of details from the researcher,
it is not clear whether the comment vector overlaps CVE-2005-1886.
|
| CVE-2005-4785 |
Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the (1) author ("your name") and (2) "comment" section.
|
| CVE-2005-4780 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0
and earlier allows remote attackers to inject arbitrary web script or
HTML via the search parameter in a query_string to the home page.
NOTE: The vendor disputes this issue, saying "Lighthouse does not in
any way make use of the PHP technology. [It] is an application server
... A technology like this cannot be susceptible to client-side
cross-site-scripting-attacks on its own, but only applications created
based on such a technology. This does not only apply to Lighthouse,
but also to Perl, PHP or web applications based on Java Servlet
technology." Since the original researcher is known to test demo
pages and is sometimes inaccurate, it is likely that this issue will
be REJECTED.
|
| CVE-2005-4774 |
Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote
attackers to inject arbitrary web script or HTML after a /%00/
sequence at the end of the URI.
|
| CVE-2005-4751 |
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic
Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and
earlier, and 6.1 SP7 and earlier allow remote attackers to inject
arbitrary web script or HTML and gain administrative privileges via
unknown attack vectors.
|
| CVE-2005-4748 |
PHP remote file include vulnerability in functions_admin.php in
Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and
execute arbitrary PHP code via unspecified attack vectors. NOTE: this
issue has been referred to as XSS, but it is clear from the vendor
description that it is a file inclusion problem.
|
| CVE-2005-4747 |
Cross-site scripting (XSS) vulnerability in WebHost Automation Ltd
Helm before 3.2.6 allows remote attackers to inject arbitrary web
script or HTML via unknown vectors involving the default page.
|
| CVE-2005-4732 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Tux Racer TuxBank 0.7x and 0.8 allow remote attackers to inject
arbitrary web script or HTML via the (1) name and (2) description
parameters.
|
| CVE-2005-4727 |
Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before
1.0.2 allows remote attackers to inject arbitrary web script or HTML
via the User-Agent HTTP header field.
|
| CVE-2005-4721 |
Cross-site scripting (XSS) vulnerability in search.cfm in tmsPUBLISHER
3.3 allows remote attackers to inject arbitrary web script or HTML via
the q parameter.
|
| CVE-2005-4707 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before
1.3 allow remote attackers to inject arbitrary web script or HTML via
unknown attack vectors.
|
| CVE-2005-4698 |
Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
91) q_IP (IP) or (2) q_Host (HOST) parameters.
|
| CVE-2005-4682 |
Cross-site scripting (XSS) vulnerability in error.asp in AudienceView
allows remote attackers to inject arbitrary web script or HTML via the
TSerrorMessage parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2005-4675 |
Cross-site scripting (XSS) vulnerability in list.php in Complete PHP
Counter allows remote attackers to inject arbitrary web script or HTML
via the c parameter.
|
| CVE-2005-4672 |
Cross-site scripting (XSS) vulnerability in image-editor-52/index.php
in CityPost Simple Image-Editor 0.52 allows remote attackers to inject
arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4)
imgsrc, and (5) m4 parameter.
|
| CVE-2005-4671 |
Cross-site scripting (XSS) vulnerability in simple-upload-53.php in
CityPost Simple PHP Upload 5.3 allows remote attackers to inject
arbitrary web script or HTML via the message parameter.
|
| CVE-2005-4670 |
Cross-site scripting (XSS) vulnerability in message.php in CityPost
Automated Link Exchange (LNKX) allows remote attackers to inject
arbitrary web script or HTML via the msg parameter.
|
| CVE-2005-4666 |
Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1
allows remote attackers to inject arbitrary Javascript via unknown
attack vectors.
|
| CVE-2005-4665 |
Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier
allows remote attackers to inject arbitrary web script or HTML via
Javascript contained in nested, malformed BBcode url tags.
|
| CVE-2005-4663 |
Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly
earlier versions, allows remote attackers to inject arbitrary web
script or HTML via unknown attack vectors.
|
| CVE-2005-4658 |
Multiple cross-site scripting (XSS) vulnerabilities in
ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject
arbitrary web script or HTML via unknown attack vectors in the
administrative interface.
|
| CVE-2005-4655 |
Cross-site scripting (XSS) vulnerability in submit.php in PHP-Fusion
6.0.204 allows remote attackers to inject arbitrary web script or HTML
via nested tags in the news_body parameter, as demonstrated by
elements such as "<me<meta>ta" and "<sc<script>ript>".
|
| CVE-2005-4649 |
Multiple cross-site scripting (XSS) vulnerabilities in Advanced
Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web
script or HTML via (1) the entry parameter in index.php and (2) the
gb_id parameter in comment.php. NOTE: The index.php/entry vector
might be resultant from CVE-2005-1548.
|
| CVE-2005-4644 |
Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in
Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web
script or HTML via javascript in the SRC attribute of an IMG tag.
|
| CVE-2005-4642 |
Multiple cross-site scripting (XSS) vulnerabilities in HydroBB 1.0.0
Beta 2 allow remote attackers to inject arbitrary web script or HTML
via the s parameter to (1) search.php, (2) members.php, (3) stats.php,
(4) viewforum.php, (5) register.php, (6) usercp.php, (7) groups.php,
(8) pms.php, and (9) calendar.php.
|
| CVE-2005-4637 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Kayako SupportSuite 3.00.26 and earlier allow remote attackers to
inject arbitrary web script or HTML via the (1) nav parameter in the
downloads module, (2) Full Name and (3) Email fields in the core
module, (4) Full Name, (5) Email, and (6) Subject fields in the
tickets module, or (7) Registered Email field in the lostpassword
feature in the core module.
|
| CVE-2005-4627 |
Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite
1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote
attackers to inject arbitrary web script or HTML via the lng
parameter.
|
| CVE-2005-4621 |
Cross-site scripting (XSS) vulnerability in the editavatar page in
vBulletin 3.5.1 allows remote attackers to inject arbitrary web script
or HTML via a URL in the remote avatar url field, in which the URL
generates a parsing error, and possibly requiring a trailing extension
such as .jpg.
|
| CVE-2005-4613 |
Cross-site scripting (XSS) vulnerability in VUBB alpha rc1 allows
remote attackers to inject arbitrary web script or HTML via
unspecified fields in the user edit profile.
|
| CVE-2005-4607 |
Cross-site scripting (XSS) vulnerability in index.php in BugPort 1.147
and earlier allows remote attackers to inject arbitrary web script or
HTML via the (1) ids[0], (2) action, (3) report_id, (4)
devWherePair[1][1], and (5) binds[0] parameters.
|
| CVE-2005-4603 |
Cross-site scripting (XSS) vulnerability in printthread.php in MyBB
1.0.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via a thread message, which is not properly sanitized
in the print view of the thread.
|
| CVE-2005-4599 |
Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in
TinyMCE Compressor PHP before 1.06 allows remote attackers to inject
arbitrary web script or HTML via the index parameter.
|
| CVE-2005-4598 |
Cross-site scripting (XSS) vulnerability in home.php in OoApp
Guestbook 2.1 allows remote attackers to inject arbitrary web script
or HTML via the page parameter.
|
| CVE-2005-4597 |
Cross-site scripting (XSS) vulnerability in index.php in iPei
Guestbook 1.7 allows remote attackers to inject arbitrary web script
or HTML via the email parameter, as used by the email field, when
signing a guestbook.
|
| CVE-2005-4596 |
Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook
2.0 allows remote attackers to inject arbitrary web script or HTML via
the totalRows_rsRead parameter.
|
| CVE-2005-4588 |
Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote
attackers to inject arbitrary web script or HTML via nested, malformed
url BBCode tags. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2005-4583 |
Unspecified vulnerability in the Management Interface in VMware ESX
Server 2.x up to 2.5.x before 24 December 2005 allows "remote code
execution in the Web browser" via unspecified attack vectors, probably
related to cross-site scripting (XSS).
|
| CVE-2005-4580 |
Cross-site scripting (XSS) vulnerability in Day Communique 4 allows
remote attackers to inject arbitrary web script or HTML via the query
parameter in a search.
|
| CVE-2005-4577 |
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi
Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on
Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote
attackers to inject arbitrary web script or HTML via unknown attack
vectors in an unspecified input form.
|
| CVE-2005-4576 |
Multiple cross-site scripting (XSS) vulnerabilities in the
UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow
remote attackers to inject arbitrary web script or HTML via the (1)
COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters.
|
| CVE-2005-4574 |
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin
CommonSpot Content Server 4.5 and earlier allows remote attackers to
inject arbitrary web script or HTML via the bNewWindow parameter.
|
| CVE-2005-4571 |
Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart
allows remote attackers to inject arbitrary web script or HTML via the
Keyword parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2005-4567 |
Multiple cross-site scripting (XSS) vulnerabilities in FTGate
Technology (formerly known as Floosietek) FTGate 4.4 (Build 4.4.000
Oct 26 2005) allow remote attackers to inject arbitrary web script or
HTML by sending (1) the href parameter to index.fts, or the param1
parameter to (2) /domains/index.fts, (3) /config/licence.fts, or (4)
/config/systemacl.fts.
|
| CVE-2005-4555 |
Cross-site scripting (XSS) vulnerability in add.php in DEV web
management system 1.5 and earlier allows remote attackers to inject
arbitrary web script or HTML via the (1) ENTER_ARTICLE_TITLE, (2)
SPECIFY_ZONE, (3) ENTER_ARTICLE_HEADER, and (4) ENTER_ARTICLE_BODY
indices in the language array parameter.
|
| CVE-2005-4551 |
Cross-site scripting (XSS) vulnerability in sign.php in codegrrl
SimpBook 1.0, when html_enable is on, allows remote attackers to
inject arbitrary web script or HTML via the message parameter to
index.php.
|
| CVE-2005-4549 |
Cross-site scripting (XSS) vulnerability in Oracle Application Server
(OracleAS) Discussion Forum Portlet allows remote attackers to inject
arbitrary web script or HTML via the (1) RowKeyValue parameter in the
PORTAL schema; and the (2) title and (3) content input fields when
creating an forum article.
|
| CVE-2005-4547 |
Cross-site scripting (XSS) vulnerability in home/search.php in eggblog
2.0 allows remote attackers to execute arbitrary SQL commands via the
q parameter, as used by the Keyword and Search fields.
|
| CVE-2005-4545 |
Cross-site scripting (XSS) vulnerability in search.asp in NetDirect
ShopEngine allows remote attackers to inject arbitrary web script or
HTML via the EXPS parameter. NOTE: the provenance of this information
is unknown; the details are obtained solely from third party
information.
|
| CVE-2005-4530 |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay
Enterprise 3.0 (formerly DoPays) allow remote attackers to inject
arbitrary web script or HTML via multiple unspecified parameters in
(1) profile.htm, (2) card.htm, (3) bank.htm, (4) subscriptions.htm,
(5) send.htm, (6) request.htm, (7) forgot.htm, (8) escrow.htm, (9)
donations.htm, and (10) products.htm.
|
| CVE-2005-4522 |
Multiple cross-site scripting (XSS) vulnerabilities in the
view_filters_page.php filters script in Mantis 1.0.0rc3 and earlier
allow remote attackers to inject arbitrary web script or HTML via the
(1) view_type and (2) target_field parameters.
|
| CVE-2005-4516 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion
6.00.200 through 6.00.300 allow remote attackers to inject arbitrary
web script or HTML via (1) the sortby parameter in members.php and (2)
IMG tags.
|
| CVE-2005-4513 |
Cross-site scripting (XSS) vulnerability in WANDSOFT e-SEARCH allows
remote attackers to inject arbitrary web script or HTML via
unspecified search parameters, possibly the keywords parameter.
|
| CVE-2005-4512 |
Cross-site scripting (XSS) vulnerability in WAXTRAPP 3.0.1 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters.
|
| CVE-2005-4507 |
Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts
Dev Hound 2.24 and earlier allow remote attackers to inject arbitrary
web script or HTML via multiple unspecified user input fields.
|
| CVE-2005-4502 |
Cross-site scripting (XSS) vulnerability in httprint v202, and
possibly other versions before v301, allows remote attackers to inject
arbitrary web script or HTML via the Server field in an HTTP response,
which is not sanitized before being displayed to the user.
|
| CVE-2005-4501 |
MediaWiki before 1.5.4 uses a hard-coded "internal placeholder
string", which allows remote attackers to bypass protection against
cross-site scripting (XSS) attacks and execute Javascript using inline
style attributes, which are processed by Internet Explorer.
|
| CVE-2005-4500 |
SQL injection vulnerability in MusicBox 2.3 allows remote attackers to
execute arbitrary SQL commands via the (1) show and (2) type
parameter. NOTE: the provenance of this information is unknown,
although it was later rediscovered.
|
| CVE-2005-4498 |
Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters.
|
| CVE-2005-4497 |
Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the action parameter in a search page, as demonstrated using (1)
page1631.aspx and (2) page496.aspx.
|
| CVE-2005-4496 |
Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1
and earlier allows remote attackers to inject arbitrary web script or
HTML via the search_query parameter.
|
| CVE-2005-4494 |
Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.
|
| CVE-2005-4493 |
Cross-site scripting (XSS) vulnerability in SpearTek 6.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters.
|
| CVE-2005-4492 |
Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18
and earlier allows remote attackers to inject arbitrary web script or
HTML via unspecified search parameters, possibly the
norelay_highlight_words parameter.
|
| CVE-2005-4491 |
Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) query string, (2) textonly, (3) locID, and (4) lang
parameters to (a) Default.aspx, and the (6) ClickFrom parameter to (b)
Request-call-back.html and (c) registration-form.html. NOTE: the
vendor states "This issue was resolved by a minor update to Sitekit
CMS v6.6, sanitising the html code and eradicating related security
issues."
|
| CVE-2005-4490 |
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and
earlier allow remote attackers to inject arbitrary web script or HTML
via the (1) keyword and (2) invalid parameter to articleSearch.asp;
(3) username and (4) invalid parameter to lostPassword.asp; (5)
Username, (6) Password, and (7) invalid parameter to
account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11)
invalid parameters to category.asp; and invalid parameters to (12)
articleZone.asp, (13) prePurchaserRegistration.asp, and (14)
requestDemo.asp.
|
| CVE-2005-4489 |
Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
(1) type and (2) count parameters, and (3) the query string in a
story.
|
| CVE-2005-4488 |
Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in
Redakto WCMS 3.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4)
cart, (5) str, (6) nf, and (7) a parameters.
|
| CVE-2005-4487 |
Cross-site scripting (XSS) vulnerability in RAMSite R|1 CMS 1.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the searchfield parameter.
|
| CVE-2005-4485 |
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3
and earlier allow remote attackers to inject arbitrary web script or
HTML via the keywords parameter to (1) forums.asp, (2)
search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid
parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and
(7) skin_number parameter to default.asp.
|
| CVE-2005-4484 |
Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) ret_page parameter to login.asp or the (2) do_search
and (3) search parameters to content.asp.
|
| CVE-2005-4483 |
Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable
3.3 and earlier allows remote attackers to inject arbitrary web script
or HTML via the ret_page parameter.
|
| CVE-2005-4482 |
Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3
and earlier allows remote attackers to inject arbitrary web script or
HTML via the ret_page parameter.
|
| CVE-2005-4481 |
** DISPUTED **
Cross-site scripting (XSS) vulnerability in Polopoly 9 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters. NOTE: the vendor has disputed this
vulnerability, stating that the "XSS flaw was only part of the custom
implementation of the [polopoly] site". As of 20061003, CVE has no
further information on this issue, except that the original researcher
has a history of testing live sites and assuming that discoveries
indicate vulnerabilities in the associated package.
|
| CVE-2005-4480 |
Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified search parameters.
|
| CVE-2005-4477 |
Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the bab[searchfor] parameter.
|
| CVE-2005-4476 |
Cross-site scripting (XSS) vulnerability in store/search/results.html
in OpenEdit 4.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the (1) oe-action and (2) page
parameters.
|
| CVE-2005-4475 |
Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters.
|
| CVE-2005-4460 |
Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the (1) Name, (2) Description, and (3) Comment fields to (a)
links.php and (b) links_add.php.
|
| CVE-2005-4454 |
Validate-before-filter vulnerability in cleanhtml.pl 1.129 in
LiveJournal CVS before Dec 7 2005, when the cleancss option is
enabled, allows remote attackers to conduct cross-site scripting (XSS)
attacks via a "\" (backslash) within a "javascript" scheme in a style
property (such as "javas\cript"), which bypasses the "javascript"
check before the "\" is stripped and then rendered in web browsers
that allow scripting in style sheets.
|
| CVE-2005-4446 |
Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x
allows remote attackers to inject arbitrary web script or HTML via the
strSearch parameter.
|
| CVE-2005-4435 |
Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man
3.x allows remote attackers to inject arbitrary web script or HTML via
the title parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2005-4434 |
Cross-site scripting (XSS) vulnerability in AbleDesign ReSearch 2.x
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors. NOTE: the provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2005-4433 |
Cross-site scripting (XSS) vulnerability in search.php in Esselbach
Storyteller CMS 1.8 allows remote attackers to inject arbitrary web
script or HTML via the query parameter, which is used by the Search
field.
|
| CVE-2005-4432 |
Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8
allows remote attackers to inject arbitrary web script or HTML via the
err parameter.
|
| CVE-2005-4428 |
Cross-site scripting (XSS) vulnerability in index.php in Cerberus
Helpdesk allows remote attackers to inject arbitrary web script or
HTML via the kb_ask parameter.
|
| CVE-2005-4420 |
Cross-site scripting (XSS) vulnerability in Honeycomb Archive
Enterprise 3.0 allows remote attackers to inject arbitrary web script
or HTML via unspecified search parameters, possibly the keyword
parameter in search.cfm.
|
| CVE-2005-4415 |
Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5
allows remote attackers to inject arbitrary web script or HTML via the
form parameter.
|
| CVE-2005-4413 |
Multiple cross-site scripting (XSS) vulnerabilities in sample scripts
in IBM WebSphere Application Server 6 allow remote attackers to inject
arbitrary web script or HTML via the (1) E-mail address field to (a)
PlantsByWebSphere/login.jsp, (2) message field to (b)
TechnologySample/BulletinBoard Script, (3) Email address field to (c)
TechnologySamples/Subscription, and the (4) Movie Name, (5) Movie
Reviewer, and (6) Movie Review fields to (d)
TechnologySamples/MovieReview2_1.
|
| CVE-2005-4410 |
Cross-site scripting (XSS) vulnerability in NQcontent 3 allows remote
attackers to inject arbitrary web script or HTML via unspecified
search parameters, possibly the text parameter.
|
| CVE-2005-4409 |
Cross-site scripting (XSS) vulnerability in MMBase 1.7.4 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters.
|
| CVE-2005-4407 |
Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS
4.0 and earlier allows remote attackers to inject arbitrary web script
or HTML via the (1) content and (2) criteria parameters.
|
| CVE-2005-4401 |
Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters, possibly the query parameter.
|
| CVE-2005-4400 |
Cross-site scripting (XSS) vulnerability in downloads/portal_ent in
Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to
inject arbitrary web script or HTML via the (1) _77_struts_action, (2)
p_p_mode, and (3) p_p_state parameters.
|
| CVE-2005-4399 |
Cross-site scripting (XSS) vulnerability in search/index.php in
Libertas Enterprise CMS 3.0 and earlier allows remote attackers to
inject arbitrary web script or HTML via the page_search parameter.
|
| CVE-2005-4398 |
** DISPUTED **
NOTE: the vendor has disputed this issue. Cross-site scripting (XSS)
vulnerability in lemoon 2.0 and earlier allows remote attackers to
inject arbitrary web script or HTML via unspecified search parameters,
possibly the q parameter. NOTE: the vendor has disputed this issue,
saying "Sites are built on top of ASP.NET and you use lemoon core
objects to easily manage and render content. The XSS vuln. you are
referring to exists in one of our public sites built on lemoon i.e. a
custom made site (as all sites are). The problem exists in a
UserControl that handles form input and is in no way related to the
lemoon core product."
|
| CVE-2005-4396 |
Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS
allows remote attackers to inject arbitrary web script or HTML via the
LoginMSG parameter. NOTE: the provenance of this issue is unknown;
the details were obtained solely from third party sources.
|
| CVE-2005-4395 |
Cross-site scripting (XSS) vulnerability in FarCry 3.0 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters, possibly the criteria parameter.
|
| CVE-2005-4394 |
Cross-site scripting (XSS) vulnerability in EPiX 3.1.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search query parameters.
|
| CVE-2005-4393 |
Cross-site scripting (XSS) vulnerability in show.cfm in e-publish CMS
2.0 and earlier allows remote attackers to inject arbitrary web script
or HTML via the (1) obcatid and (2) comid parameters.
|
| CVE-2005-4391 |
Cross-site scripting (XSS) vulnerability in damoon allows remote
attackers to inject arbitrary web script or HTML via unspecified
search parameters, possibly the q parameter.
|
| CVE-2005-4388 |
Cross-site scripting (XSS) vulnerability in search.cfm in CONTENS 3.0
and earlier allows remote attackers to inject arbitrary web script or
HTML via the near parameter.
|
| CVE-2005-4387 |
Cross-site scripting (XSS) vulnerability in home.php in contenite 0.11
and earlier allows remote attackers to inject arbitrary web script or
HTML via the id parameter.
|
| CVE-2005-4386 |
Cross-site scripting (XSS) vulnerability in Colony CMS 2.75 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified search parameters.
|
| CVE-2005-4385 |
Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0
RC3 and earlier allows remote attackers to inject arbitrary web script
or HTML via the searchstring parameter.
|
| CVE-2005-4383 |
Cross-site scripting (XSS) vulnerability in index.cfm in CitySoft
Community Enterprise 4.x allows remote attackers to inject arbitrary
web script or HTML via the (1) presentationSite, (2) docPublishYear,
(3) docDescription, (4) publishState, (5) docAuthor, (6) docTitle, (7)
subTopic, (8) topic, (9) topicRadio, (10) topicOnly, (11) startrow,
and (12) sortby parameters.
|
| CVE-2005-4381 |
Multiple cross-site scripting (XSS) vulnerabilities in Caravel CMS 3.0
Beta 1 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) fileDN and (2) folderviewer_attrs
parameters.
|
| CVE-2005-4379 |
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.1
and 1.1.1 beta allow remote attackers to inject arbitrary web script
or HTML via the (1) sort_mode parameter to (a)
fisheye/list_galleries.php, (b) messages/message_box.php, and (c)
users/my.php; the (2) post_id parameter to (d) blogs/view_post.php;
the (3) blog_id parameter to (e) blogs/view.php; and the (4) search
field to (f) users/my_groups.php.
|
| CVE-2005-4377 |
Cross-site scripting (XSS) vulnerability in Page.asp in Baseline CMS
1.95 and earlier allows remote attackers to inject arbitrary web
script or HTML via the (1) PageID and (2) SiteNodeID parameters.
|
| CVE-2005-4375 |
Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
change parameter. NOTE: it is possible that this is resultant from
CVE-2005-4376.
|
| CVE-2005-4374 |
Multiple cross-site scripting (XSS) vulnerabilities in Allinta 2.3.2
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) s parameter to faq.asp and (2) searchQuery parameter
to search.asp.
|
| CVE-2005-4372 |
Cross-site scripting (XSS) vulnerability in account.html in Adaptive
Website Framework (AWF) 2.10 and earlier allows remote attackers to
inject arbitrary web script or HTML via the page parameter.
|
| CVE-2005-4369 |
Cross-site scripting (XSS) vulnerability in Acuity CMS 2.6.2 allows
remote attackers to inject arbitrary web script or HTML via
unspecified search parameters, possibly strSearchKeywords to
browse.asp.
|
| CVE-2005-4367 |
Cross-site scripting (XSS) vulnerability in register_domain.php in
DRZES HMS 3.2 allows remote attackers to inject arbitrary web script
or HTML via unspecified search parameters, possibly the "Domain
Availability" field. NOTE: this issue was later reported to affect
CONTROLzx (renamed from DRZES) 3.3.4.
|
| CVE-2005-4365 |
Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029
allow remote attackers to inject arbitrary web script or HTML via the
(1) name parameter in text.php and (2) frame parameter in forum.php.
|
| CVE-2005-4364 |
Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana
Web Content Management Suite 5.3 allows remote attackers to inject
arbitrary web script or HTML via the keywords parameter.
|
| CVE-2005-4363 |
Cross-site scripting (XSS) vulnerability in the search engine in
Komodo CMS 2.1 allows remote attackers to inject arbitrary web script
or HTML via unspecified search parameters.
|
| CVE-2005-4361 |
Cross-site scripting (XSS) vulnerability in search.html in Magnolia
Content Management Suite 2.1 allows remote attackers to inject
arbitrary web script or HTML via the query parameter.
|
| CVE-2005-4358 |
admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to
obtain the installation path via a direct request with a non-empty
setmodules parameter, which causes an invalid append_sid function call
that leaks the path in an error message.
|
| CVE-2005-4357 |
Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when
"Allowed HTML tags" is enabled, allows remote attackers to inject
arbitrary Javascript via a permitted HTML tag with " (quote)
characters and active attributes such as onmouseover.
|
| CVE-2005-4355 |
Multiple cross-site scripting (XSS) vulnerabilities in UStore allow
remote attackers to inject arbitrary web script or HTML via the (1)
Cat parameter in default.asp and the (2) accessdenied parameter in
admin/default.asp. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2005-4354 |
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in
Webglimpse 2.14.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the query parameter.
|
| CVE-2005-4339 |
Cross-site scripting (XSS) vulnerability in Blackboard Learning and
Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and
other versions before 6 allows remote attackers to inject arbitrary
web script or HTML via the context parameter to announcement.pl, which
is reflected in the resulting page.
|
| CVE-2005-4336 |
Cross-site scripting (XSS) vulnerability in ProjectForum 4.7.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the (1) fwd parameter in admin/adminsignin.html and (2)
originalpageid parameter in admin/newpage.html associated with a
group.
|
| CVE-2005-4333 |
Multiple cross-site scripting (XSS) vulnerabilities in Binary Board
System (BBS) 0.2.5 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) inreplyto, (2) article, and
(3) board parameters to reply.pl, (4) branch, (5) board, and (6)
stats.pl parameters to (b) stats.pl, and (7) board parameter to (c)
toc.pl.
|
| CVE-2005-4328 |
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in
Webglimpse 2.14.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the ID parameter.
|
| CVE-2005-4327 |
Multiple cross-site scripting (XSS) vulnerabilities in Michael Arndt
WebCal 1.11-3.04 allow remote attackers to inject arbitrary web script
or HTML via the (1) function, (2) year, and (3) date parameters to
webcal.cgi, (4) new calendar entries, and (5) notes for entries.
|
| CVE-2005-4322 |
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi
Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax
Collaboration Portal 07-00 through 07-10-/B, and Groupmax
Collaboration Web Client 07-00 through 07-10-/A allow remote attackers
to inject arbitrary web script or HTML via the (1) Schedule and (2)
Calendar components.
|
| CVE-2005-4317 |
Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not
protect the $_SERVER variable from external modification, which allows
remote attackers to use the _SERVER[REMOTE_ADDR] parameter to (1)
conduct cross-site scripting (XSS) attacks in the stats module or (2)
execute arbitrary code via an eval injection attack in the wrapper
option in index2.php.
|
| CVE-2005-4314 |
Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal
Shopping Cart 3.3.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the (1) stop and (2) user parameters.
|
| CVE-2005-4311 |
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier,
and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary
web script or HTML via (1) the page parameter in dcboard.php and (2)
unspecified search parameters.
|
| CVE-2005-4307 |
Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user
parameter to profile.cgi.
|
| CVE-2005-4306 |
Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to
netboardr.cgi, or (5) cid parameter to search.cgi.
|
| CVE-2005-4305 |
Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1,
and 0.9.2 allows remote attackers to inject arbitrary web script or
HTML via the URL, which is not properly sanitized before it is
returned in an error page.
|
| CVE-2005-4301 |
Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the address bar field.
|
| CVE-2005-4299 |
Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02
and earlier allows remote attackers to inject arbitrary web script or
HTML via the (1) before and (2) ct parameters.
|
| CVE-2005-4298 |
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum
4.02 and earlier allows remote attackers to inject arbitrary web
script or HTML via the (1) sch_allsubct, (2) before, and (3) ct
parameters.
|
| CVE-2005-4297 |
Cross-site scripting (XSS) vulnerability in bbBoard 2.56 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unspecified search parameters, possibly via the "keys" parameter.
|
| CVE-2005-4295 |
Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE
2.x allows remote attackers to inject arbitrary web script or HTML via
the text parameter. NOTE: the provenance of this information is
unknown; the details are obtained solely from third party information.
|
| CVE-2005-4294 |
Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before
6.0.3 allows remote attackers to inject arbitrary web script or HTML
via the username in the login page.
|
| CVE-2005-4293 |
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro
(CCP) 5.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via the affl parameter.
|
| CVE-2005-4292 |
Cross-site scripting (XSS) vulnerability in CommerceSQL 1.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified search module parameters, possibly the keywords
parameter in the Quick Find feature.
|
| CVE-2005-4291 |
Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS
Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the (1) product, (2) category, and (3) uid
parameters.
|
| CVE-2005-4290 |
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03
and earlier allows remote attackers to inject arbitrary web script or
HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f
parameters.
|
| CVE-2005-4289 |
Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3
allows remote attackers to inject arbitrary web script or HTML via the
user_action parameter.
|
| CVE-2005-4288 |
Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb
E-commerce allows remote attackers to inject arbitrary web script or
HTML via the page parameter to index.php. NOTE: this might be
resultant from CVE-2005-4287.
|
| CVE-2005-4285 |
Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick
Copits PDEstore 1.8 and earlier allows remote attackers to inject
arbitrary web script or HTML via (1) the search module parameter or
the (2) product and (3) cart_id parameters.
|
| CVE-2005-4284 |
Cross-site scripting (XSS) vulnerability in StaticStore Search Engine
1.189A and earlier allows remote attackers to inject arbitrary web
script or HTML via unspecified parameters to search.cgi, possibly the
keywords parameter. NOTE: this issue was originally disputed by the
vendor, but it has since been acknowledged.
|
| CVE-2005-4283 |
Cross-site scripting (XSS) vulnerability in The CITY Shop 1.3 and
earlier allows remote attackers to inject arbitrary web script or HTML
via parameters to the search module, possibly SKey to store.cgi.
|
| CVE-2005-4282 |
Cross-site scripting (XSS) vulnerability in Zaygo DomainCart 2.0 and
earlier allows remote attackers to inject arbitrary web script or
HTML, possibly via the root parameter to zaygo.cgi.
|
| CVE-2005-4281 |
Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via certain search module parameters, possibly the root parameter to
zaygo.cgi.
|
| CVE-2005-4277 |
Cross-site scripting (XSS) vulnerability in index.php in toendaCMS
before 0.7 Beta allows remote attackers to inject arbitrary web script
or HTML via the id parameter.
|
| CVE-2005-4262 |
Cross-site scripting (XSS) vulnerability in the News module in
Envolution allows remote attackers to inject arbitrary web script or
HTML via the (1) startrow and (2) catid parameter. NOTE: this issue
might be resultant from the SQL injection problem (CVE-2005-4263).
|
| CVE-2005-4260 |
Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and
later allows remote attackers to perform cross-site scripting (XSS)
attacks by replacing the ">" in the tag with a "<", which bypasses the
regular expressions that sanitize the data, but is automatically
corrected by many web browsers. NOTE: it could be argued that this
vulnerability is due to a design limitation of many web browsers; if
so, then this should not be treated as a vulnerability in PHP-Nuke.
|
| CVE-2005-4256 |
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM
Forum RC3 allows remote attackers to inject arbitrary web script or
HTML via the forum_title parameter. NOTE: the provenance of this
issue is unknown; the details are obtained solely from the BID. In
addition, its accuracy is in question because "forum_title" does not
appear to be specified in the source code for XM Forum RC3. It is
possible, but not certain, that this is CVE-2004-2211.
|
| CVE-2005-4255 |
Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki
1.1.6.0 allows remote attackers to inject arbitrary web script or HTML
via a hex-encoded phrase parameter.
|
| CVE-2005-4253 |
Cross-site scripting (XSS) vulnerability in getdox.php in Torrential
1.2 allows remote attackers to inject arbitrary web script or HTML via
the URL. NOTE: this might be resultant from CVE-2005-4160.
|
| CVE-2005-4252 |
Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified search module parameters.
|
| CVE-2005-4248 |
Multiple cross-site scripting (XSS) vulnerabilities in QuickPayPro 3.1
allow remote attackers to inject arbitrary web script or HTML via
various fields, such as those in (1)
communication/subscribers.tracking.add.php, (2)
support/tickets.add.php, and (3) mycompany/categories.php.
|
| CVE-2005-4247 |
Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta
2 and earlier allows remote attackers to inject arbitrary web script
or HTML via the searchterms parameter.
|
| CVE-2005-4245 |
Cross-site scripting (XSS) vulnerability in search.php in Snipe
Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary
web script or HTML via the keyword parameter.
|
| CVE-2005-4242 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3
2.0.4 and earlier allow remote attackers to inject arbitrary web
script or HTML via (1) the address book and (2) contact data.
|
| CVE-2005-4241 |
Cross-site scripting (XSS) vulnerability in the category page in
VCD-db 0.98 and earlier allows remote attackers to inject arbitrary
web script or HTML via the batch parameter.
|
| CVE-2005-4239 |
Cross-site scripting (XSS) vulnerability in Search/DisplayResults.php
in PHP JackKnife 2.21 and earlier allows remote attackers to inject
arbitrary web script or HTML via URL-encoded values in the sKeywords
parameter.
|
| CVE-2005-4238 |
Cross-site scripting (XSS) vulnerability in view_filters_page.php in
Mantis 1.0.0rc3 and earlier allows remote attackers to inject
arbitrary web script or HTML via the target_field parameter.
|
| CVE-2005-4237 |
Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via unspecified search module parameters, possibly the keyword
parameter in the SearchZoom module.
|
| CVE-2005-4236 |
Cross-site scripting (XSS) vulnerability in search.php in CKGOLD
allows remote attackers to inject arbitrary web script or HTML via the
search parameters.
|
| CVE-2005-4235 |
Cross-site scripting (XSS) vulnerability in knowledgebase.php in
WHMCompleteSolution 2.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the search parameters.
|
| CVE-2005-4231 |
Cross-site scripting (XSS) vulnerability in Link Up Gold 2.5 and
earlier allows remote attackers to inject arbitrary web script or HTML
via (1) link parameter to tell_friend.php, (2) phrase[] parameter to
search.php in a search_links_advanced action, and the (3) direction or
(4) sort parameter to articles.php.
|
| CVE-2005-4229 |
Cross-site scripting (XSS) vulnerability in auction.pl in EveryAuction
1.53 and earlier allows remote attackers to inject arbitrary web
script or HTML via the searchstring parameter. NOTE: the provenance
of this issue is unknown; the details were obtained solely from third
party sources and independently verified using source code inspection.
|
| CVE-2005-4222 |
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi
in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers
to inject arbitrary web script or HTML via unspecified message fields.
|
| CVE-2005-4209 |
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to
prevent arbitrary users from accessing their inboxes via script tags
in the Subject header of an e-mail message, which prevents the user
from being able to access the Inbox folder, possibly due to a
cross-site scripting (XSS) vulnerability.
|
| CVE-2005-4205 |
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList
1.03c and earlier allows remote attackers to inject arbitrary web
script or HTML via the q parameter.
|
| CVE-2005-4204 |
Cross-site scripting (XSS) vulnerability in LogiSphere 0.9.9j allows
remote attackers to inject arbitrary Javascript via the msg command.
NOTE: due to lack of appropriate details by the original researcher,
it is unclear whether this issue is distinct from the msg DoS.
|
| CVE-2005-4203 |
LogiSphere 0.9.9j does not restrict the number of messages that can be
sent, which allows remote attackers to cause a denial of service by
sending a large number of messages via the msg command. NOTE: due to
lack of appropriate details by the original researcher, it is unclear
whether this description accurately reflects the discloser's claim and
is distinct from the XSS issue.
|
| CVE-2005-4196 |
Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal
Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject
arbitrary web script or HTML via (1) the ss parameter in
SPT--QuickSearch.php; (2) ParentId parameter in
SPT--BrowseResources.php; (3) the ResourceId parameter in
SPT--FullRecord.php; (4) ResourceOffset parameter in SPT--Home.php,
(5) F_SearchString parameter in SPT--QuickSearch.php; (6) F_UserName
and (7) F_Password parameters in SPT--UserLogin.php; (8) F_SearchCat1,
(9) F_TextField1, (10) F_SearchCat2, (11) F_TextField2, (12)
F_SearchCat3, (13) F_TextField3, (14) F_SearchCat4, (15) F_TextField4,
(16) ResourceType, (17) Language, (18) Audience, (19) Format
parameters in SPT--AdvancedSearch.php.
|
| CVE-2005-4193 |
Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows
remote attackers to inject arbitrary web script or HTML via the
$_SERVER['PHP_SELF'] variable.
|
| CVE-2005-4192 |
Multiple cross-site scripting (XSS) vulnerabilities in
templates/notepads/notepads.inc in Horde Mnemo Note Manager H3 before
2.0.3 allow remote authenticated users to inject arbitrary web script
or HTML via (1) the notepad's name or (2) description, when creating a
new notepad.
|
| CVE-2005-4191 |
Multiple cross-site scripting (XSS) vulnerabilities in
templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3
before 2.0.4 allow remote authenticated users to inject arbitrary web
script or HTML via (1) the tasklist's name or (2) description, when
creating a new tasklist.
|
| CVE-2005-4190 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde
Application Framework before 3.0.8 allow remote authenticated users to
inject arbitrary web script or HTML via multiple vectors, as
demonstrated by (1) the identity field, (2) Category and (3) Label
search fields, (4) the Mobile Phone field, and (5) Date and (6) Time
fields when importing CSV files, as exploited through modules such as
(a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.
|
| CVE-2005-4189 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith
H3 before 2.0.6 allow remote authenticated users to inject arbitrary
web script or HTML via (1) the Calendar name field when creating
calendars, (2) event title field when deleting events, the (3)
Category and (4) Location search fields, and the (5) attendees email
address fields when editing event attendees, and possibly other
vectors.
|
| CVE-2005-4177 |
Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book
Personal and Professional 2.0 allows remote attackers to inject
arbitrary web script or HTML via the StartRow parameter.
|
| CVE-2005-4167 |
Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1
allows remote attackers to inject arbitrary web script or HTML via the
let parameter in a viewlist action to titles.php.
|
| CVE-2005-4166 |
Cross-site scripting (XSS) vulnerability in password.asp in DUWare
DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web
script or HTML via the result parameter.
|
| CVE-2005-4162 |
Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME
PerlCal 2.99.20 allows remote attackers to inject arbitrary web script
or HTML via the p0 parameter.
|
| CVE-2005-4161 |
** DISPUTED **
Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts
1.4 redirect script allow remote attackers to inject arbitrary web
script or HTML via the domainname parameter to register.php, and other
unspecified vectors. NOTE: the vendor has disputed this issue,
stating "No invalid input can reach the script."
|
| CVE-2005-4150 |
Cross-site scripting (XSS) vulnerability in the portal login page in
Computer Associates CleverPath 4.7 allows remote attackers to execute
Javascript via unknown vectors.
|
| CVE-2005-4138 |
Multiple cross-site scripting (XSS) vulnerabilities in ThWboard before
3 Beta 2.84 allow remote attackers to inject arbitrary web script or
HTML via the (1) Wohnort and (2) Beruf fields in editprofile.php, (3)
user parameter array in v_profile.php, and (4) the action parameter in
misc.php.
|
| CVE-2005-4137 |
SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows
remote attackers to execute arbitrary SQL commands via the invoiceID
parameter.
|
| CVE-2005-4136 |
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2
allows remote attackers to inject arbitrary web script or HTML via the
customerEmailAddress parameter.
|
| CVE-2005-4091 |
Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script
1-Search 1.8 allows remote attackers to inject arbitrary web script or
HTML via the q parameter.
|
| CVE-2005-4080 |
Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16
null characters, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via UTF16 encoded attachments and strings that
will be executed when viewed using Internet Explorer, which ignores
the characters.
|
| CVE-2005-4078 |
Multiple cross-site scripting (XSS) vulnerabilities in Ideal BB.NET
1.3 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) forumID, (2) boardID, and (3) topicRepeater1-p
parameters in topics.aspx, (4) boardID parameter in
categoryindex.aspx, (5) postID parameter in posts.aspx, (6) catID
parameter in forums.aspx, and (7) memberID parameter in member.aspx.
|
| CVE-2005-4075 |
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in
CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) topic and (2) newsid parameter in the news
sector, and (3) cat parameter in the links sector.
|
| CVE-2005-4072 |
Cross-site scripting (XSS) vulnerability in CFMagic Magic Forum
Personal 2.5 and earlier allows remote attackers to inject arbitrary
web script or HTML via the Words parameter in search_forums.cfm, as
used in the "Search For:" field.
|
| CVE-2005-4063 |
Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp
3.0 and earlier allow remote attackers to inject arbitrary HTML and
web script via the (1) L, (2) sort, (3) category, (4) categoryname
parameters to search.asp.
|
| CVE-2005-4062 |
Cross-site scripting (XSS) vulnerability in CPSearch.asp in
XcClassified 3.x allows remote attackers to inject arbitrary web
script or HTML via the search parameters.
|
| CVE-2005-4061 |
Cross-site scripting (XSS) vulnerability in PASearch.asp in
XcPhotoAlbum 1.x allows remote attackers to inject arbitrary web
script or HTML via the search parameters.
|
| CVE-2005-4060 |
Cross-site scripting (XSS) vulnerability in search.asp in rwAuction
Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script
or HTML via the searchtxt parameter.
|
| CVE-2005-4057 |
Cross-site scripting (XSS) vulnerability in search.php in PluggedOut
Nexus 0.1 allows remote attackers to inject arbitrary web script or
HTML via the (1) Location, (2) Last Name, and (3) First Name
parameters.
|
| CVE-2005-4053 |
Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote
attackers to inject arbitrary web script or HTML via the q parameter,
as demonstrated using 26.html.
|
| CVE-2005-4047 |
Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks
ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web
script or HTML via the a parameter.
|
| CVE-2005-4044 |
Cross-site scripting (XSS) vulnerability in search.cgi in Amazon
Search Directory 1.0.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, possibly the
search parameter.
|
| CVE-2005-4042 |
Cross-site scripting (XSS) vulnerability in Warm Links 1.0.0 and
earlier allows remote attackers to inject arbitrary web script or HTML
via a parameter to search.cgi.
|
| CVE-2005-4041 |
Cross-site scripting (XSS) vulnerability in search.cgi in MR CGI Guy
Hot Links SQL 3.1.x and Hot Links Pro 3.1.x allows remote attackers to
inject arbitrary web script or HTML via the query string.
|
| CVE-2005-4036 |
Cross-site scripting (XSS) vulnerability in index.cgi in Web4Future
KeyWord Frequency Counter 1.0 allows remote attackers to inject
arbitrary web script or HTML via the "remote URL."
|
| CVE-2005-4032 |
Cross-site scripting (XSS) vulnerability in search.cgi in Easy Search
System 1.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via the q parameter.
|
| CVE-2005-4028 |
Multiple cross-site scripting (XSS) vulnerabilities in aMember allow
remote attackers to inject arbitrary web script or HTML via the (1)
lamember_login parameter to sendpass.php and (2) login parameter to
member.php.
|
| CVE-2005-4024 |
Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004
and 2005 allows remote attackers to inject arbitrary web script or
HTML via the query parameter.
|
| CVE-2005-4022 |
Cross-site scripting (XSS) vulnerability in the "Add Image From Web"
feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject
arbitrary web script or HTML via Javascript in an IMG tag.
|
| CVE-2005-4012 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP Web
Statistik 1.4 allows remote attackers to inject arbitrary web script
or HTML via (1) the lastnumber parameter to stat.php and (2) the HTTP
referer to pixel.php.
|
| CVE-2005-4004 |
Cross-site scripting (XSS) vulnerability in search.asp in
MyTemplateSite 1.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the q parameter.
|
| CVE-2005-4003 |
Multiple SQL injection vulnerabilities in Absolute Shopping Package
Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite
2.1 and earlier, allow remote attackers to execute arbitrary SQL
commands via the (1) srch_product_name parameter to adv_search.asp and
(2) b_search parameter to bsearch.asp. NOTE: the original disclosure
was specifically only for an XSS issue, but the CVE description was
for SQL injection. Since the original disclosure, SQL injection
vectors have been reported. This CVE might be REJECTed or
significantly altered pending additional information.
|
| CVE-2005-4000 |
Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater
News System 4.00 and earlier allows remote attackers to inject
arbitrary web script or HTML via the sKeywords parameter.
|
| CVE-2005-3999 |
Cross-site scripting (XSS) vulnerability in Search.asp in SiteBeater
MP3 Catalog 2.03 and earlier allows remote attackers to inject
arbitrary web script or HTML via unspecified parameters.
|
| CVE-2005-3998 |
Cross-site scripting (XSS) vulnerability in search.asp in Solupress
News 1.0 and earlier allows remote attackers to inject arbitrary web
script or HTML via the keywords parameter.
|
| CVE-2005-3991 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat
0.14.6 allow remote attackers to inject arbitrary web script or HTML
via the medium parameter to (1) start_page.css.php and (2)
style.css.php; or the From parameter to users_popupL.php.
|
| CVE-2005-3977 |
Cross-site scripting (XSS) vulnerability in QualityEBiz Quality PPC
1553 allows remote attackers to inject web script or HTML via the REQ
parameter to the search module.
|
| CVE-2005-3975 |
Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and
4.6.0 through 4.6.3 allows remote authenticated users to inject
arbitrary web script or HTML via HTML in a file with a GIF or JPEG
file extension, which causes the HTML to be executed by a victim who
views the file in Internet Explorer as a result of CVE-2005-3312.
NOTE: it could be argued that this vulnerability is due to a design
flaw in Internet Explorer and the proper fix should be in that
browser; if so, then this should not be treated as a vulnerability in
Drupal.
|
| CVE-2005-3973 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0
through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject
arbitrary web script or HTML via various HTML tags and values, such as
the (1) legend tag and the value parameter used in (2) label and (3)
input tags, possibly due to an incomplete blacklist.
|
| CVE-2005-3972 |
Cross-site scripting (XSS) vulnerability in extremesearch.php in
Extreme Search Corporate Edition 6.0 and earlier allows remote
attackers to inject arbitrary web script or HTML via the search
parameter.
|
| CVE-2005-3971 |
Cross-site scripting (XSS) vulnerability in the login form in Citrix
MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0
allows remote attackers to inject arbitrary web script or HTML via the
username field.
|
| CVE-2005-3970 |
Cross-site scripting (XSS) vulnerability in MXChange before
0.2.0-pre10 PL492 allows remote attackers to inject arbitrary web
script or HTML via unknown vectors.
|
| CVE-2005-3967 |
Cross-site scripting (XSS) vulnerability in the dosearchsite.action
module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers
to inject arbitrary web script or HTML via the searchQuery.queryString
search module parameter.
|
| CVE-2005-3966 |
Cross-site scripting (XSS) vulnerability in search.jsp in Java Search
Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web
script or HTML via the q parameter.
|
| CVE-2005-3959 |
Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0
rev37 allow remote attackers to inject arbitrary web script or HTML
via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to
pixel.php, which are not sanitized before being included in the
logdb.html file, and (5) the search key to stat.php.
|
| CVE-2005-3955 |
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1,
as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other
products, allow remote attackers to inject arbitrary web script or
HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url
parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
|
| CVE-2005-3954 |
Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows
remote attackers to inject arbitrary web script or HTML via the u
parameter to index.php.
|
| CVE-2005-3921 |
Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for
IOS 12.0(2a) allows remote attackers to inject arbitrary web script or
HTML by (1) packets containing HTML that an administrator views via an
HTTP interface to the contents of memory buffers, as demonstrated by
the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the
router Cisco Discovery Protocol (CDP) packets with HTML payload that
an administrator views via the CDP status pages. NOTE: these vectors
were originally reported as being associated with the dump and packet
options in /level/15/exec/-/show/buffers.
|
| CVE-2005-3919 |
Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote
attackers to inject arbitrary web script or HTML via multiple fields
in (1) UCP.php and (2) SendPm.php.
|
| CVE-2005-3908 |
Cross-site scripting (XSS) vulnerability in search.php in
GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2,
allows remote attackers to inject web script or HTML via the query
parameter.
|
| CVE-2005-3902 |
Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in
Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows
remote attackers to inject arbitrary web script or HTML via query
strings that are included in an error message, as demonstrated using a
parameter containing script.
|
| CVE-2005-3895 |
Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0
through 2.0.3, when AttachmentDownloadType is set to inline, renders
text/html e-mail attachments as HTML in the browser when the queue
moderator attempts to download the attachment, which allows remote
attackers to execute arbitrary web script or HTML. NOTE: this
particular issue is referred to as XSS by some sources.
|
| CVE-2005-3894 |
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in
Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0
through 2.0.3 allow remote authenticated users to inject arbitrary web
script or HTML via (1) hex-encoded values in the QueueID parameter and
(2) Action parameters.
|
| CVE-2005-3869 |
Cross-site scripting (XSS) vulnerability in index.php in Google API
Search 1.3.1 and earlier allows remote attackers to inject arbitrary
web script or HTML via hex-encoded values in the REQ parameter.
|
| CVE-2005-3867 |
Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine
Script 1.2.0 and earlier allows remote attackers to inject arbitrary
web script or HTML via the REQ parameter, which is used when
performing a search.
|
| CVE-2005-3866 |
Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine
1.3.2 and earlier allows remote attackers to inject arbitrary HTML and
web script, possibly via the REQ parameter, which is used when
performing a search.
|
| CVE-2005-3854 |
Cross-site scripting (XSS) vulnerability in index.php in EasyPageCMS
allows remote attackers to inject arbitrary web script or HTML via the
cat parameter.
|
| CVE-2005-3851 |
Cross-site scripting (XSS) vulnerability in search.asp in Online
Attendance System (OASYS) Lite 1.0 allows remote attackers to inject
arbitrary web script or HTML via certain search parameters, possibly
the keyword parameter.
|
| CVE-2005-3850 |
Cross-site scripting (XSS) vulnerability in search.asp in Online
Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote
attackers to inject arbitrary web script or HTML via hex-encoded
values in the q parameter.
|
| CVE-2005-3849 |
Cross-site scripting (XSS) vulnerability in the Search module in
PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web
script or HTML via the q parameter.
|
| CVE-2005-3841 |
Cross-site scripting (XSS) vulnerability in kPlaylist 1.6 (build 400),
and possibly other versions, allows remote attackers to inject
arbitrary web script or HTML via the searchfor search parameter.
|
| CVE-2005-3839 |
Cross-site scripting (XSS) vulnerability in SupportPRO Supportdesk
allows remote attackers to inject arbitrary web script or HTML via the
(1) post tickers and (2) view tickets options.
|
| CVE-2005-3837 |
Cross-site scripting (XSS) vulnerability in the search module in
sCssBoard 1.2 and 1.12, and earlier versions, allows remote attackers
to inject arbitrary web script or HTML via the search_term parameter.
|
| CVE-2005-3834 |
Cross-site scripting (XSS) vulnerability in search.php in Tunez 1.21
and earlier allows remote attackers to inject arbitrary web script or
HTML via the searchFor parameter.
|
| CVE-2005-3821 |
Cross-site scripting (XSS) vulnerability in vTiger CRM 4.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via
multiple vectors, including the account name.
|
| CVE-2005-3818 |
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) various input fields, including the contact, lead, and
first or last name fields, (2) the record parameter in a DetailView
action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF']
variable, which is used in multiple locations such as index.php, and
(4) aggregated RSS feeds in the RSS aggregation module.
|
| CVE-2005-3814 |
Multiple cross-site scripting (XSS) vulnerabilities in SmartPPC Pro
allow remote attackers to inject arbitrary web script or HTML via the
username parameter in (1) directory.php, (2) frames.php, and (3)
search.php.
|
| CVE-2005-3796 |
Direct static code injection vulnerability in admin_options_manage.php
in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute
arbitrary PHP code via the number parameter. NOTE: it is not clear
from the original report whether administrator privileges are
required. If not, then this does not cross privilege boundaries and
is not a vulnerability.
|
| CVE-2005-3795 |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft
Affiliate Network Pro 7.2 allow remote attackers to inject arbitrary
web script or HTML via (1) the Err parameter in admin/index.php and
the (2) firstname and (3) lastname parameters in index.php.
|
| CVE-2005-3794 |
AlstraSoft Affiliate Network Pro 7.2 allows remote attackers to obtain
sensitive information via a direct request to scripts such as (1)
togateway.php and (2) other unspecified scripts.
|
| CVE-2005-3793 |
Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network
Pro 7.2 allow remote attackers to bypass authentication and execute
arbitrary SQL commands via the (1) username or (2) password to
admin/admin_validate_login, or the (3) login, (4) password, and (5)
flag parameters to login_validate.php.
|
| CVE-2005-3790 |
Multiple cross-site scripting (XSS) vulnerabilities in
act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject
arbitrary web script or HTML via the (1) i and (2) text parameters.
|
| CVE-2005-3787 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
before 2.6.4-pl4 allow remote attackers to inject arbitrary web script
or HTML via (1) the cookie-based login panel, (2) the title parameter
and (3) the table creation dialog.
|
| CVE-2005-3776 |
Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard
(MyBB) 1.0 PR2 Rev 686 allow remote attackers to inject arbitrary web
script or HTML via (1) the subject field when creating a new thread
and (2) information passed to the Reputation system.
|
| CVE-2005-3771 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.0.4 allow remote attackers to inject arbitrary web script or HTML
via (1) "GET and other variables" and (2) "SEF".
|
| CVE-2005-3770 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp)
1.0 allow remote attackers to inject arbitrary web script or HTML via
(1) the subject in a post, or the user parameter to (2) profile.php
and (3) mail.php.
|
| CVE-2005-3761 |
Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and
later versions allows remote attackers to inject arbitrary web script
or HTML via (1) Javascript in forms produced by the form generator or
(2) the parameters to the installer.
|
| CVE-2005-3759 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde before
3.0.7 allow remote attackers to inject arbitrary web script or HTML
via the (1) gzip/tar and (2) css MIME viewers, which do not filter or
escape dangerous HTML when extracting and displaying attachments.
|
| CVE-2005-3758 |
Cross-site scripting (XSS) vulnerability in Google Mini Search
Appliance, and possibly Google Search Appliance, allows remote
attackers to inject arbitrary Javascript, and possibly other web
script or HTML, via a proxystylesheet variable that contains a
malicious XSLT style sheet.
|
| CVE-2005-3754 |
Cross-site scripting (XSS) vulnerability in Google Mini Search
Appliance, and possibly Google Search Appliance, allows remote
attackers to inject arbitrary Javascript, and possibly other web
script or HTML, via the proxystylesheet variable, which will be
executed in the resulting error message.
|
| CVE-2005-3751 |
HTTP request smuggling vulnerability in Pound before 1.9.4 allows
remote attackers to poison web caches, bypass web application firewall
protection, and conduct XSS attacks via an HTTP request with
conflicting Content-length and Transfer-encoding headers.
|
| CVE-2005-3745 |
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and
possibly other versions allows remote attackers to inject arbitrary
web script or HTML via the query string, which is not properly quoted
or filtered when the request handler generates an error message.
|
| CVE-2005-3742 |
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll
2.0.3 and earlier allows remote attackers to inject arbitrary web
script or HTML via the poll_ident parameter.
|
| CVE-2005-3736 |
Multiple cross-site scripting (XSS) vulnerabilities in e-Quick Cart
allow remote attackers to inject arbitrary web script or HTML via the
(1) strgifttoname parameter in shopgift.asp, (2) strfirstname
parameter in shopmaillist.asp, (3) strpid parameter in
shopprojectlogin.asp, and (4) Custname parameter in
shoptellafriend.asp.
|
| CVE-2005-3734 |
Cross-site scripting (XSS) vulnerability in the "add content" page in
phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary
web script or HTML via the (1) thema, (2) username, and (3) usermail
parameters.
|
| CVE-2005-3730 |
Multiple cross-site scripting (XSS) vulnerabilities in
HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow
remote attackers to inject arbitrary web script or HTML via the (1)
resourcetype, (2) objectmap, and (3) redirect parameters, possibly
involving setWebSpace.jsp.
|
| CVE-2005-3695 |
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php
in LiteSpeed Web Server 2.1.5 allows remote attackers to inject
arbitrary web script or HTML via the m parameter.
|
| CVE-2005-3692 |
Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server
4.2 (build 0824) and earlier allows remote attackers to inject
arbitrary web script or HTML via the (1) retid parameter in
badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML
mail attachments.
|
| CVE-2005-3688 |
Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3
and earlier allows remote attackers to inject arbitrary web script or
HTML via the "Your Current Mood" field in the registration page.
|
| CVE-2005-3685 |
Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP
Shopping Cart 5.50 allows remote attackers to inject arbitrary web
script or HTML via the UserName parameter.
|
| CVE-2005-3665 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
before 2.7.0 allow remote attackers to inject arbitrary web script or
HTML via the (1) HTTP_HOST variable and (2) various scripts in the
libraries directory that handle header generation.
|
| CVE-2005-3638 |
Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow
remote attackers to inject arbitrary web script or HTML via the (1) id
parameter in profile.php and (2) titles of posts.
|
| CVE-2005-3636 |
Cross-site scripting (XSS) vulnerability in SAP Web Application Server
(WAS) 6.10 allows remote attackers to inject arbitrary web script or
HTML via Error Pages.
|
| CVE-2005-3635 |
Multiple cross-site scripting (XSS) vulnerabilities in SAP Web
Application Server (WAS) 6.10 through 7.00 allow remote attackers to
inject arbitrary web script or HTML via (1) the sap-syscmd in
sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test
application.
|
| CVE-2005-3619 |
Cross-site scripting (XSS) vulnerability in the management interface
for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2
upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote
attackers to inject arbitrary web script or HTML via messages that are
not sanitized when viewing syslog log files.
|
| CVE-2005-3585 |
SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows
remote attackers to execute arbitrary SQL commands via the forum
parameter.
|
| CVE-2005-3584 |
Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings
1.4.4 allows remote attackers to inject arbitrary web script or HTML
via the forum parameter.
|
| CVE-2005-3577 |
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in
Walla TeleSite 3.0 and earlier allows remote attackers to inject
arbitrary web script or HTML via the sug parameter.
|
| CVE-2005-3570 |
Unspecified cross-site scripting (XSS) vulnerability in Horde before
2.2.9 allows remote attackers to inject arbitrary web script or HTML
via "not properly escaped error messages".
|
| CVE-2005-3556 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) listname parameter in (a) admin/editlist.php, (2)
title parameter in (b) admin/spageedit.php, (3) title field in (c)
admin/template.php, (4) filter, (5) delete, and (6) start parameters
in (d) admin/eventlog.php, (7) id parameter in (e)
admin/configure.php, (8) find parameter in (f) admin/users.php, (9)
start parameter in (g) admin/admin.php, and (10) action parameter in
(h) admin/fckphplist.php.
|
| CVE-2005-3552 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2
and earlier allow remote attackers to inject arbitrary web script or
HTML via multiple vectors in (1) login/profile.php, (2)
login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5)
referer statistics, the (6) HTML title element and (7) logo alt
attributes in forum postings, and the (8) Homepage field in the
Guestbook.
|
| CVE-2005-3547 |
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1
allows remote attackers to inject arbitrary web script or HTML via the
(1) adsess, (2) name, and (3) description parameters in admin.php, and
the (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address,
(8) Components, and multiple other input fields.
|
| CVE-2005-3544 |
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3
allows remote attackers to inject arbitrary web script or HTML via the
username parameter.
|
| CVE-2005-3530 |
Cross-site scripting (XSS) vulnerability in Antville 1.1 allows remote
attackers to inject arbitrary web script or HTML via the notfound.skin
error document.
|
| CVE-2005-3528 |
Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php
in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject
arbitrary web script or HTML via the topics_offset parameter.
|
| CVE-2005-3522 |
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine
Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web
script or HTML via the grDisp parameter.
|
| CVE-2005-3520 |
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0
allow remote attackers to inject arbitrary web script or HTML via (1)
the target_url parameter in upgrade_in_progress_backend.php, (2) the
stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the
bgcolor parameter in (3) insert_table.php, (4)
edit_table_cell_props.php, (5) header.php, (6)
edit_table_row_props.php, and (7) edit_table_props.php.
|
| CVE-2005-3517 |
Chipmunk Scripts Guestbook allows remote attackers to obtain the
installation path of the script via a URL that causes an error message
to be displayed, such as a URL that contains a single quote (') in the
start parameter of index.php.
|
| CVE-2005-3516 |
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk
Directory script allows remote attackers to inject arbitrary web
script or HTML via the entryID parameter.
|
| CVE-2005-3515 |
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk
Topsites script allows remote attackers to inject arbitrary web script
or HTML via the ID parameter.
|
| CVE-2005-3514 |
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum
script allow remote attackers to inject arbitrary web script or HTML
via the forumID parameter to (1) newtopic.php, (2) quote.php, (3)
index.php, and (4) reply.php.
|
| CVE-2005-3513 |
index.php in VUBB alpha rc1 allows remote attackers to obtain the
installation path of the application via a viewforum action with the f
parameter set to a single quote (').
|
| CVE-2005-3512 |
Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha
rc1 allows remote attackers to inject arbitrary web script or HTML via
the t parameter in a newreply action.
|
| CVE-2005-3511 |
Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS
4.0 allow remote attackers to inject arbitrary web script or HTML via
(a) the blogs module, including the (1) curr parameter in index.php,
(2) inspire, (3) system, or (4) title parameter in blog_newentry.php,
(5) entry parameter in blog_newentry_comment.php, (6) entry parameter
in blog_edit_entry.php, or (7) caldate parameter in blog.php; and (b)
the notes module, including the (1) forwardid parameter in a noteform
action; (2) del_folder parameter in a delete_folder action; (3)
isread, (4) dateorder, (5) subjectorder, (6) curr, (7) fromorder, or
(8) action parameters; (9) ppp or (10) totalreplies parameter in an
Inbox action; (11) totalnotes parameter; or (12) touserid parameter in
a noteform action.
|
| CVE-2005-3506 |
Cross-site scripting (XSS) vulnerability in proxy.asp in Sambar Server
6.3 BETA 2 and possibly earlier versions allows remote attackers to
inject arbitrary web script or HTML via the (1) Remote Proxy Server or
(2) Proxy Filter IPs field.
|
| CVE-2005-3505 |
Cross-site scripting (XSS) vulnerability in the Entropy Chat script in
cPanel 10.2.0-R82 and 10.6.0-R137 allows remote attackers to inject
arbitrary web script or HTML via a chat message containing Javascript
in style attributes in tags such as <b>, which are processed by
Internet Explorer.
|
| CVE-2005-3496 |
Cross-site scripting (XSS) vulnerability in PHP Handicapper allows
remote attackers to inject arbitrary web script or HTML via the msg
parameter to msg.php. NOTE: some sources identify a second vector in
the login parameter to process_signup.php, but the original source
says that it is for CRLF injection (CVE-2005-4712). Also note: the
vendor has disputed CVE-2005-3497, and it is possible that the dispute
was intended to include this issue as well. If so, followup
investigation strongly suggests that the original report is correct.
|
| CVE-2005-3494 |
Cross-site scripting (XSS) vulnerability in Ar-blog 5.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
blog comment.
|
| CVE-2005-3479 |
Cross-site scripting (XSS) vulnerability in login.asp in Ringtail
CaseBook 6.1.0 allows remote attackers to inject arbitrary web script
or HTML via the users parameter.
|
| CVE-2005-3477 |
Multiple interpretation error in the image upload handling code in
Invision Gallery 2.0.3 allows remote attackers to conduct cross-site
scripting (XSS) attacks via HTML or script in an image whose type does
not match its extension, which is rendered by Internet Explorer due to
CVE-2005-3312. NOTE: it could be argued that this vulnerability is
due to a design flaw in Internet Explorer and the proper fix should be
in that browser; if so, then this should not be treated as a
vulnerability in Invision Gallery.
|
| CVE-2005-3473 |
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog
0.4.5 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text
parameters (involving the temp_subject variable) in (a)
preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name
parameter and (5) bg_color parameters (involving the preset_name and
result variables) in (c) colors.php.
|
| CVE-2005-3436 |
Cross-site scripting (XSS) vulnerability in Nuked-Klan 1.7 allows
remote attackers to inject arbitrary web script or HTML via the (1)
Search module, (2) certain edit fields in Guestbook, (3) the title in
the Forum module, and (4) Textbox.
|
| CVE-2005-3429 |
Rockliffe MailSite Express before 6.1.22, with the option to save
login information enabled, saves user passwords in plaintext in
cookies, which allows local users to obtain passwords by reading the
cookie file, or remote attackers to obtain the cookies via cross-site
scripting (XSS) vulnerabilities.
|
| CVE-2005-3428 |
Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express
before 6.1.22 allows remote attackers to inject arbitrary web script
or HTML via a message body.
|
| CVE-2005-3425 |
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors, a different vulnerability than CVE-2005-3424.
|
| CVE-2005-3424 |
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5
allows remote attackers to inject arbitrary web script or HTML via 404
error pages, a different vulnerability than CVE-2005-3425.
|
| CVE-2005-3422 |
Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast
Forum allows remote attackers to inject arbitrary web script or HTML
via the error parameter.
|
| CVE-2005-3418 |
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.17
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) error_msg parameter to usercp_register.php, (2)
forward_page parameter to login.php, and (3) list_cat parameter to
search.php, which are not initialized as variables.
|
| CVE-2005-3413 |
Cross-site scripting (XSS) vulnerability in desktop.php in eyeOS 0.8.4
allows remote attackers to inject arbitrary web script or HTML via the
motd parameter.
|
| CVE-2005-3412 |
Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows
remote attackers to inject arbitrary web script or HTML via a Post
Reply to a topic, in which the reply contains a javascript: URL in an
<img> tag.
|
| CVE-2005-3411 |
Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums
2000 3.4.05 allows remote attackers to inject arbitrary web script or
HTML via the type parameter in a Topic method.
|
| CVE-2005-3406 |
Cross-site scripting (XSS) vulnerability in phpESP 1.7.5 and earlier
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2005-3403 |
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1
through 1.5.1-pl1 allow remote attackers to inject arbitrary web
script or HTML via (1) the _base_href parameter in translate.php, (2)
the _base_path parameter in news.inc.php, and (3) the p parameter in
add_note.php.
|
| CVE-2005-3397 |
Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows
remote attackers to inject arbitrary web script or HTML via the error
parameter to comersus_backoffice_supportError.asp. NOTE: the
comersus_backoffice_message.asp/message vector is already covered by
CVE-2005-2191 item 2.
|
| CVE-2005-3388 |
Cross-site scripting (XSS) vulnerability in the phpinfo function in
PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL with a "stacked
array assignment."
|
| CVE-2005-3368 |
Cross-site scripting (XSS) vulnerability in the Search_Enhanced module
in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script
or HTML via the query parameter.
|
| CVE-2005-3367 |
Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog
2.1 allows remote attackers to inject arbitrary web script or HTML via
the name field.
|
| CVE-2005-3366 |
PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2
through 2.0.1 allows remote attackers to execute arbitrary PHP code
and include arbitrary local files via the phpicalendar cookie. NOTE:
this is not a cross-site scripting (XSS) issue as claimed by the
original researcher.
|
| CVE-2005-3365 |
Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier
allow remote attackers to execute arbitrary SQL commands, possibly
requiring encoded characters, via (1) the name parameter in
register.php, (2) the email parameter in lostpassword.php, (3) the
year parameter in calendar.php, and the (4) cid parameter to
index.php. NOTE: the mid parameter for forums.php is already
associated with CVE-2005-0454. NOTE: the index.php/cid vector was
later reported to affect 6.11.
|
| CVE-2005-3361 |
Cross-site scripting (XSS) vulnerability in forum/index.php in
FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script
or HTML via the nome parameter in a login operation, a variant of
CVE-2005-3306.
|
| CVE-2005-3352 |
Cross-site scripting (XSS) vulnerability in the mod_imap module of
Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before
2.0.56-dev allows remote attackers to inject arbitrary web script or
HTML via the Referer when using image maps.
|
| CVE-2005-3337 |
Multiple cross-site scripting (XSS) vulnerabilities in Mantis before
0.19.3 allow remote attackers to inject arbitrary web script or HTML
via (1) unknown vectors involving Javascript and (2)
mantis/view_all_set.php.
|
| CVE-2005-3334 |
Cross-site scripting (XSS) vulnerability in index.php in Flyspray
0.9.7 through 0.9.8 (devel) allows remote attackers to inject
arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3)
string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2
parameters.
|
| CVE-2005-3329 |
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent
for Web 5.3 and earlier allows remote attackers to inject arbitrary
web script or HTML via the image parameter in a GetPic operation.
|
| CVE-2005-3320 |
Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager
Pro allows remote attackers to inject arbitrary web script or HTML via
the err parameter in the panel script.
|
| CVE-2005-3312 |
The HTML rendering engine in Microsoft Internet Explorer 6.0 allows
remote attackers to conduct cross-site scripting (XSS) attacks via
HTML in corrupted images and other files such as .GIF, JPG, and WAV,
which is rendered as HTML when the user clicks on the link, even
though the web server response and file extension indicate that it
should be treated as a different file type.
|
| CVE-2005-3310 |
Interpretation conflict in phpBB 2.0.17, with remote avatars and
avatar uploading enabled, allows remote authenticated users to inject
arbitrary web script or HTML via an HTML file with a GIF or JPEG file
extension, which causes the HTML to be executed by a victim who views
the file in Internet Explorer, which renders malformed image types as
HTML, enabling cross-site scripting (XSS) attacks. NOTE: it could be
argued that this vulnerability is due to a design flaw in Internet
Explorer (CVE-2005-3312) and the proper fix should be in that browser;
if so, then this should not be treated as a vulnerability in phpBB.
|
| CVE-2005-3308 |
Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4
allow remote attackers to inject arbitrary web script or HTML via the
(1) name or (2) comment parameter in detail.php, (3) the username
parameter in get.php, and (4) the search parameter in index.php.
|
| CVE-2005-3306 |
Cross-site scripting (XSS) vulnerability in index.php for FlatNuke
2.5.6 allows remote attackers to inject arbitrary web script or HTML
via the user parameter in a profile operation, a different
vulnerability than CVE-2005-2814. NOTE: it is possible that this XSS
is a resultant vulnerability of CVE-2005-3307.
|
| CVE-2005-3301 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
before 2.6.4-pl3 allow remote attackers to inject arbitrary web script
or HTML via certain arguments to (1) left.php, (2) queryframe.php, or
(3) server_databases.php.
|
| CVE-2005-3292 |
Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93
allow remote attackers to inject arbitrary web script or HTML via
Javascript events in tages such as <b>.
|
| CVE-2005-3285 |
Cross-site scripting (XSS) vulnerability in
comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus
allows remote attackers to inject arbitrary web script or HTML via the
(1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2
parameters.
|
| CVE-2005-3283 |
Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2005-3264 |
Cross-site scripting (XSS) vulnerability in thread.php for Zeroblog
1.1f and 1.2a allows remote attackers to inject arbitrary web script
or HTML via the threadID parameter.
|
| CVE-2005-3260 |
Multiple cross-site scripting (XSS) vulnerabilities in
versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to
inject arbitrary web script or HTML via (1) the url parameter in
dereferrer.php and (2) the file parameter in imagewin.php.
|
| CVE-2005-3237 |
Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote
attackers to inject arbitrary web script or HTML via the t_login
parameter of footer.php.
|
| CVE-2005-3236 |
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote
attackers to execute arbitrary SQL and obtain administrative access
via (1) the fid parameter of newmsg.php, which can enable XSS attacks
when the SQL syntax is invalid or (2) the nick parameter of
lostpwd.php.
|
| CVE-2005-3208 |
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop
and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL
code via (a) the password parameter in control.asp, and (b) the strSQL
parameter in search.asp, which can enable XSS attacks in resulting
error messages.
|
| CVE-2005-3205 |
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in
Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to
inject arbitrary web script or HTML via script in the "set markup HTML
TABLE" command, which is executed when the user selects a table.
|
| CVE-2005-3204 |
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows
remote attackers to inject arbitrary web script or HTML via the query
string in an HTTP request.
|
| CVE-2005-3202 |
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB
(HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary
web script or HTML, and subsequently execute SQL statements via the
(1) p or (2) p_t02 parameters.
|
| CVE-2005-3200 |
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro
(UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web
script or HTML via (1) the sitetitle parameter in header.php and (2)
the version and (3) query_count parameters in footer.php.
|
| CVE-2005-3167 |
Incomplete blacklist vulnerability in MediaWiki before 1.4.11 does not
properly remove certain CSS inputs (HTML inline style attributes) that
are processed as active content by Internet Explorer, which allows
remote attackers to conduct cross-site scripting (XSS) attacks.
|
| CVE-2005-3165 |
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki
before 1.4.9 allow remote attackers to inject arbitrary web script or
HTML via (1) <math> tags or (2) Extension or <nowiki> sections that
"bypass HTML style attribute restrictions" that are intended to
protect against XSS vulnerabilities in Internet Explorer clients.
|
| CVE-2005-3156 |
Directory traversal vulnerability in printfaq.php in EasyGuppy (Guppy
for Windows) 4.5.4 and 4.5.5 allows remote attackers to read arbitrary
files via ".." sequences in the pg parameter, which is cleansed for
XSS but not directory traversal.
|
| CVE-2005-3152 |
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3
allow remote attackers to inject arbitrary web script or HTML via the
redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr
parameter in a viewCat action to index.php. Note: vectors (1) and (2)
were later reported to affect 3.0.7-pl1.
|
| CVE-2005-3131 |
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail
Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier
versions, allow remote attackers to inject arbitrary web script or
HTML via the (1) id parameter to blank.html, or the createdataCX
parameter to (2) calendar_d.html, (3) calendar_m.html, or (4)
calendar_w.html.
|
| CVE-2005-3128 |
Cross-site scripting (XSS) vulnerability in add.php in Address Add
Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject
arbitrary web script or HTML via the IMG tag.
|
| CVE-2005-3127 |
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS
1.0.11 allows remote attackers to inject arbitrary web script or HTML
via the query string.
|
| CVE-2005-3103 |
Cross-site scripting (XSS) vulnerability in Movable Type before 3.2
allows remote attackers to inject arbitrary web script or HTML via the
(1) title, (2) category, (3) body, (4) extended body, and (5) excerpt
form fields in new blog entries.
|
| CVE-2005-3091 |
Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1
allows remote attackers to inject arbitrary web script or HTML via
unknown attack vectors, as identified by bug#0005751 "thraxisp".
|
| CVE-2005-3090 |
Cross-site scripting (XSS) vulnerability in bug_actiongroup_page.php
in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject
arbitrary web script or HTML via the summary of the bug, which is not
quoted when view_all_bug_page.php is used to delete the bug, as
identified by bug#0006002, a different vulnerability than
CVE-2005-2557.
|
| CVE-2005-3085 |
Multiple cross-site scripting (XSS) vulnerabilities in rss.php in
Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers
to inject arbitrary web script or HTML via the (1) forum or (2) topic
parameters.
|
| CVE-2005-3083 |
Cross-site scripting (XSS) vulnerability in index.php in CMS Made
Simple 0.10 allows remote attackers to inject arbitrary web script or
HTML via the page parameter.
|
| CVE-2005-3078 |
Cross-site scripting (XSS) vulnerability in PunBB before 1.2.8 allows
remote attackers to inject arbitrary web script or HTML via the
"forgotten e-mail" feature.
|
| CVE-2005-3067 |
Cross-site scripting (XSS) vulnerability in perldiver.cgi in PerlDiver
2.x allows remote attackers to inject arbitrary web script or HTML via
the module parameter.
|
| CVE-2005-3066 |
Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver
1.x allows remote attackers to inject arbitrary web script or HTML via
the query string. NOTE: this issue was originally disputed by the
vendor, but it has since been acknowledged.
|
| CVE-2005-3047 |
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) PMF_CONF[version] parameter to footer.php or (2)
PMF_LANG[metaLanguage] to header.php.
|
| CVE-2005-3037 |
Cross-site scripting (XSS) vulnerability in Handy Address Book Server
1.1 allows remote attackers to inject arbitrary web script or HTML via
the SEARCHTEXT parameter in a demos URL.
|
| CVE-2005-3025 |
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7
and earlier allow remote attackers to inject arbitrary web script or
HTML via the loc parameter to (1) modcp/index.php or (2)
admincp/index.php, or the ip parameter to (3) modcp/user.php or (4)
admincp/usertitle.php.
|
| CVE-2005-3023 |
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9
and earlier allow remote attackers to inject arbitrary web script or
HTML via certain arguments to (1) announcement.php, (2)
admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php,
(6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10)
ranks.php, (11) replacement.php, (12) replacement.php, (13)
template.php, (14) template.php, (15) usergroup.php, or (16)
usertitle.php.
|
| CVE-2005-3020 |
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin
before 3.0.9 allow remote attackers to inject arbitrary web script or
HTML via the (1) group parameter to css.php, (2) redirect parameter to
index.php, (3) email parameter to user.php, (4) goto parameter to
language.php, (5) orderby parameter to modlog.php, and the (6) hex,
(7) rgb, or (8) expandset parameter to template.php.
|
| CVE-2005-3017 |
PHP file inclusion vulnerability in index.php in Content2Web 1.0.1
allows remote attackers to include arbitrary files via the show
parameter, which can lead to resultant errors such as path disclosure,
SQL error messages, and cross-site scripting (XSS).
|
| CVE-2005-3015 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2
allows remote attackers to inject arbitrary web script or HTML via the
(1) BaseTarget or (2) Src parameters.
|
| CVE-2005-3014 |
Cross-site scripting (XSS) vulnerability in Ensim webplliance allows
remote attackers to inject arbitrary web script or HTML via the Login
(OCW_login_username) field.
|
| CVE-2005-3009 |
Cross-site scripting (XSS) vulnerability in CuteNews allows remote
attackers to inject arbitrary web script or HTML via the mod parameter
to index.php.
|
| CVE-2005-3000 |
Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php
in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject
arbitrary web script or HTML via the (1) font, (2) normalfontcolor, or
(3) mess[31] parameters.
|
| CVE-2005-2994 |
Unspecified vulnerability in the web client for IBM Rational
ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through
2003.06.15 before SR5, allows remote attackers to execute XML Style
Sheets (XSS).
|
| CVE-2005-2982 |
Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1
allows remote attackers to inject arbitrary web script or HTML via the
URL, which is not properly quoted in the resulting 404 error page.
|
| CVE-2005-2981 |
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5
allows remote attackers to inject arbitrary web script or HTML via the
URL, which is not properly quoted in the resulting 404 error page.
|
| CVE-2005-2980 |
Cross-site scripting (XSS) vulnerability in index.php in
phpoutsourcing Noah's classifieds 1.3 allows remote attackers to
inject arbitrary web script or HTML via the rollid parameter.
|
| CVE-2005-2979 |
SQL injection vulnerability in index.php in phpoutsourcing Noah's
classifieds allows remote attackers to execute arbitrary SQL commands
via the rollid parameter.
|
| CVE-2005-2953 |
Cross-site scripting (XSS) vulnerability in merchant.mvc in MIVA
Merchant 5 allows remote attackers to inject arbitrary web script or
HTML via the Customer_Login parameter.
|
| CVE-2005-2950 |
Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through
7.1.13 allows remote attackers to inject arbitrary web script or HTML
via the query string in an HTTP GET request.
|
| CVE-2005-2901 |
Multiple Cross-site scripting (XSS) vulnerabilities in CjWeb2Mail 3.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) name, (2) message, or (3) ip parameter to thankyou.php or (4) emsg
parameter to web2mail.php.
|
| CVE-2005-2900 |
Cross-site scripting (XSS) vulnerability in top.php in CjLinkOut 1.0
allows remote attackers to inject arbitrary web script or HTML via the
123 parameter.
|
| CVE-2005-2899 |
Multiple cross-site scripting (XSS) vulnerabilities in details.php in
CjTagBoard 3.0 allow remote attackers to inject arbitrary web script
or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or
(6) msg parameter.
|
| CVE-2005-2894 |
Cross-site scripting (XSS) vulnerability in the user registration in
PBLang 4.65, and possibly earlier versions, allows remote attackers to
inject arbitrary web script or PHP via the location field.
|
| CVE-2005-2886 |
Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro
1.0.73, and possibly earlier versions, allow remote attackers to
inject arbitrary web script or HTML via (1) the print parameter to the
print module, the sitename parameter to (2) bb_smilies or (3)
bbcode_ref module, or (4) the hlpfile parameter to openwindow.php.
|
| CVE-2005-2884 |
Cross-site scripting (XSS) vulnerability in events.php in Land Down
Under (LDU) 801 and earlier allows remote attackers to inject
arbitrary web script or HTML via the Description field in an event.
|
| CVE-2005-2882 |
Multiple cross-site scripting (XSS) vulnerabilities in
phpCommunityCalendar 4.0.3, and possibly earlier versions, allow
remote attackers to inject arbitrary web script or HTML via the
LocationID parameter to (1) thankyou.php or (2) day.php, font
parameter to (3) calDaily.php, (4) calMonthly.php, (5)
calMonthlyP.php, (6) calWeekly.php, (7) calWeeklyP.php, (8)
calYearly.php, (9) calYearlyP.php, (10) day.php, or (11) week.php, or
(12) CeTi, (13) Contact, (14) Description, (15) ShowAddress parameter
to event.php, and other attack vectors.
|
| CVE-2005-2869 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
before 2.6.4 allow remote attackers to inject arbitrary web script or
HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2)
the error parameter to error.php.
|
| CVE-2005-2863 |
Cross-site scripting (XSS) vulnerability in openwebmail-main.pl in
OpenWebMail 2.41 allows remote attackers to inject arbitrary web
script or HTML via the sessionid parameter.
|
| CVE-2005-2861 |
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial
Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote
attackers to inject arbitrary web script or HTML via the Server field
in an HTTP response header, which is directly injected into an HTML
report.
|
| CVE-2005-2860 |
Cross-site scripting (XSS) vulnerability in Nikto 1.35 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
Server field in an HTTP response header, which is directly injected
into an HTML report.
|
| CVE-2005-2855 |
Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard
1.5.3 allows remote attackers to inject arbitrary web script or HTML
via the description field.
|
| CVE-2005-2853 |
Multiple cross-site scripting (XSS) vulnerabilities in GuppY 4.5.3a
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the pg parameter to printfaq.php, or the (2) Referer or
(3) User-Agent HTTP headers, which are not properly handled by
error.php.
|
| CVE-2005-2839 |
Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro
1.0.72 allow remote attackers to inject arbitrary web script or HTML
via (1) dl-search.php or (2) wl-search.php.
|
| CVE-2005-2836 |
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the username parameter to register.php or (2) a signature
of a logged-in user in "My Control Center," which is not properly
handled by control.php.
|
| CVE-2005-2820 |
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows
remote attackers to inject arbitrary web script or HTML via an e-mail
message containing Internet Explorer "Conditional Comments" such as
"[if]" and "[endif]".
|
| CVE-2005-2818 |
Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote
attackers to inject arbitrary web script or HTML via the id parameter
to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.
|
| CVE-2005-2816 |
Cross-site scripting (XSS) vulnerability in Greymatter allows remote
attackers to inject arbitrary web script or HTML via a post comment,
which is recorded in a log file but not properly handled when the
administrator uses "View Control Panel Log" to read the log file.
|
| CVE-2005-2814 |
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows
remote attackers to inject arbitrary web script or HTML via the usr
parameter in a vis_reg operation to index.php.
|
| CVE-2005-2803 |
Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows
remote attackers to inject arbitrary web script or HTML via a page
name in a Login link, a different vulnerability than CVE-2005-2336.
|
| CVE-2005-2783 |
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and
earlier allows remote attackers to inject arbitrary web script or HTML
via nested, malformed URL BBCode tags.
|
| CVE-2005-2780 |
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU)
allows remote attackers to inject arbitrary web script or HTML via a
signature.
|
| CVE-2005-2776 |
Multiple cross-site scripting (XSS) vulnerabilities in Looking Glass
20040427 allow remote attackers to inject arbitrary web script or HTML
via the (1) version[fullname], (2) version[homepage], or (3)
version[no] parameter to footer.php, or the (4) version[fullname], (5)
version[no], (6) version[author], (7) version[email] parameter to
header.php.
|
| CVE-2005-2775 |
php_api.php in phpWebNotes 2.0.0 uses the extract function to modify
key variables such as $t_path_core, which leads to a PHP file
inclusion vulnerability that allows remote attackers to execute
arbitrary PHP code via the t_path_core parameter.
|
| CVE-2005-2769 |
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and
possibly other versions allows remote attackers to inject arbitrary
web script or HTML via an HTML e-mail containing tags with strings
that contain ">" or other special characters, which is not properly
sanitized by SqWebMail.
|
| CVE-2005-2761 |
Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000
allows administrators to inject arbitrary web script or HTML by
modifying the main screen message.
|
| CVE-2005-2737 |
Cross-site scripting (XSS) vulnerability in PhotoPost PHP Pro 5.1
allows remote attackers to inject arbitrary web script or HTML via
EXIF data, such as the Camera Model Tag.
|
| CVE-2005-2736 |
Cross-site scripting (XSS) vulnerability in YaPig 0.95 and earlier
allows remote attackers to inject arbitrary web script or HTML via
EXIF data, such as the Camera Model Tag.
|
| CVE-2005-2735 |
Cross-site scripting (XSS) vulnerability in phpGraphy 0.9.9a and
earlier allows remote attackers to inject arbitrary web script or HTML
via EXIF data, such as the Camera Model Tag.
|
| CVE-2005-2734 |
Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via EXIF data, such as the Camera Model Tag.
|
| CVE-2005-2724 |
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows
remote attackers to inject arbitrary web script or HTML via a file
attachment that is processed by the Display feature. NOTE: the
severity of this issue has been disputed by the developer.
|
| CVE-2005-2721 |
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php
or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject
arbitrary web script or HTML via the Referer field in the HTTP header.
|
| CVE-2005-2698 |
Cross-site scripting (XSS) vulnerability in browse.php in Nephp
Publisher Enterprise 3.04 allows remote attackers to inject arbitrary
web script or HTML via a hex-encoded keywords parameter.
|
| CVE-2005-2689 |
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke
0.760-RC4b allows remote attackers to inject arbitrary web script or
HTML via (1) the moderate parameter to the Comments module or (2)
htmltext parameter to html/user.php.
|
| CVE-2005-2688 |
Multiple cross-site scripting (XSS) vulnerabilities in SaveWebPortal
3.4 allow remote attackers to inject arbitrary web script or HTML via
a large number of parameters to (1) footer.php, (2) header.php, (3)
menu_dx.php, or (4) menu_sx.php, or Javascript code in the (5)
HTTP_REFERER (referer) or (6) HTTP_USER_AGENT (user agent) fields.
|
| CVE-2005-2676 |
Cross-site scripting (XSS) vulnerability in displayimage.php in
Coppermine Photo Gallery before 1.3.4 allows remote attackers to
inject arbitrary web script or HTML via EXIF data.
|
| CVE-2005-2674 |
** DISPUTED ** Note: the vendor has disputed this issue.
Multiple cross-site scripting (XSS) vulnerabilities in Land Down Under
(LDU) 800 allow remote attackers to inject arbitrary web script or
HTML via the (1) c or (2) m parameters to index.php or (3) w parameter
to journal.php. NOTE: this issue has been disputed by the vendor, who
says "None of the tricks written there are working, the variables are
properly sanitized and no LDU version is affected."
|
| CVE-2005-2653 |
Cross-site scripting (XSS) vulnerability in BBCaffe 2.0 allows remote
attackers to inject arbitrary web script or HTML via e-mail data in a
message.
|
| CVE-2005-2650 |
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa
Guestbook 1.2 allows remote attackers to inject arbitrary web script
or HTML via the (1) name, (2) location, and (3) email parameters.
|
| CVE-2005-2649 |
Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote
attackers to inject arbitrary web script or HTML via (1) course
parameter in login.php or (2) words parameter in search.php.
|
| CVE-2005-2647 |
Cross-site scripting (XSS) vulnerability in Xerox MicroServer Web
Server in Document Centre 220 through 265, 332 and 340, 420 through
490, and 535 through 555 allows remote attackers to inject arbitrary
web script or HTML and modify web pages via unknown vectors.
|
| CVE-2005-2638 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews
1.40 and earlier allow remote attackers to inject arbitrary web script
or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the
(2) Match or (3) NewsMode parameter to SearchResults.php.
|
| CVE-2005-2622 |
Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop
6.0.2 allows remote attackers to inject arbitrary web script or HTML
via the (1) max or (2) ctg parameter.
|
| CVE-2005-2610 |
Cross-site scripting (XSS) vulnerability in index.php in VegaDNS
0.8.1, 0.9.8, and possibly other versions, allows remote attackers to
inject arbitrary web script or HTML via the message parameter.
|
| CVE-2005-2608 |
SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS
comments, which allows remote attackers to conduct cross-site
scripting (XSS) attacks in vulnerable applications that use SafeHTML.
|
| CVE-2005-2603 |
Cross-site scripting (XSS) vulnerability in index.php for My Image
Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web
script or HTML via the (1) currDir or (2) image parameters.
|
| CVE-2005-2595 |
Cross-site scripting (XSS) vulnerability in Dada Mail before 2.10
Alpha 1 allows remote attackers to execute arbitrary Javascript via
archived messages.
|
| CVE-2005-2590 |
Cross-site scripting (XSS) vulnerability in Parlano MindAlign 5.0 and
later versions allows remote attackers to inject arbitrary web script
or HTML via unknown vectors.
|
| CVE-2005-2588 |
Multiple cross-site scripting (XSS) vulnerabilities in DVBBS 7.1 SP2
and earlier allow remote attackers to inject arbitrary web script or
HTML via (1) the page parameter to dispbbs.asp, (2) name parameter to
dispuser.asp, or the (3) title, (4) view, or (5) act parameter to
boardhelp.asp.
|
| CVE-2005-2569 |
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard
0.66CF, and possibly earlier versions, allow remote attackers to
inject arbitrary web script or HTML via the fbusername or fbpassword
parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4)
reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www,
(9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig
or (15) aim parameter to register.php, or (16) subject parameter to
newtopic.php.
|
| CVE-2005-2563 |
Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X
(GBX) 1.1 allow remote attackers to inject arbitrary web script or
HTML via (1) the board_id parameter to deletethread.php or (2) the
template.
|
| CVE-2005-2560 |
Cross-site scripting (XSS) vulnerability in index.cfm in CFBB 1.1.0
allows remote attackers to inject arbitrary web script or HTML via the
page parameter.
|
| CVE-2005-2557 |
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis
0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary
web script or HTML via the dir parameter, as identified by
bug#0005959, and a different vulnerability than CVE-2005-3090.
|
| CVE-2005-2556 |
core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with
register_globals enabled, allows remote attackers to connect to
internal databases by modifying the g_db_type variable and monitoring
the speed of responses, as identified by bug#0005956.
|
| CVE-2005-2545 |
Multiple cross-site scripting (XSS) vulnerabilities in PHPOpenChat
3.0.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) title or (2) content parameter to profile.php and
profile_misc.php, (3) the profile fields in userpage.php, (4) subject
or (5) body in mail.php, or (8) disinvited_chatter or (7)
invited_chatter parameter to invite.php.
|
| CVE-2005-2539 |
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5
and possibly earlier versions allow remote attackers to inject
arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3)
theme, or (4) logo parameter to structure.php, (5) admin, (6)
admin_mail, or (7) back parameter to footer.php, or (8) the message
body in a news post.
|
| CVE-2005-2523 |
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server
in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary
web script or HTML via unknown vectors.
|
| CVE-2005-2488 |
Cross-site scripting (XSS) vulnerability in Web Content Management
News System allows remote attackers to inject arbitrary web script or
HTML via (1) the strRootpath parameter to validsession.php or (2) the
strTable parameter to Admin/News/List.php.
|
| CVE-2005-2485 |
Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus
before 1.1.1 allows remote attackers to inject arbitrary web script or
HTML via unknown vectors.
|
| CVE-2005-2480 |
Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0
allows remote attackers to inject arbitrary web script or HTML via the
fuseaction parameter, which is not quoted in an error page, as
demonstrated using index.cfm.
|
| CVE-2005-2476 |
Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor
Shopping Cart 1.0 allows remote attackers to inject arbitrary web
script or HTML via the email parameter.
|
| CVE-2005-2467 |
Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum
1.5.5 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) id parameter to view.php, (2) release
parameter to list.php, or (3) F parameter to get_jsrs_data.php.
|
| CVE-2005-2465 |
Cross-site scripting (XSS) vulnerability in pm.php in PCXP/TOPPE CMS
allows remote attackers to inject arbitrary web script or HTML via the
msg variable.
|
| CVE-2005-2460 |
Multiple cross-site scripting (XSS) vulnerabilities in Kayako
liveResponse 2.x allow remote attackers to inject arbitrary web script
or HTML via the (1) username parameter or (2) name field when entering
a session or sending a message.
|
| CVE-2005-2453 |
Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server
1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows
remote attackers to inject arbitrary web script or HTML via the query
string.
|
| CVE-2005-2441 |
Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow
remote attackers to inject arbitrary web script and HTML via the (1)
UserName parameter to profile.php or (2) UserID parameter to
login.php.
|
| CVE-2005-2438 |
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier
allows remote attackers to inject arbitrary Javascript via the BBCode
color value.
|
| CVE-2005-2435 |
Cross-site scripting (XSS) vulnerability in browse.php in Website
Baker Project allows remote attackers to inject arbitrary web script
or HTML via the dir parameter.
|
| CVE-2005-2430 |
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) forum_id or (2) group_id parameter to forum.php, (3)
project_task_id parameter to task.php, (4) id parameter to detail.php,
(5) the text field on the search page, (6) group_id parameter to
qrs.php, (7) form, (8) rows, (9) cols or (10) wrap parameter to
notepad.php, or the login field on the login form.
|
| CVE-2005-2427 |
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ
allows remote attackers to inject arbitrary web script or HTML via the
message parameter.
|
| CVE-2005-2422 |
Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum
allows remote attackers to inject arbitrary web script or HTML via the
webtag parameter.
|
| CVE-2005-2416 |
Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before
1.0.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) term parameter to the search module or (2) title in the
blog aggregation module.
|
| CVE-2005-2406 |
Opera 8.01 allows remote attackers to conduct cross-site scripting
(XSS) attacks or modify which files are uploaded by tricking a user
into dragging an image that is a "javascript:" URI.
|
| CVE-2005-2402 |
Cross-site scripting (XSS) vulnerability in search.php in
PHPSiteSearch 1.7.7d allows remote attackers to inject arbitrary web
script or HTML via the query parameter.
|
| CVE-2005-2397 |
Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook
1.46 allows remote attackers to inject arbitrary web script or HTML
via the admin parameter.
|
| CVE-2005-2396 |
Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and
earlier allows remote attackers to inject arbitrary web script or HTML
via a parameter to the page move template.
|
| CVE-2005-2393 |
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows
remote attackers to inject arbitrary web script or HTML via (1) the
lastusername parameter to index.php or (2) selected_search_arch
parameter to search.php.
|
| CVE-2005-2392 |
Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4
and earlier allows remote attackers to inject arbitrary web script or
HTML via the search parameter in the search function.
|
| CVE-2005-2386 |
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ
1.20 allows remote attackers to inject arbitrary web script or HTML
via the message parameter.
|
| CVE-2005-2379 |
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports
9.0.2 allow remote attackers to inject arbitrary web script or HTML
via the (1) debug parameter to showenv, (2) test parameter to
parsequery, or (3) delimiter or (4) CELLWRAPPER parameter to
rwservlet.
|
| CVE-2005-2339 |
Cross-site scripting (XSS) vulnerability in the Unicode version of
msearch (unicode-msearch) 1.51(U1)-beta1, 1.51(U1), and 1.52(U1)
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2005-2338 |
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP
and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1
allow remote attackers to inject arbitrary web script or HTML via (1)
modules that use "XOOPS Code" and (2) newbb in the forum module.
|
| CVE-2005-2336 |
Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows
remote attackers to inject arbitrary web script or HTML via "missing
pages" in which the page name is not properly escaped, a different
vulnerability than CVE-2005-2803.
|
| CVE-2005-2333 |
Cross-site scripting (XSS) vulnerability in smilies_popup.php in
SEO-Board 1.0 allows remote attackers to inject arbitrary web script
or HTML via the doc parameter.
|
| CVE-2005-2332 |
Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a
allows remote attackers to inject arbitrary web script or HTML via the
username parameter to (1) admin.php or (2) login.php.
|
| CVE-2005-2327 |
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier
allows remote attackers to inject arbitrary web script or HTML via
nested [url] BBCode tags.
|
| CVE-2005-2326 |
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a
allows remote attackers to inject arbitrary web script or HTML via the
yr parameter to calendar.php.
|
| CVE-2005-2324 |
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a
allows remote attackers to inject arbitrary web script or HTML via the
searchtype or searchterm parameters to (1) results.php or (2)
categorysearch.php.
|
| CVE-2005-2322 |
Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and
0.23.2, and Clever Copy with forums installed, allows remote attackers
to inject arbitrary web script or HTML via the (1) viewuser_id or (2)
group parameter to users.php.
|
| CVE-2005-2318 |
Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1
SP2 allows remote attackers to inject arbitrary web script or HTML via
the action parameter.
|
| CVE-2005-2299 |
Multiple cross-site scripting (XSS) vulnerabilities in Simple Message
Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary
web script or HTML via the (1) FID parameter to forum.cfm, (2) UID
parameter to user.cfm, (3) TID parameter to thread.cfm, or (4)
PostDate parameter to search.cfm.
|
| CVE-2005-2289 |
PHPCounter 7.2 allows remote attackers to obtain sensitive information
via a direct request to prelims.php, which reveals the path in an
error message.
|
| CVE-2005-2288 |
Cross-site scripting (XSS) vulnerability in PHPCounter 7.2 allows
remote attackers to inject arbitrary web script or HTML via the
EpochPrefix parameter.
|
| CVE-2005-2282 |
Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before
6.0.2 allow remote attackers to inject arbitrary web script and HTML
via unknown vectors.
|
| CVE-2005-2276 |
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess
6.5 before July 11, 2005 allows remote attackers to inject arbitrary
web script or HTML via an e-mail message with an encoded javascript
URI (e.g. "jAvascript" in an IMG tag.
|
| CVE-2005-2254 |
Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5
allow remote attackers to inject arbitrary web script or HTML via the
lan parameter to (1) index.php or (2) admin/index.php, or (3) the
auction_id parameter to profile.php. NOTE: there is evidence that
viewnews.php and login.php may not be part of the PhpAuction product,
so they are not included in this description.
|
| CVE-2005-2215 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x
before 1.4.6 and 1.5 before 1.5beta3 allows remote attackers to inject
arbitrary web script or HTML via a parameter in the page move
template, a different vulnerability than CVE-2005-1888.
|
| CVE-2005-2207 |
Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ
allows remote attackers to inject arbitrary web script or HTML via the
message parameter.
|
| CVE-2005-2204 |
Cross-site scripting (XSS) vulnerability in Computer Associates (CA)
eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to
"NO," allows remote attackers to inject arbitrary web script or HTML
via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe,
(3) the TARGET parameter to login.fcc, and possibly other vectors.
|
| CVE-2005-2202 |
Cross-site scripting (XSS) vulnerability in the MicroServer Web Server
for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version
0.001.04.044 through 0.001.04.504, allows remote attackers to inject
arbitrary web script or HTML via unknown vectors.
|
| CVE-2005-2191 |
Multiple cross-site scripting (XSS) vulnerabilities in Comersus
shopping cart allow remote attackers to inject arbitrary web script or
HTML via the (1) name parameter to
comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message
parameter to comersus_backoffice_message.asp.
|
| CVE-2005-2186 |
Multiple cross-site scripting (XSS) vulnerabilities in McAfee
IntruShield Security Management System allow remote authenticated
users to inject arbitrary web script or HTML via the (1) thirdMenuName
or (2) resourceName parameter to SystemEvent.jsp.
|
| CVE-2005-2167 |
Cross-site scripting (XSS) vulnerability in index.php in Plague News
System 0.6 and earlier allows remote attackers to inject arbitrary web
script or HTML via the cid parameter.
|
| CVE-2005-2163 |
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP
Script 1.5.2 allows remote attackers to inject arbitrary web script or
HTML via the search parameter.
|
| CVE-2005-2161 |
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote
attackers to inject arbitrary web script or HTML via nested [url]
tags.
|
| CVE-2005-2138 |
Cross-site scripting (XSS) vulnerability in index.php in Comdev
eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web
script or HTML via Javascript in the onMouseOver event of an "A" tag
in a review message.
|
| CVE-2005-2112 |
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) order parameter to edit.php or (2) cid parameter to
comment_edit.php.
|
| CVE-2005-2107 |
Multiple cross-site scripting (XSS) vulnerabilities in post.php in
WordPress 1.5.1.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) p or (2) comment parameter.
|
| CVE-2005-2095 |
options_identities.php in SquirrelMail 1.4.4 and earlier uses the
extract function to process the $_POST variable, which allows remote
attackers to modify or read the preferences of other users, conduct
cross-site scripting XSS) attacks, and write arbitrary files.
|
| CVE-2005-2094 |
Sun SunONE web server 6.1 SP1 allows remote attackers to poison the
web cache, bypass web application firewall protection, and conduct XSS
attacks via an HTTP request with both a "Transfer-Encoding: chunked"
header and a Content-Length header, which causes SunONE to incorrectly
handle and forward the body of the request in a way that causes the
receiving server to process it as a separate HTTP request, aka "HTTP
Request Smuggling."
|
| CVE-2005-2093 |
Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote
attackers to poison the web cache, bypass web application firewall
protection, and conduct XSS attacks via an HTTP request with both a
"Transfer-Encoding: chunked" header and a Content-Length header, which
causes Application Server to incorrectly handle and forward the body
of the request in a way that causes the receiving server to process it
as a separate HTTP request, aka "HTTP Request Smuggling."
|
| CVE-2005-2092 |
BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web
cache, bypass web application firewall protection, and conduct XSS
attacks via an HTTP request with both a "Transfer-Encoding: chunked"
header and a Content-Length header, which causes WebLogic to
incorrectly handle and forward the body of the request in a way that
causes the receiving server to process it as a separate HTTP request,
aka "HTTP Request Smuggling."
|
| CVE-2005-2091 |
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison
the web cache, bypass web application firewall protection, and conduct
XSS attacks via an HTTP request with both a "Transfer-Encoding:
chunked" header and a Content-Length header, which causes WebSphere to
incorrectly handle and forward the body of the request in a way that
causes the receiving server to process it as a separate HTTP request,
aka "HTTP Request Smuggling."
|
| CVE-2005-2090 |
Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0)
allows remote attackers to poison the web cache, bypass web
application firewall protection, and conduct XSS attacks via an HTTP
request with both a "Transfer-Encoding: chunked" header and a
Content-Length header, which causes Tomcat to incorrectly handle and
forward the body of the request in a way that causes the receiving
server to process it as a separate HTTP request, aka "HTTP Request
Smuggling."
|
| CVE-2005-2089 |
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web
cache, bypass web application firewall protection, and conduct XSS
attacks via an HTTP request with both a "Transfer-Encoding: chunked"
header and a Content-Length header, which causes IIS to incorrectly
handle and forward the body of the request in a way that causes the
receiving server to process it as a separate HTTP request, aka "HTTP
Request Smuggling."
|
| CVE-2005-2088 |
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when
acting as an HTTP proxy, allows remote attackers to poison the web
cache, bypass web application firewall protection, and conduct XSS
attacks via an HTTP request with both a "Transfer-Encoding: chunked"
header and a Content-Length header, which causes Apache to incorrectly
handle and forward the body of the request in a way that causes the
receiving server to process it as a separate HTTP request, aka "HTTP
Request Smuggling."
|
| CVE-2005-2084 |
Cross-site scripting (XSS) vulnerability in SearchResults.aspx in
Community Forum allows remote attackers to inject arbitrary web script
or HTML via the q parameter.
|
| CVE-2005-2077 |
Cross-site scripting (XSS) vulnerability in error.asp for Hosting
Controller allows remote attackers to inject arbitrary web script or
HTML via the error parameter.
|
| CVE-2005-2074 |
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.0.105 allows
remote attackers to inject arbitrary web script or HTML via a news or
article post, possibly involving the (1) news_body, (2)
article_description, or (3) article_body parameters to submit.php.
|
| CVE-2005-2063 |
Multiple cross-site scripting (XSS) vulnerabilities in
ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web
script or HTML via the (1) Title parameter to sendpassword.asp or (2)
Keyword field in search.asp.
|
| CVE-2005-2057 |
Multiple cross-site scripting (XSS) vulnerabilities in Infopop
UBB.Threads before 6.5.2 Beta allow remote attackers to inject
arbitrary web script or HTML via the (1) Searchpage parameter to
dosearch.php, (2) Number, (3) what, or (4) page parameter to
newreply.php, (5) Number, (6) Board, or (7) what parameter to
showprofile.php, (8) fpart or (9) page parameter to showflat.php, or
(10) like parameter to showmembers.php.
|
| CVE-2005-2044 |
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3
and 1.5 RC 1 allow remote attackers to inject arbitrary web script or
HTML via the (1) show_course parameter to browse.php, (2) subject
parameter to contact.php, (3) cid parameter to content.php, (4) l
parameter to inbox/send_message.php, the (5) search, (6) words, (7)
include, (8) find_in, (9) display_as, or (10) search parameter to
search.php, the (11) submit, (12) query, or (13) field parameter to
tile.php, the (14) us parameter to forum/subscribe_forum.php, or the
(15) roles[], (16) status, (17) submit, or (18) reset_filter
parameters to directory.php.
|
| CVE-2005-2042 |
Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8
allows remote attackers to inject arbitrary web script or HTML via
onmouseover or other events in HTML tags.
|
| CVE-2005-2034 |
Cross-site scripting (XSS) vulnerability in folderview.asp for
BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary
web script or HTML via the folder parameter.
|
| CVE-2005-2022 |
Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch
1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute
arbitrary Javascript, possibly due to a cross-site scripting (XSS)
vulnerability.
|
| CVE-2005-2021 |
Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
user parameter in the login page.
|
| CVE-2005-2011 |
Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta
4 allow remote attackers to inject arbitrary web script or HTML, as
demonstrated via the id parameter in a Question action.
|
| CVE-2005-2010 |
Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog
Reload 1.0.5 allows remote attackers to inject arbitrary web script or
HTML via the btitle parameter.
|
| CVE-2005-1999 |
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in
paFileDB 3.1 allow remote attackers to inject arbitrary web script or
HTML via the (1) sortby or (2) filelist parameters to the category
action (category.php), or (3) pages parameter in the viewall action
(viewall.php).
|
| CVE-2005-1975 |
Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two
1.1 and earlier allow remote attackers to inject arbitrary web script
or HTML via (1) the id parameter to index.php, or the (2) site_id, (3)
nom, (4) email, or (5) commentaire parameters in commentaires.php.
|
| CVE-2005-1969 |
Cross-site scripting (XSS) vulnerability in Pragma Systems
Telnetserver 6.0 allows remote attackers to inject arbitrary web
script or HTML, and hide activities in log files, via a "<!--" (HTML
comment) in a session.
|
| CVE-2005-1968 |
Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce
before 2.7 allows remote attackers to inject arbitrary web script or
HTML via the error parameter to techErr.asp.
|
| CVE-2005-1962 |
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3
allows remote attackers to inject arbitrary web script or HTML via the
(1) errorcode parameter to index.php or (2) certain fields to
clients.php.
|
| CVE-2005-1955 |
Cross-site scripting (XSS) vulnerability in index.php in singapore
0.9.11 allows remote attackers to inject arbitrary web script or HTML
via the gallery parameter.
|
| CVE-2005-1945 |
Cross-site scripting (XSS) vulnerability in the convert_highlite_words
function in Invision Blog before 1.1.2 Final allows remote attackers
to inject arbitrary web script or HTML via double hex encoded
highlight data.
|
| CVE-2005-1909 |
The web server control panel in 602LAN SUITE 2004 allows remote
attackers to make it more difficult for the administrator to read
portions of log files via a "</pre><!-" sequence in an HTTP GET
request in the logon, possibly due to a cross-site scripting (XSS)
vulnerability.
|
| CVE-2005-1901 |
Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before
7.1.6 allow remote attackers to inject arbitrary web script or HTML
via (1) the username in the Add User window or (2) the license key in
the Licensing page.
|
| CVE-2005-1895 |
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows
remote attackers to inject arbitrary web script or HTML via the border
or back parameters to (1) help.php or (2) footer.php.
|
| CVE-2005-1888 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5
allows remote attackers to inject arbitrary web script via HTML
attributes in page templates.
|
| CVE-2005-1886 |
Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b,
0.93u and 0.94u allows remote attackers to inject arbitrary web script
or HTML via (1) the phid parameter or (2) unknown parameters when
posting a new comment.
|
| CVE-2005-1877 |
Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel
1.59 and earlier allows remote attackers to inject arbitrary web
script or HTML and obtain sensitive information via the pid parameter.
|
| CVE-2005-1866 |
Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix
Advanced 1.5 allows remote attackers to inject arbitrary web script or
HTML via the year parameter.
|
| CVE-2005-1832 |
Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard
(MyBB) 1.00 RC4 and earlier allow remote attackers to execute
arbitrary web script or HTML via the (1) forums, (2) version, or (3)
limit parameter to misc.php, (4) page or (5) datecut parameter to
forumdisplay.php, (6) username, (7) email, or (8) email2 parameter to
member.php, (9) page or (10) usersearch parameter to memberlist.php,
(11) pid or (12) tid parameter to showthread.php, or (13) tid
parameter to printthread.php.
|
| CVE-2005-1823 |
Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam
X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or
HTML via the (1) cat or (2) printable parameter to home.php, (3)
productid or (4) mode parameter to product.php, (5) id parameter to
error_message.php, (6) section parameter to help.php, (7) mode
parameter to orders.php, (8) mode parameter to register.php, (9) mode
parameter to search.php, or the (10) gcid or (11) gcindex parameter to
giftcert.php.
|
| CVE-2005-1819 |
Cross-site scripting (XSS) vulnerability in NikoSoft WebMail before
0.11.0 allows remote attackers to inject arbitrary web script or HTML
via unknown vectors.
|
| CVE-2005-1811 |
Cross-site scripting (XSS) vulnerability in usercp.php for
MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web
script or HTML via the website field in a user profile.
|
| CVE-2005-1803 |
Multiple cross-site scripting (XSS) vulnerabilities in Net Portal
Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary
web script or HTML via the language parameter to (1) admin.php, or (2)
powerpack_f.php, (3) the sitename parameter to sdv_infos.php, (4) the
categories parameter to faq.php, (5) the lettre parameter to the
glossaire module, (6) the title parameter to reviews.php, or (7) the
image_subject parameter to reply.php.
|
| CVE-2005-1800 |
Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4
to 0.5.1 allows remote attackers to inject arbitrary web script or
HTML via the term parameter in a view or ViewTerm action to index.php.
|
| CVE-2005-1799 |
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and
WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary
web script or HTML via unknown vectors.
|
| CVE-2005-1782 |
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta
1.0 allow remote attackers to inject arbitrary web script or HTML via
the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3)
suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the
isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8)
add_classification.htm, the (9) chapters parameter to the add_contents
page in index.php (aka add_contents.htm), (10) the user parameter to
contact.htm, or (11) the submit[string] parameter to search.htm.
NOTE: it is not clear whether BookReview is available to the public.
If not, then it should not be included in CVE.
|
| CVE-2005-1778 |
Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke
0.750 allows remote attackers to inject arbitrary web script or HTML
via the start parameter.
|
| CVE-2005-1777 |
SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows
remote attackers to execute arbitrary SQL commands via the start
parameter.
|
| CVE-2005-1769 |
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail
1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web
script or HTML via unknown attack vectors in (1) the URL or (2) an
e-mail message.
|
| CVE-2005-1756 |
Cross-site scripting (XSS) vulnerability in the ModWeb agent for
Novell NetMail 3.52 before 3.52C allows remote attackers to inject
arbitrary web script or HTML via calendar display fields.
|
| CVE-2005-1747 |
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic
Server and Express 8.1 through Service Pack 4, and 7.0 through Service
Pack 6, allow remote attackers to inject arbitrary web script or HTML,
and possibly gain administrative privileges, via the (1) j_username or
(2) j_password parameters in the login page (LoginForm.jsp), (3)
parameters to the error page in the Administration Console, (4)
unknown vectors in the Server Console while the administrator has an
active session to obtain the ADMINCONSOLESESSION cookie, or (5) an
alternate vector in the Server Console that does not require an active
session but also leaks the username and password.
|
| CVE-2005-1735 |
Multiple cross-site scripting (XSS) vulnerabilities in PROMS before
0.11 allow remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2005-1715 |
Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2
(2.2.178) allows remote attackers to inject arbitrary web script or
HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5)
field name, (6) Your Web field, or (7) email field in the comments
section.
|
| CVE-2005-1714 |
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2005-1713 |
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8
allow remote attackers to inject arbitrary web script or HTML via the
(1) templatedropdown and (2) shoutbox plugins.
|
| CVE-2005-1710 |
Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat
Reporter before 7.1.2 allow remote attackers to inject arbitrary web
script or HTML via (1) the username in an Add User window or (2) the
license key (volatile.license_to_add parameter) in the Licensing page.
|
| CVE-2005-1698 |
PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain
sensitive information via a direct request to (1) theme.php or (2)
Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5)
text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9)
button.php in the pnblocks directory in the Blocks module, (10)
config.php in the NS-Multisites (aka Multisites) module, or (11)
xmlrpc.php, which reveals the path in an error message.
|
| CVE-2005-1697 |
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote
attackers to obtain sensitive information via a direct request to
simple_smarty.php, which reveals the path in an error message.
|
| CVE-2005-1696 |
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.750
and 0.760RC3 allow remote attackers to inject arbitrary web script or
HTML via the (1) skin or (2) paletteid parameter to demo.php in the
Xanthia module, or (3) the serverName parameter to config.php in the
Multisites (aka NS-Multisites) module.
|
| CVE-2005-1695 |
Multiple cross-site scripting (XSS) vulnerabilities in the RSS module
in PostNuke 0.750 and 0.760RC2 and RC3 allow remote attackers to
inject arbitrary web script or HTML via the (1) rss_url parameter to
magpie_slashbox.php, or the url parameter to (2) magpie_simple.php or
(3) magpie_debug.php.
|
| CVE-2005-1684 |
Cross-site scripting (XSS) vulnerability in default.asp for episodex
guestbook allows remote attackers to inject arbitrary web script or
HTML via the Name field and other fields.
|
| CVE-2005-1676 |
Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile
Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a
build 2364, and Groove Workspace before 2.5n build 1871 allow remote
attackers to inject arbitrary web script or HTML via the (1) picture
columns embedded within SharePoint lists or (2) drop-down menus in a
SharePoint list.
|
| CVE-2005-1672 |
Multiple cross-site scripting (XSS) vulnerabilities in Help Center
Live allow remote attackers to inject arbitrary web script or HTML via
the (1) find parameter to index.php, (2) name or (3) message field of
a chat request, or (4) the message body when opening a trouble ticket.
|
| CVE-2005-1669 |
Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095
allows remote attackers to inject arbitrary web script or HTML via
"javascript:" URLs when a new window or frame is opened, which allows
remote attackers to bypass access restrictions and perform
unauthorized actions on other domains.
|
| CVE-2005-1659 |
Cross-site scripting (XSS) vulnerability in filemanager.cpp in
MyServer 0.8 allows remote attackers to inject arbitrary Javascript
via a URL with a "..." (triple dot) followed by an onmouseover event.
|
| CVE-2005-1653 |
Cross-site scripting (XSS) vulnerability in message.htm for Woppoware
PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject
arbitrary web script or HTML via the email parameter.
|
| CVE-2005-1644 |
Cross-site scripting (XSS) vulnerability in guestbook.php for 1Two
Livre d'Or 1.0 allows remote attackers to inject arbitrary web script
or HTML via the (1) livreornom, (2) livreoremail, or (3)
livreormessage parameters.
|
| CVE-2005-1638 |
The _writeAttrs function in SafeHTML before 1.3.2 does not properly
handle quotes in attribute values, which could allow remote attackers
to exploit cross-site scripting (XSS) vulnerabilities in applications
that rely on SafeHTML for protection.
|
| CVE-2005-1634 |
Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA
JGS-Portal 3.0.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) anzahl_beitraege parameter to
jgs_portal.php, (2) year parameter to jgs_portal_statistik.php, (3)
year parameter to jgs_portal_beitraggraf.php, (4) tag parameter to
jgs_portal_viewsgraf.php, (5) year parameter to
jgs_portal_themengraf.php, (6) year parameter to
jgs_portal_mitgraf.php, (7) id parameter to jgs_portal_sponsor.php, or
(8) the Accept-Language header to jgs_portal_log.php. NOTE: this
issue may stem from the same core problem as CVE-2005-1633.
|
| CVE-2005-1622 |
Cross-site scripting (XSS) vulnerability in productsByCategory.asp in
MetaCart e-Shop allows remote attackers to inject arbitrary web script
or HTML via the strCatalog_NAME parameter.
|
| CVE-2005-1620 |
Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook
1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web
script or HTML via the (1) title or (2) content of a message.
|
| CVE-2005-1619 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in
PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script
or HTML commands via the FontName parameter. NOTE: it was later
reported that 0.14.5 is also affected.
|
| CVE-2005-1614 |
Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate
PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject
arbitrary web script or HTML via the postorder parameter.
|
| CVE-2005-1613 |
Cross-site scripting (XSS) vulnerability in member.php in Open
Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject
arbitrary web script or HTML via the reverse parameter in a list
action.
|
| CVE-2005-1611 |
Cross-site scripting (XSS) vulnerability in WebX in Web Crossing 5.x
allows remote attackers to inject arbitrary web script or HTML via a
URL with an "@" followed by the desired script.
|
| CVE-2005-1610 |
Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone
NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web
script or HTML via a base64 encoded Codigo parameter.
|
| CVE-2005-1607 |
Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart
allows remote attackers to inject arbitrary web script or HTML via the
(1) merchant or (2) demo parameters.
|
| CVE-2005-1605 |
Cross-site scripting (XSS) vulnerability in the guestbook for
SiteStudio 1.6 allows remote attackers to inject arbitrary web script
or HTML via the name field to (1) psoft.guestbook.GuestBookServ in
Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site
Studio with H-Sphere.
|
| CVE-2005-1599 |
Cross-site scripting (XSS) vulnerability in Kryloff Technologies
Subject Search Server (SSServer) 1.1 allows remote attackers to inject
arbitrary web script or HTML via the "Search For" field.
|
| CVE-2005-1597 |
Cross-site scripting (XSS) vulnerability in (1) search.php and (2)
topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows
remote attackers to inject arbitrary web script or HTML via the
highlite parameter.
|
| CVE-2005-1593 |
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat
ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web
script or HTML via the id parameter.
|
| CVE-2005-1587 |
Cross-site scripting (XSS) vulnerability in index.php for Quick.cart
0.3.0 allows remote attackers to inject arbitrary web script or HTML
via the sWord parameter.
|
| CVE-2005-1584 |
Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum
2.1.6 allows remote attackers to inject arbitrary web script or HTML
via the topic field in a NewTopic action.
|
| CVE-2005-1582 |
Cross-site scripting (XSS) vulnerability in index.php for 1Two News
1.0 allows remote attackers to inject arbitrary web script or HTML via
the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables.
|
| CVE-2005-1581 |
Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows
remote attackers to inject arbitrary web script or HTML via various
fields to bug_report.php, which are not filtered or quoted when
processed by bug_list.php or admin/index.php.
|
| CVE-2005-1569 |
Cross-site scripting (XSS) vulnerability in DirectTopics 2.1 and 2.2
allows remote attackers to inject arbitrary web script via a
javascript: URL in (1) a thread or (2) an IMG tag.
|
| CVE-2005-1562 |
Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and
earlier allow remote attackers to execute arbitrary SQL commands via
the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3)
message, or (4) subject parameter to post_info.asp, (5) andor
parameter to search.asp, (6) verkey parameter to pop_profile.asp, or
(7) Remove or (8) Delete parameter to pm_delete2.asp.
|
| CVE-2005-1561 |
Multiple cross-site scripting (XSS) vulnerabilities in post.asp in
MaxWebPortal 1.3.5 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) mod, (2) M, or (3) type
parameter.
|
| CVE-2005-1557 |
Multiple cross-site scripting (XSS) vulnerabilities in WebApp
Guestbook PRO 3.2.1 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) title or (2) content of a
message.
|
| CVE-2005-1555 |
Cross-site scripting (XSS) vulnerability in the JRun Web Server in
ColdFusion MX 7.0 allows remote attackers to inject arbitrary script
or HTML via the URL, which is not properly quoted in the resulting
default 404 error page.
|
| CVE-2005-1508 |
Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) month or (2) annee parameters to the news module, (3) nbractif or
(4) annee parameters to the stats module, (5) id parameter to
profil.php, (6) mb_lettre or (7) lettre parameter to memberlist.php,
or (8) chaine_search, or (9) auteur_search parameter to the recherche
module.
|
| CVE-2005-1502 |
Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart
allows remote attackers to inject arbitrary web script or HTML via the
(1) searchstring parameter to search_list.php or the (2) secondgroup
or (3) maingroup parameters to item_list.php.
|
| CVE-2005-1498 |
Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no,
or (4) post_id parameter in index.php, which are not properly
sanitized before they are displayed in an error message. NOTE: issues
2, 3, and 4 may be due to a problem in associated products rather than
myBloggie itself.
|
| CVE-2005-1494 |
Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in
MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) entryid or (2) password parameter.
|
| CVE-2005-1492 |
Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer
Threads Links SQL 2.x and 3.0 allows remote attackers to inject
arbitrary web script or HTML via the url parameter.
|
| CVE-2005-1488 |
Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail
Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated
users to inject arbitrary web script or HTML via (1) the E-mail
address, Note, or Public Certificate fields to address.html, (2)
addressaction.html, (3) the Signature field to settings.html, or (4)
the Shared calendars to calendarsettings.html.
|
| CVE-2005-1487 |
** DISPUTED **
Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote
attackers to execute arbitrary SQL commands via the (1) cartid
parameter to upstnt.php or (2) psku parameter to display.php. NOTE:
the vendor disputes this report, saying that they are forced SQL
errors. The original researcher is known to be unreliable.
|
| CVE-2005-1486 |
Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow
remote attackers to inject arbitrary web script or HTML via the (1)
trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or
(4) nlst parameter to display.php. NOTE: the vendor was not able to
reproduce some of the reported vectors but believes that they have
been addressed. The original researcher is known to be unreliable.
|
| CVE-2005-1483 |
Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive
2005 allow remote attackers to inject arbitrary web script or HTML via
the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5)
BlogId parameter.
|
| CVE-2005-1482 |
ArticleLive 2005 allows remote attackers to gain privileges by
modifying the (1) auth and (2) userId fields in a cookie.
|
| CVE-2005-1477 |
The install function in Firefox 1.0.3 allows remote web sites on the
browser's whitelist, such as update.mozilla.org or addon.mozilla.org,
to execute arbitrary Javascript with chrome privileges, leading to
arbitrary code execution on the system when combined with
vulnerabilities such as CVE-2005-1476, as demonstrated using a
javascript: URL as the package icon and a cross-site scripting (XSS)
attack on a vulnerable whitelist site.
|
| CVE-2005-1448 |
Cross-site scripting (XSS) vulnerability in the BBCode plugin for
Serendipity before 0.8 allows remote attackers to inject arbitrary web
script or HTML via unknown vectors.
|
| CVE-2005-1444 |
Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1
and earlier (SitePanel2) allows remote attackers to inject arbitrary
web script or HTML via (1) the v, show, or sec_name parameters to
main.php, (2) the inadmin, newsev, or postid parameters to 5.php, or
(3) the id parameter to 0.php.
|
| CVE-2005-1443 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php for
Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote
attackers to inject arbitrary web script or HTML via the (1) act, (2)
Members, (3) calendar, or (4) HID parameters.
|
| CVE-2005-1440 |
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop
Enterprise 2.1.6 allow remote attackers to inject arbitrary web script
or HTML via (1) various parameters to basket.php, (2) the nickname,
email, topic, and message fields in forum.php, as demonstrated using
forum_new_thread.php and forum_thread.php, (3) the page parameter to
page.php, (4) category_id and item_id parameters to reviews.php, (5)
the category_id parameter to product_details.php, (6) the category_id
or search_string parameters to products.php, or (7) the rp or page
parameters to news_view.php.
|
| CVE-2005-1436 |
Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow
remote attackers to inject arbitrary web script or HTML via (1) the t
parameter to view.php, (2) the osticket_title parameter to header.php,
(3) the em parameter to admin_login.php, (4) the e parameter to
user_login.php, (5) the err parameter to open_submit.php, or (6) the
name and subject fields when adding a ticket.
|
| CVE-2005-1403 |
Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's
Amazon Webstore 04050100 allow remote attackers to inject arbitrary
web script or HTML via the (1) image parameter to closeup.php, the (2)
currentIsExpanded or (3) searchFor parameters to index.php, (4) the
currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5)
a cookie.
|
| CVE-2005-1398 |
phpcart.php in PHPCart 3.2 allows remote attackers to change product
price information by modifying the (1) price or (2) postage
parameters. NOTE: it was later reported that 3.4 through 4.6.4 are
also affected.
|
| CVE-2005-1388 |
Cross-site scripting (XSS) vulnerability in SURVIVOR before 0.9.6
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2005-1381 |
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache
9i allow remote attackers to inject arbitrary web script or HTML via
the (1) cache_dump_file or (2) PartialPageErrorPage parameter.
|
| CVE-2005-1380 |
Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1
allows remote attackers to execute arbitrary web script or HTML via
the server parameter to a JndiFramesetAction action.
|
| CVE-2005-1374 |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3
through 1.6 Release Candidate 1, and possibly Dokeos, allow remote
attackers to inject arbitrary web script or HTML via (1)
exercise_result.php, (2) exercice_submit.php, (3) agenda.php, (4)
learningPathList.php, (5) learningPathAdmin.php, (6) learningPath.php,
(7) userLog.php, (8) tool parameter to toolaccess_details.php, (9)
data parameter to user_access_details.php, or (10) coursePath
parameter to myagenda.php.
|
| CVE-2005-1359 |
Cross-site scripting (XSS) vulnerability in text.cgi script allows
remote attackers to inject arbitrary web script or HTML via the
argument.
|
| CVE-2005-1356 |
Cross-site scripting (XSS) vulnerability in includer.cgi script in The
Includer allows remote attackers to inject arbitrary web script or
HTML via the argument.
|
| CVE-2005-1352 |
Cross-site scripting (XSS) vulnerability in the ad.cgi script allows
remote attackers to inject arbitrary web script or HTML via the
argument.
|
| CVE-2005-1327 |
Cross-site scripting (XSS) vulnerability in pms.php for Woltlab
Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the folderid parameter.
|
| CVE-2005-1324 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php for
phpMyVisites allow remote attackers to inject arbitrary web script or
HTML via the (1) part, (2) per, or (3) site parameters.
|
| CVE-2005-1322 |
Cross-site scripting (XSS) vulnerability in Horde Nag Task List
Manager before 1.1.3 allows remote attackers to inject arbitrary web
script or HTML via the parent's frame page title.
|
| CVE-2005-1321 |
Cross-site scripting (XSS) vulnerability in Horde Vacation module
before 2.2.2 allows remote attackers to inject arbitrary web script or
HTML via the parent's frame page title.
|
| CVE-2005-1320 |
Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager
before 1.1.4 allows remote attackers to inject arbitrary web script or
HTML via the parent's frame page title.
|
| CVE-2005-1319 |
Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client
before 3.2.8 allows remote attackers to inject arbitrary web script or
HTML via the parent's frame page title.
|
| CVE-2005-1318 |
Cross-site scripting (XSS) vulnerability in Horde Forwards E-Mail
Forwarding Manager before 2.2.2 allows remote attackers to inject
arbitrary web script or HTML via the parent's frame page title.
|
| CVE-2005-1317 |
Cross-site scripting (XSS) vulnerability in Horde Chora module before
1.2.3 allows remote attackers to inject arbitrary web script or HTML
via the parent's frame page title.
|
| CVE-2005-1316 |
Cross-site scripting (XSS) vulnerability in Horde Accounts module
before 2.1.2 allows remote attackers to inject arbitrary web script or
HTML via the parent's frame page title.
|
| CVE-2005-1315 |
Cross-site scripting (XSS) vulnerability in Horde Turba module before
1.2.5 allows remote attackers to inject arbitrary web script or HTML
via the parent's frame page title.
|
| CVE-2005-1314 |
Cross-site scripting (XSS) vulnerability in Horde Kronolith module
before 1.1.4 allows remote attackers to inject arbitrary web script or
HTML via the parent's frame page title.
|
| CVE-2005-1313 |
Cross-site scripting (XSS) vulnerability in Horde Passwd module before
2.2.2 allows remote attackers to inject arbitrary web script or HTML
via the parent's frame page title.
|
| CVE-2005-1311 |
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2005-1309 |
Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote
attackers to inject arbitrary web script or HTML via the (1)
entry title field or (2) comment body text.
|
| CVE-2005-1300 |
Cross-site scripting (XSS) vulnerability in the inserter.cgi script
allows remote attackers to inject arbitrary web script or HTML via the
argument.
|
| CVE-2005-1297 |
Cross-site scripting (XSS) vulnerability in the include.cgi script
allows remote attackers to inject arbitrary web script or HTML via the
argument.
|
| CVE-2005-1292 |
Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP
Cart allow remote attackers to inject arbitrary web script or HTML via
the idProduct parameter to (1) tellAFriend.asp or (2)
addToWishlist.asp, redirect parameter to (3) access.asp or (4)
login.asp, message parameter to (5) login.asp or (6) error.asp, or (7)
sku or (8) name parameter to searchResults.asp.
|
| CVE-2005-1291 |
Multiple SQL injection vulnerabilities in CartWIZ ASP Cart allow
remote attackers to execute arbitrary SQL commands via the idProduct
parameter to (1) addToCart.asp or (2) productDetails.asp, the (3)
priceFrom, (4) idCategory, or (5) priceTo parameter to
searchResults.asp, or (6) the idParentCategory parameter to
productCatalogSubCats.asp.
|
| CVE-2005-1290 |
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) u parameter to profile.php, (2) highlight parameter
to viewtopic.php, or (3) forumname or forumdesc parameters to
admin_forums.php.
|
| CVE-2005-1285 |
Cross-site scripting (XSS) vulnerability in thread.php in WoltLab
Burning Board 2.3.1 and earlier allows remote attackers to inject
arbitrary web script or HTML via the hilight parameter.
|
| CVE-2005-1282 |
Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail
Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web
script or HTML via (1) the src parameter in an IMG tag, (2) User
settings, or (3) Address book input boxes in the webmail interface.
|
| CVE-2005-1245 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2,
when using HTML Tidy ($wgUseTidy), allows remote attackers to inject
arbitrary web script or HTML via unknown vectors.
|
| CVE-2005-1233 |
Cross-site scripting (XSS) vulnerability in index.php in PHP Labs
proFile allows remote attackers to inject arbitrary web script or HTML
via the (1) dir or (2) file parameters.
|
| CVE-2005-1231 |
Cross-site scripting (XSS) vulnerability in the NewTerm function in
GlossaryModel.php in JAWS 0.4 allows remote attackers to inject
arbitrary web script or HTML via the (1) term or (2) description.
|
| CVE-2005-1227 |
Cross-site scripting (XSS) vulnerability in PHProjekt 4.2 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
chatroom text submission form.
|
| CVE-2005-1202 |
Multiple cross-site scripting (XSS) vulnerabilities in eGroupware
before 1.0.0.007 allow remote attackers to inject arbitrary web script
or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter
to index.php or (5) category_id parameter.
|
| CVE-2005-1189 |
Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the chat name, as demonstrated by using an IFRAME to redirect
users to other sites.
|
| CVE-2005-1188 |
Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in
Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web
script or HTML via the curPage parameter.
|
| CVE-2005-1186 |
Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com
domain to the Trusted Sites zone in Internet Explorer, which allows
systems in the domain to conduct unauthorized activities, as
demonstrated using cross-site scripting (XSS) attacks.
|
| CVE-2005-1183 |
Cross-site scripting (XSS) vulnerability in mvnForum 1.0 RC4 allows
remote attackers to inject arbitrary web script or HTML via the Search
parameter.
|
| CVE-2005-1172 |
Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine
Photo Gallery 1.3.x allows remote attackers to inject arbitrary web
script or HTML via the X-Forwarded-For parameter.
|
| CVE-2005-1171 |
Cross-site scripting (XSS) vulnerability in mod.php in the datenbank
module for phpBB allows remote attackers to inject arbitrary web
script or HTML via the id parameter.
|
| CVE-2005-1170 |
SQL injection vulnerability in mod.php in the datenbank module for
phpBB allows remote attackers to execute arbitrary SQL commands via
the id parameter.
|
| CVE-2005-1162 |
Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore
allow remote attackers to inject arbitrary web script or HTML via the
(1) sEmail parameter to owContactUs.asp, (2) bSub parameter to
owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields
in owProductDetail.asp.
|
| CVE-2005-1161 |
Multiple SQL injection vulnerabilities in OneWorldStore allow remote
attackers to execute arbitrary SQL commands via the idProduct
parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3)
idCategory parameter to owListProduct.asp, or (4) bSpecials parameter
to owListProduct.asp.
|
| CVE-2005-1146 |
** DISPUTED **
NOTE: this issue has been disputed by the vendor.
Cross-site scripting (XSS) vulnerability in the login command in
calendar.pl in CalendarScript 3.21 allows remote attackers to inject
arbitrary web script or HTML via the username parameter, a different
vulnerability than CVE-2005-1145.
|
| CVE-2005-1145 |
** DISPUTED **
NOTE: this issue has been disputed by the vendor.
Cross-site scripting (XSS) vulnerability in calendar.pl in
CalendarScript 3.20 allows remote attackers to inject arbitrary web
script or HTML via the template parameter, a different vulnerability
than CVE-2005-1146.
|
| CVE-2005-1143 |
Cross-site scripting (XSS) vulnerability in index.php in
EasyPHPCalendar before 6.2.8 allows remote attackers to inject
arbitrary web script or HTML via the yr parameter.
|
| CVE-2005-1140 |
Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows
remote attackers to inject arbitrary web script or HTML via the
comments.
|
| CVE-2005-1135 |
Cross-site scripting (XSS) vulnerability in search.php for Simple PHP
Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web
script or HTML via the q parameter.
|
| CVE-2005-1130 |
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart
allows remote attackers to inject arbitrary web script or HTML via the
pg parameter.
|
| CVE-2005-1120 |
Multiple cross-site scripting (XSS) vulnerabilities in IlohaMail
0.8.14 and earlier allow remote attackers to inject arbitrary web
script or HTML via the e-mail (1) body, (2) filename, or (3) MIME
type.
|
| CVE-2005-1118 |
Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the
RSA Authentication Agent for Web 5.2 allows remote attackers to inject
arbitrary web script or HTML via the postdata parameter.
|
| CVE-2005-1116 |
Cross-site scripting (XSS) vulnerability in the Calendar module for
phpBB allow remote attackers to inject arbitrary web script or HTML
via the start parameter to calendar_scheduler.php.
|
| CVE-2005-1115 |
Multiple cross-site scripting (XSS) vulnerabilities in Photo Album
2.0.53 module for phpBB allow remote attackers to inject arbitrary web
script or HTML via the bsid parameter to (1) album_cat.php or (2)
album_comment.php.
|
| CVE-2005-1114 |
Multiple SQL injection vulnerabilities in album_search.php in Photo
Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL
commands via the (1) mode or (2) search parameters.
|
| CVE-2005-1113 |
Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52
and earlier allow remote attackers to inject arbitrary web script or
HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3)
portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c
parameter to index.php, or (7) the article parameter to portal.php.
|
| CVE-2005-1104 |
Multiple cross-site scripting (XSS) vulnerabilities in Centra 7
allow remote attackers to inject arbitrary web script or HTML via the
(1) username, (2) first name, or (3) last name fields.
|
| CVE-2005-1102 |
Multiple cross-site scripting (XSS) vulnerabilities in
template-functions-post.php in WordPress 1.5 and earlier allow remote
attackers to execute arbitrary commands via the (1) content or (2)
title of the post.
|
| CVE-2005-1095 |
Cross-site scripting (XSS) vulnerability in main.asp for Ocean12
Membership Manager Pro 1.x allows remote attackers to inject arbitrary
web script or HTML via the page parameter.
|
| CVE-2005-1085 |
Cross-site scripting (XSS) vulnerability in the control panel in
aeDating 3.2 allows remote attackers to inject arbitrary web script or
HTML.
|
| CVE-2005-1081 |
Cross-site scripting (XSS) vulnerability in view.php in
AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary
web script or HTML via the id parameter.
|
| CVE-2005-1077 |
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x
allow remote attackers to inject arbitrary web script or HTML via (1)
cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.
|
| CVE-2005-1076 |
Cross-site scripting (XSS) vulnerability in the discussion board
functionality for WebCT Campus Edition 4.1 allows remote attackers to
inject arbitrary web script or HTML via the message field.
|
| CVE-2005-1075 |
Multiple cross-site scripting (XSS) vulnerabilities in RadScripts
RadBids Gold 2 allow remote attackers to inject arbitrary web script
or HTML via (1) the farea parameter to faq.php or the (2) cat, (3)
order, or (4) area parameters to index.php.
|
| CVE-2005-1074 |
SQL injection vulnerability in index.php for RadScripts RadBids Gold 2
allows remote attackers to execute arbitrary SQL commands via the mode
parameter.
|
| CVE-2005-1073 |
Directory traversal vulnerability in index.php for RadScripts RadBids
Gold 2 allows remote attackers to read arbitrary files via the read
parameter.
|
| CVE-2005-1072 |
Cross-site scripting (XSS) vulnerability in PunBB before 1.2.5 allows
remote attackers to inject arbitrary web script or HTML.
|
| CVE-2005-1068 |
Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier
allows remote attackers to execute arbitrary Javascript via [url]
tags.
|
| CVE-2005-1053 |
Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in
ModernBill 4.3.0 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) c_code or (2) aid parameters.
|
| CVE-2005-1050 |
The modload op in the Reviews module for PostNuke 0.760-RC3 allows
remote attackers to obtain sensitive information via an invalid id
parameter, which reveals the path in a PHP error message.
|
| CVE-2005-1049 |
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3
allow remote attackers to inject arbitrary web script or HTML via the
(1) module parameter to admin.php or (2) op parameter to user.php.
NOTE: the vendor reports that certain issues could not be reproduced
for 760 RC3, or for .750. However, the op/user.php issue exists when
the pnAntiCracker setting is disabled.
|
| CVE-2005-1048 |
SQL injection vulnerability in modules.php in PostNuke 0.760 RC3
allows remote attackers to execute arbitrary SQL statements via the
sid parameter. NOTE: the vendor reports that they could not reproduce
the issues for 760 RC3, or for .750.
|
| CVE-2005-1030 |
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction
House allow remote attackers to inject arbitrary web script or HTML
via the (1) ReturnURL, (2) password, (3) username parameter, (4)
ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to
sendpassword.asp, or (7) itemid to watchthisitem.asp.
|
| CVE-2005-1029 |
Multiple SQL injection vulnerabilities in Active Auction House allow
remote attackers to execute arbitrary SQL commands via the (1) catid,
(2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID
parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.
|
| CVE-2005-1028 |
PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive
information via a direct request to (1) index.php with the forum_admin
parameter set, (2) the Surveys module, or (3) the Your_Account module,
which reveals the path in a PHP error message.
|
| CVE-2005-1027 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x
through 7.6 allow remote attackers to inject arbitrary web script or
HTML via the (1) username parameter in the Your_Account module, (2)
avatarcategory parameter in the Your_Account module, or (3) lid
parameter in the Downloads module.
|
| CVE-2005-1024 |
modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain
sensitive information via a direct request to (1) my_headlines, (2)
userinfo, or (3) search, which reveals the path in a PHP error
message.
|
| CVE-2005-1023 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to
7.6 allow remote attackers to inject arbitrary web script or HTML via
the (1) min parameter to the Search module, (2) the categories
parameter to the FAQ module, or (3) the ltr parameter to the
Encyclopedia module. NOTE: the bid parameter issue in banners.php is
already an item in CVE-2005-1000.
|
| CVE-2005-1016 |
Cross-site scripting (XSS) vulnerability in links_add_form.asp for
MaxWebPortal 1.33 and earlier allows remote attackers to inject
arbitrary web script or HTML via a Javascript URL in a banner URL.
|
| CVE-2005-1012 |
Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows
remote attackers to inject arbitrary web script or HTML via (1) the
contenttype parameter to content.asp, (2) the title, or (3) the
description.
|
| CVE-2005-1010 |
Cross-site scripting (XSS) vulnerability in Comersus Cart 6 allows
remote attackers to inject arbitrary web script or HTML via the
account username.
|
| CVE-2005-1008 |
Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM
Forum RC3 allows remote attackers to inject arbitrary web script or
HTML via a "javascript:" URL in an IMG tag.
|
| CVE-2005-1006 |
Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO
5.1.7.0 allow remote attackers to inject arbitrary web script or HTML
via (1) the URL or (2) the user login name, which is not filtered when
the administrator views the log file.
|
| CVE-2005-1005 |
ProfitCode PayProCart 3.0 allows remote attackers to bypass
authentication and gain administrative privileges to the admin control
panel, as demonstrated via a direct request to adminshop/index.php
with hex-encoded .. sequences in the ftoedit parameter.
|
| CVE-2005-1004 |
Cross-site scripting (XSS) vulnerability in usrdetails.php in
ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary
web script or HTML via the sgnuptype parameter.
|
| CVE-2005-1003 |
Directory traversal vulnerability in index.php for ProfitCode
PayProCart 3.0 allows remote attackers to include arbitrary PHP files
via .. (dot dot) sequences in the modID parameter.
|
| CVE-2005-1000 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6
allow remote attackers to inject arbitrary web script or HTML via (1)
the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum
parameter in the TopRated and MostPopular actions in the Web_Links
module, (3) the ttitle parameter in the viewlinkdetails,
viewlinkeditorial, viewlinkcomments, and ratelink actions in the
Web_Links module, or (4) the username parameter in the Your_Account
module.
|
| CVE-2005-0995 |
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7
allow remote attackers to inject arbitrary web script or HTML via (1)
the keyword parameter to advSearch_h.asp, (2) the redirectUrl
parameter to NewCust.asp, (3) the country parameter to
storelocator_submit.asp, or (4) the error parameter to techErr.asp.
NOTE: it has been reported that storelocator_submit.asp does not exist
in ProductCart.
|
| CVE-2005-0992 |
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin
before 2.6.2-rc1 allows remote attackers to inject arbitrary web
script or HTML via the convcharset parameter.
|
| CVE-2005-0982 |
Multiple cross-site scripting (XSS) vulnerabilities in Yet Another
Forum.net 0.9.9 allow remote attackers to inject arbitrary web script
or HTML via the (1) name, (2) location, or (3) Subject field.
|
| CVE-2005-0981 |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay
Pro 2.0 allow remote attackers to inject arbitrary web script or HTML
via the (1) payment or (2) send parameter.
|
| CVE-2005-0980 |
PHP remote file inclusion vulnerability in index.php in AlstraSoft
EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by
modifying the view parameter to reference a URL on a remote web server
that contains the code.
|
| CVE-2005-0961 |
Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before
3.0.4-RC2 allows remote attackers to inject arbitrary web script or
HTML via the parent frame title.
|
| CVE-2005-0952 |
Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1
allows remote attackers to inject arbitrary web script or HTML via the
id parameter.
|
| CVE-2005-0949 |
Multiple cross-site scripting (XSS) vulnerabilities in content.asp in
Iatek PortalApp allow remote attackers to inject arbitrary web script
or HTML via the (1) contenttype or (2) keywords parameter.
|
| CVE-2005-0948 |
SQL injection vulnerability in ad_click.asp for PortalApp allows
remote attackers to execute arbitrary SQL commands via the banner_id
parameter.
|
| CVE-2005-0945 |
Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows
remote attackers to inject arbitrary web script or HTML via
onmouseover or onload events in (1) img, (2) link, or (3) mail tags.
|
| CVE-2005-0936 |
Cross-site scripting vulnerability in products1h.php in ESMI PayPal
Storefront allows remote attackers to inject arbitrary web script or
HTML via the id parameter.
|
| CVE-2005-0935 |
Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow
remote attackers to execute arbitrary SQL commands via the (1) idpages
parameter to pages.php or the (2) id2 parameter to products1.php.
|
| CVE-2005-0934 |
Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4
allow remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2005-0930 |
Cross-site scripting (XSS) vulnerability in message.php in Chatness
2.5.1 and earlier allows remote attackers to inject arbitrary web
script or HTML via (1) the user field or (2) the message parameter to
message.php.
|
| CVE-2005-0929 |
SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote
attackers to execute arbitrary SQL commands via (1) the sl parameter
to showmembers.php or (2) the photo parameter to showphoto.php.
|
| CVE-2005-0928 |
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP
Pro 5.x allow remote attackers to inject arbitrary web script or HTML
via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si
parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si
parameters to showmembers.php, or (9) the photo parameter to
slideshow.php.
|
| CVE-2005-0925 |
Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload
1.0 through 1.0.4 allows remote attackers to inject arbitrary web
script or HTML via the msg parameter.
|
| CVE-2005-0924 |
Cross-site scripting (XSS) vulnerability in Adventia E-Data 2.0 allows
remote attackers to inject arbitrary web script or HTML via a query
keyword.
|
| CVE-2005-0919 |
Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject
arbitrary web script or HTML into the chat space, which leaves other
users vulnerable to cross-site scripting (XSS) attacks.
|
| CVE-2005-0914 |
Multiple cross-site scripting (XSS) vulnerabilities in CPG Dragonfly
9.0.2.0 allow remote attackers to inject arbitrary web script or HTML
via (1) the profile parameter to index.php or (2) the cat parameter.
|
| CVE-2005-0910 |
Multiple cross-site scripting (XSS) vulnerabilities in exoops allow
remote attackers to inject arbitrary web script or HTML via (1) the
sortdays parameter to viewforum.php or (2) the viewcat parameter to
index.php.
|
| CVE-2005-0909 |
PHP remote file inclusion vulnerability in shoutact.php for TKai's
Shoutbox allows remote attackers to execute arbitrary PHP code via the
query parameter.
|
| CVE-2005-0908 |
Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft
Shopping Cart 3.0 allow remote attackers to inject arbitrary web
script or HTML via (1) the lang parameter to index.php or (2) the
searchTopCategoryID parameter to search_result.php.
|
| CVE-2005-0907 |
Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0
allow remote attackers to execute arbitrary SQL commands via (1) the
id parameter to category.php, (2) the id parameter to item.php, (3)
the lang parameter to index.php, (4) the searchQuery parameter to
search_result.php, (5) or the searchTopCategoryID parameter to
search_result.php.
|
| CVE-2005-0901 |
Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks
0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script
or HTML via the (1) catname, (2) markname, (3) comment, or (4)
category parameter.
|
| CVE-2005-0898 |
Cross-site scripting (XSS) vulnerability in downloadform.php in
E-Store Kit-2 PayPal Edition allows remote attackers to inject
arbitrary web script or HTML via the txn_id parameter.
|
| CVE-2005-0897 |
PHP remote file inclusion vulnerability in catalog.php in E-Store
Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP
code by modifying the menu and main parameters to reference a URL on a
remote web server that contains the code.
|
| CVE-2005-0896 |
Multiple cross-site scripting (XSS) vulnerabilities in review.php in
phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary
web script or HTML via the (1) subcat, (2) page, or (3) subsubcat
parameter.
|
| CVE-2005-0889 |
Cross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi
CMS 4.2.3 allows remote attackers to inject arbitrary web script or
HTML via the area parameter.
|
| CVE-2005-0888 |
Multiple cross-site scripting (XSS) vulnerabilities in
functions.inc.php for Double Choco Latte 0.9.4.3 allow remote
attackers to inject arbitrary web script or HTML via the (1) class or
(2) method name.
|
| CVE-2005-0886 |
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2
and earlier allows remote attackers to inject arbitrary web script or
HTML via an HTTP POST request.
|
| CVE-2005-0885 |
Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) Mood or (2) "Send To" fields.
|
| CVE-2005-0883 |
Multiple cross-site scripting (XSS) vulnerabilities in base.php for
DigitalHive 2.0 allow remote attackers to inject arbitrary web script
or HTML via (1) the mt parameter to the membres.php page or (2) the
-afs-1- query string to the msg.php page.
|
| CVE-2005-0881 |
Cross-site scripting (XSS) vulnerability in articles.newcomment for
Interspire ArticleLive 2005 allows remote attackers to inject
arbitrary web script or HTML via the Articleld parameter.
|
| CVE-2005-0878 |
Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3
allows remote attackers to inject arbitrary web script or HTML via the
title field of a PM (private message).
|
| CVE-2005-0873 |
Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in
Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject
arbitrary web script or HTML via the (1) desname or (2) repprod
parameter.
|
| CVE-2005-0872 |
Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in
the Topic Calendar 1.0.1 module for phpBB allows remote attackers to
inject arbitrary web script or HTML via the start parameter.
|
| CVE-2005-0870 |
Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3,
when register_globals is enabled, allow remote attackers to inject
arbitrary web script or HTML via the (1) sensor_program parameter to
index.php, (2) text[language], (3) text[template], or (4)
hide_picklist parameter to system_footer.php.
|
| CVE-2005-0863 |
Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows
remote attackers to inject arbitrary web script or HTML via (1) the
chatter parameter to regulars.php or (2) the chatter, chatter1,
chatter2, chatter3, or chatter4 parameters to register.php.
|
| CVE-2005-0857 |
Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum
0.8 and earlier allows remote attackers to inject arbitrary web script
or HTML via the img parameter.
|
| CVE-2005-0846 |
Multiple cross-site scripting (XSS) vulnerabilities in the email
auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject
arbitrary web script or HTML via the (1) message subject or (2)
message header field.
|
| CVE-2005-0845 |
Directory traversal vulnerability in the Webmail interface in
SurgeMail 2.2g3 allows remote authenticated users to write arbitrary
files or directories via a .. (dot dot) in the attach_id parameter.
|
| CVE-2005-0842 |
Cross-site scripting (XSS) vulnerability in index.php in Kayako
eSupport 2.3 allows remote attackers to inject arbitrary web script or
HTML via the (1) _i or (2) _c parameter.
|
| CVE-2005-0832 |
Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2005-0829 |
Cross-site scripting (XSS) vulnerability in setuser.php of the
Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject
arbitrary web script or HTML via the (1) user_name or (2) user_pass
parameters.
|
| CVE-2005-0818 |
Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote
attackers to inject arbitrary web script or HTML via the (1) email or
(2) Jabber parameters.
|
| CVE-2005-0802 |
Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8
through 1.1b allows remote attackers to execute arbitrary web script
or HTML via the search parameter.
|
| CVE-2005-0791 |
Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew
2.0.4-pr1, when register_globals is enabled, allows remote attackers
to inject arbitrary web script or HTML via the refresh parameter.
|
| CVE-2005-0785 |
Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB
2.0 rc1 allows remote attackers to inject arbitrary web script or HTML
via the username parameter.
|
| CVE-2005-0784 |
Multiple cross-site scripting (XSS) vulnerabilities in Phorum before
5.0.15 allow remote attackers to inject arbitrary web script or HTML
via (1) the subject line to follow.php or (2) the subject line in the
user's personal control panel.
|
| CVE-2005-0783 |
Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a
allows remote attackers to inject arbitrary web script or HTML via the
filename of an attached file.
|
| CVE-2005-0782 |
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2)
category.php for paFileDB 3.1 and earlier allows remote attackers to
inject arbitrary web script or HTML via the start parameter to
pafiledb.php.
|
| CVE-2005-0781 |
SQL injection vulnerability in (1) viewall.php and (2) category.php in
paFileDB 3.1 and earlier allows remote attackers to execute arbitrary
SQL commands via the start parameter to pafiledb.php.
|
| CVE-2005-0777 |
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP
5.0 RC3 allow remote attackers to inject arbitrary web script or HTML
via (1) the check_tags function or (2) the editbio field in the user
profile.
|
| CVE-2005-0742 |
Cross-site scripting (XSS) vulnerability in Sun Java System
Application Server 7 allows remote attackers to inject arbitrary web
script or HTML via unknown vectors.
|
| CVE-2005-0741 |
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1
allows remote attackers to inject arbitrary web script or HTML via the
username parameter in a usersrecentposts action.
|
| CVE-2005-0723 |
Cross-site scripting (XSS) vulnerability in the jumpmenu function in
functions.php for paFileDB 3.1 and earlier allows remote attackers to
inject arbitrary web script or HTML via the URL parameters, which is
not properly cleansed in the $pageurl variable, as demonstrated using
pafiledb.php.
|
| CVE-2005-0692 |
Cross-site scripting (XSS) vulnerability in fusion_core.php for
PHP-Fusion 5.x allows remote attackers to inject arbitrary web script
or HTML via a message with IMG bbcode containing character-encoded
Javascript.
|
| CVE-2005-0682 |
Cross-site scripting (XSS) vulnerability in common.inc in Drupal
before 4.5.2 allows remote attackers to inject arbitrary web script or
HTML via certain inputs.
|
| CVE-2005-0675 |
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5
allows remote attackers to inject arbitrary web script or HTML via the
(1) list or (2) frommethod parameters.
|
| CVE-2005-0674 |
Cross-site scripting (XSS) vulnerability in the News module for paBox
1.6 allows remote attackers to inject arbitrary web script or HTML via
the text hidden parameter in an HTTP POST request.
|
| CVE-2005-0673 |
Cross-site scripting (XSS) vulnerability in usercp_register.php for
phpBB 2.0.13 allows remote attackers to inject arbitrary web script or
HTML by setting the (1) allowhtml, (2) allowbbcode, or (3)
allowsmilies parameters to inject HTML into signatures for personal
messages, possibly when they are processed by privmsg.php or
viewtopic.php.
|
| CVE-2005-0670 |
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through
1.2.1b allows remote attackers to inject arbitrary web script or HTML
via (1) the new parameter to mod.php, (2) the w parameter to mod.php,
(3) the e parameter to login.php, (4) the o parameter to login.php,
and possibly other scripts.
|
| CVE-2005-0662 |
Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard
1.1.2 allows remote attackers to inject arbitrary web script or HTML
via the Avatar field.
|
| CVE-2005-0660 |
Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11
allows remote attackers to inject arbitrary web script or HTML via
certain fields, as demonstrated using the page parameter in nav.php3.
|
| CVE-2005-0656 |
Multiple cross-site scripting (XSS) vulnerabilities in auraCMS 1.5
allow remote attackers to inject arbitrary web script or HTML via the
(1) hits parameter to hits.php, (2) query parameter to index.php, or
(3) theCount parameter to counter.php.
|
| CVE-2005-0650 |
Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB
0.4.5.1 allow remote attackers to inject arbitrary web script or HTML
via (1) the pages parameter to divers.php (incorrectly referred to as
"drivers.php" by some sources), (2) in the search feature text area,
(3) forum name, (4) site name or (5) the maximum avatar size in the
option section, (5) new category or (6) new forum fields in the forum
section.
|
| CVE-2005-0649 |
Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass
cross-site scripting (XSS) protection via "hexadecimal HTML entities."
|
| CVE-2005-0648 |
Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow
remote attackers to bypass cross-site scripting (XSS) protection via
(1) "decimal HTML entities" or (2) "the \x00 symbol."
|
| CVE-2005-0645 |
Cross-site scripting (XSS) vulnerability in show.inc.php in cuteNews
1.3.6 allows remote attackers to inject arbitrary HTML, web script,
and PHP code via the (1) CLIENT-IP or (2) X-FORWARDED-FOR header in an
HTTP POST request to show_news.php.
|
| CVE-2005-0641 |
Cross-site scripting (XSS) vulnerability in the Reporter for Computer
Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote
attackers to inject arbitrary HTML or web script via the (1) name or
(2) description in a report template.
|
| CVE-2005-0629 |
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in
427BB 2.2 allow remote attackers to inject arbitrary web script or
HTML via the (1) user or (2) Avatar parameters.
|
| CVE-2005-0628 |
Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0
allow remote attackers to inject arbitrary web script or HTML via (1)
the keyword parameter in search.php or the (2) body or (3) subject of
a forum message.
|
| CVE-2005-0616 |
Multiple cross-site scripting (XSS) vulnerabilities in the Download
module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to
inject arbitrary web script or HTML via the (1) Program name, (2) File
link, (3) Author name (4) Author e-mail address, (5) File size, (6)
Version, or (7) Home page variables.
|
| CVE-2005-0606 |
Cross-site scripting (XSS) vulnerability in settings.inc.php for
CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows
remote attackers to inject arbitrary HTML or web script via the (1)
cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6)
catname, (7) search, or (8) page parameters.
|
| CVE-2005-0567 |
Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1
allow remote attackers to execute arbitrary PHP code by modifying the
(1) theme parameter to phpmyadmin.css.php or (2)
cfg[Server][extension] parameter to database_interface.lib.php to
reference a URL on a remote web server that contains the code.
|
| CVE-2005-0563 |
Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web
Access (OWA) component in Exchange Server 5.5 allows remote attackers
to inject arbitrary web script or HTML via an email message with an
encoded javascript: URL ("javAsc
ript:") in an IMG tag.
|
| CVE-2005-0549 |
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2
Documentation 1.4.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via the "View Log Files" function.
|
| CVE-2005-0548 |
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2
Documentation 1.4.4 and earlier allows remote attackers to inject
arbitrary web script or HTML via the Search function.
|
| CVE-2005-0543 |
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows
remote attackers to inject arbitrary HTML and web script via (1) the
strServer, cfg[BgcolorOne], or strServerChoice parameters in
select_server.lib.php, (2) the bg_color or row_no parameters in
display_tbl_links.lib.php, the left_font_family parameter in
theme_left.css.php, or the right_font_family parameter in
theme_right.css.php.
|
| CVE-2005-0534 |
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x
before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to
inject arbitrary web script.
|
| CVE-2005-0526 |
Multiple cross-site scripting (XSS) vulnerabilities in PBLang 4.65
allow remote attackers to inject arbitrary web script or HTML via (1)
the search string to search.php, (2) the subject of a PM, which is
processed by pm.php, or (3) the body of a PM, which is processed by
pmpshow.php.
|
| CVE-2005-0514 |
Cross-site scripting (XSS) vulnerability in Verity Ultraseek before
5.3.3 allows remote attackers to inject arbitrary HTML and web script
via search parameters.
|
| CVE-2005-0509 |
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5
implementation of ASP.NET (.Net) allow remote attackers to inject
arbitrary HTML or web script via Unicode representations for ASCII
fullwidth characters that are converted to normal ASCII characters,
including ">" and "<".
|
| CVE-2005-0495 |
Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote
attackers to inject arbitrary web script or HTML via the (1) sn1, (2)
year, or (3) page parameter to zboard.php or (4) filename to
view_image.php.
|
| CVE-2005-0487 |
Cross-site scripting (XSS) vulnerability in index.php for Kayako
ESupport 2.3.1, and possibly other versions, allows remote attackers
to inject arbitrary HTML and web script via the nav parameter.
|
| CVE-2005-0485 |
Cross-site scripting (XSS) vulnerability in comment.php for paNews
2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML
and web script via the showpost parameter.
|
| CVE-2005-0480 |
Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and
earlier allows remote attackers to inject arbitrary HTML or web script
via the login request, which is recorded in a log file but not
properly handled when the administrator views the log file.
|
| CVE-2005-0477 |
Cross-site scripting (XSS) vulnerability in the SML code for Invision
Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary
web script via (1) a signature file or (2) a message post containing
an IMG tag within a COLOR tag whose style is set to background:url.
|
| CVE-2005-0476 |
Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows
remote attackers to inject arbitrary web script or HTML by posting a
message.
|
| CVE-2005-0462 |
Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and
1.1.x allows remote attackers to inject arbitrary HTML and web script
via the f parameter.
|
| CVE-2005-0458 |
Cross-site scripting (XSS) vulnerability in contact_us.php in
osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web
script or HTML via the enquiry parameter.
|
| CVE-2005-0452 |
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft
ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject
arbitrary HTML or web script via Unicode representations for ASCII
fullwidth characters that are converted to normal ASCII characters,
including ">" and "<".
|
| CVE-2005-0445 |
Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows
remote attackers to inject arbitrary HTML or web script via the domain
name parameter (logindomain) in the login page.
|
| CVE-2005-0443 |
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the
full path for the web server or (2) conduct cross-site scripting (XSS)
attacks via an invalid language parameter, which echoes the parameter
in a PHP error message.
|
| CVE-2005-0434 |
Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5
allow remote attackers to inject arbitrary HTML or web script via (1)
the newdownloadshowdays parameter in a NewDownloads operation or (2)
the newlinkshowdays parameter in a NewLinks operation.
|
| CVE-2005-0412 |
Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows
remote attackers to inject arbitrary HTML and web script via the page
parameter.
|
| CVE-2005-0407 |
Cross-site scripting (XSS) vulnerability in Openconf 1.04, and
possibly other versions before 1.10, allows remote attackers to inject
arbitrary HTML and web script via the paper title.
|
| CVE-2005-0386 |
Cross-site scripting (XSS) vulnerability in network.cgi in mailreader
before 2.3.29 earlier allows remote attackers to inject arbitrary web
script or HTML via MIME text/enriched or text/richtext messages.
|
| CVE-2005-0381 |
Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0
allows remote attackers to inject arbitrary web script or HTML via the
members parameter.
|
| CVE-2005-0378 |
Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow
remote attackers to inject arbitrary web script or HTML via the (1)
group parameter to prefs.php or (2) url parameter to index.php.
|
| CVE-2005-0374 |
Cross-site scripting (XSS) vulnerability in Bitboard 2.5 and earlier
allows remote attackers to inject arbitrary web script or HTML via an
[img] bbcode image tag with an event such as mouseover.
|
| CVE-2005-0341 |
Apple Safari 1.2.4 does not obey the Content-type field in the HTTP
header and renders text as HTML, which allows remote attackers to
inject arbitrary web script or HTML and perform cross-site scripting
(XSS) attacks.
|
| CVE-2005-0336 |
Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web
Server 5.0 allows remote attackers to inject arbitrary HTML or web
script, as demonstrated using a URL containing .. sequences and HTML,
which results in a directory browsing page that does not properly
filter the HTML.
|
| CVE-2005-0324 |
Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain
sensitive information via an HTTP request that contains invalid
characters for a Windows foldername, which reveals the path in an
error message.
|
| CVE-2005-0323 |
Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery
Webmail 2.6 allows remote attackers to inject arbitrary web script or
HTML via the URL.
|
| CVE-2005-0319 |
Direct remote injection vulnerability in modalfram.wdm in Alt-N
WebAdmin 3.0.4 allows remote attackers to load external webpages that
appear to come from the WebAdmin server, which allows remote attackers
to inject arbitrary HTML or web script to facilitate cross-site
scripting (XSS) and phishing attacks.
|
| CVE-2005-0317 |
Cross-site scripting (XSS) vulnerability in useredit_account.wdm in
Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web
script or HTML via the user parameter.
|
| CVE-2005-0314 |
Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail
Server 4.0 Build 1112 allows remote attackers to inject arbitrary web
script or HTML via the personal information fields.
|
| CVE-2005-0309 |
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php
or (2) mod.php in Exponent 0.95 allow remote attackers to inject
arbitrary web script or HTML via the module parameter.
|
| CVE-2005-0307 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web
script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re
parameters.
|
| CVE-2005-0303 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
comersus_supportError.asp or (2)
comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and
6.01 allow remote attackers to inject arbitrary web script or HTML via
the error parameter.
|
| CVE-2005-0291 |
Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR
FVS318 running firmware 2.4, and possibly other versions, allows
remote attackers to inject arbitrary web script or HTML via a blocked
URL phrase.
|
| CVE-2005-0281 |
Cross-site scripting (XSS) vulnerability in the web interface in
Soldner Secret Wars 30830 allows remote attackers to inject arbitrary
web script or HTML via a user message, which is not filtered or quoted
when the administrator views the server logs.
|
| CVE-2005-0280 |
Format string vulnerability in Soldner Secret Wars 30830 and earlier
allows remote attackers to cause a denial of service (server crash)
and possibly execute arbitrary code via format string specifiers in a
message.
|
| CVE-2005-0279 |
Soldner Secret Wars 30830 and earlier does not properly handle the
"message too long" socket error, which allows remote attackers to
cause a denial of service (socket termination) via a long UDP packet.
|
| CVE-2005-0274 |
Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php
in PhotoPost before 4.86 allow remote attackers to inject arbitrary
web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser
parameters.
|
| CVE-2005-0270 |
Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP
Pro before 2.84 allow remote attackers to inject arbitrary web script
or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page
parameter to showproduct.php, or (4) report parameter to
reportproduct.php.
|
| CVE-2005-0266 |
Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X
allows remote attackers to inject arbitrary web script or HTML via the
(1) return_module, (2) return_action, (3) name, (4) module, or (5)
record parameter.
|
| CVE-2005-0264 |
Multiple cross-site scripting (XSS) vulnerabilities in browse.php in
OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script
or HTML via the (1) expand or (2) order parameter.
|
| CVE-2005-0251 |
Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB
1.3.2, and possibly earlier versions, allows remote attackers to
inject arbitrary HTML and web script via the search parameter.
|
| CVE-2005-0221 |
Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0
Alpha allows remote attackers to inject arbitrary web script or HTML
via the g2_form[subject] field.
|
| CVE-2005-0219 |
Multiple cross-site scripting (XSS) vulnerabilities in Gallery
1.3.4-pl1 allow remote attackers to inject arbitrary web script or
HTML via (1) the index field in add_comment.php, (2) set_albumName,
(3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7)
slide_dir fields in slideshow_low.php, or (8) username field in
search.php.
|
| CVE-2005-0216 |
Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab
Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows
remote attackers to inject arbitrary web script and HTML via the
userid parameter.
|
| CVE-2005-0104 |
Cross-site scripting (XSS) vulnerability in webmail.php in
SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary
web script or HTML via certain integer variables.
|
| CVE-2005-0085 |
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before
3.1.6-r7 allows remote attackers to execute arbitrary web script or
HTML via the config parameter, which is not properly sanitized before
it is displayed in an error message.
|
| CVE-2005-0049 |
Windows SharePoint Services and SharePoint Team Services for Windows
Server 2003 does not properly validate an HTTP redirection query,
which allows remote attackers to inject arbitrary HTML and web script
via a cross-site scripting (XSS) attack, or to spoof the web cache.
|
| CVE-2005-0040 |
Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke
before 3.0.12 allow remote attackers to inject arbitrary web script or
HTML via the (1) register a new user page, (2) User-Agent, or (3)
Username, which is not properly quoted before sending to the error
log.
|
| CVE-2004-2765 |
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE
Messaging Server 6.1 and iPlanet Messaging Server 5.2 before
5.2hf2.02, when Internet Explorer is used, allows remote attackers to
inject arbitrary web script or HTML via a crafted e-mail message, a
different vulnerability than CVE-2005-2022 and CVE-2006-5486.
|
| CVE-2004-2757 |
Cross-site scripting (XSS) vulnerability in the failed login page in
Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship
(FCS) allows remote attackers to inject arbitrary web script or HTML
via url parameter.
|
| CVE-2004-2756 |
Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops
2.x, possibly 2 through 2.0.5, allows remote attackers to inject
arbitrary web script or HTML via the (1) forum and (2) topic_id
parameters.
|
| CVE-2004-2755 |
Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5,
3.0.0, and 3.0.1 before build 62 allows remote attackers to inject
arbitrary web script or HTML via the query string in blocked URLs that
are listed in (1) error or (2) block page messages.
|
| CVE-2004-2752 |
Cross-site scripting (XSS) vulnerability in the Downloads module in
PostNuke up to 0.726, and possibly later versions, allows remote
attackers to inject arbitrary HTML and web script via the ttitle
parameter in a viewdownloaddetails action.
|
| CVE-2004-2749 |
Directory traversal vulnerability in wra/public/wralogin in 2Wire
Gateway, possibly as used in HomePortal and other product lines,
allows remote attackers to read arbitrary files via a .. (dot dot) in
the return parameter. NOTE: this issue was reported as XSS, but this
might be a terminology error.
|
| CVE-2004-2742 |
Cross-site scripting (XSS) vulnerability in the report viewer in
Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject
arbitrary web script or HTML via script in the URL to a report (RPT)
file.
|
| CVE-2004-2741 |
Cross-site scripting (XSS) vulnerability in the "help window"
(help.php) in Horde Application Framework 2.2.6 allows remote
attackers to inject arbitrary web script or HTML via the (1) module,
(2) topic, or (3) module parameters.
|
| CVE-2004-2738 |
Cross-site scripting (XSS) vulnerability in check_user_id.php in
ZeroBoard 4.1pl4 and earlier allows remote attackers to inject
arbitrary web script or HTML via the user_id parameter.
|
| CVE-2004-2735 |
Cross-site scripting (XSS) vulnerability in P4DB 2.01 and earlier
allows remote attackers to inject arbitrary web script or HTML via (1)
SET_PREFERENCES parameter in SetPreferences.cgi; (2) BRANCH parameter
in branchView.cgi; (3) FSPC and (4) COMPLETE parameters in
changeByUsers.cgi; (5) FSPC, (6) LABEL, (7) EXLABEL, (8) STATUS, (9)
MAXCH, (10) FIRSTCH, (11) CHOFFSETDISP, (12) SEARCHDESC, (13)
SEARCH_INVERT, (14) USER, (15) GROUP, and (16) CLIENT parameters in
changeList.cgi; (17) CH parameter in changeView.cgi; (18) USER
parameter in clientList.cgi; (19) CLIENT parameter in clientView.cgi;
(20) FSPC parameter in depotTreeBrowser.cgi; (21) FSPC parameter in
depotStats.cgi; (22) FSPC, (23) REV, (24) ACT, (25) FSPC2, (26) REV2,
(27) CH, and (28) CONTEXT parameters in fileDiffView.cgi; (29) FSPC
and (30) REV parameters in fileDownLoad.cgi; (31) FSPC, (32) LISTLAB,
and (33) SHOWBRANCH parameters in fileLogView.cgi; (34) FSPC and (35)
LABEL parameters in fileSearch.cgi; (36) FSPC, (37) REV, and (38)
FORCE parameters in fileViewer.cgi; (39) FSPC parameter in
filesChangedSince.cgi; (40) GROUP parameter in groupView.cgi; (41)
TYPE, (42) FSPC, and (43) REV parameters in htmlFileView.cgi; (44) CMD
parameter in javaDataView.cgi; (45) JOBVIEW and (46) FLD parameters in
jobList.cgi; (47) JOB parameter in jobView.cgi; (48) LABEL1 and (49)
LABEL2 parameters in labelDiffView.cgi; (50) LABEL parameter in
labelView.cgi; (51) FSPC parameter in searchPattern.cgi; (52) TYPE,
(53) FSPC, and (54) REV parameters in specialFileView.cgi; (55)
GROUPSONLY parameter in userList.cgi; or (56) USER parameter in
userView.cgi.
|
| CVE-2004-2725 |
Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0
allow remote attackers to inject arbitrary web script or HTML via (1)
the search parameter in (a) search.php, (2) the email parameter in (b)
subscribe.php, and (3) the return and (4) title parameters in (c)
forum_2.php.
|
| CVE-2004-2720 |
Cross-site scripting (XSS) vulnerability in register.asp in Snitz
Forums 2000 3.4.04 and earlier allows remote attackers to inject
arbitrary web script or HTML via javascript events in the Email
parameter.
|
| CVE-2004-2704 |
Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development)
does not send the "attachment" parameter in the Content-Disposition
field for attachments, which causes the attachment to be rendered
inline by Internet Explorer when the victim clicks the download link,
which facilitates cross-site scripting (XSS) and possibly other
attacks.
|
| CVE-2004-2702 |
Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0
and 7.1 Reloaded allows remote attackers to inject arbitrary web
script or HTML via the login_name parameter. NOTE: this might be the
same vector as CVE-2006-6451.
|
| CVE-2004-2701 |
Cross-site scripting (XSS) vulnerability in signin.aspx for
AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary
web script or HTML via the returnurl parameter.
|
| CVE-2004-2690 |
Unrestricted file upload vulnerability in the Administration Panel for
NewsPHP allows remote authenticated administrators to upload and
execute arbitrary code instead of video files.
|
| CVE-2004-2689 |
NewsPHP allows remote attackers to gain unauthorized administrative
access by setting a cookie to the "autorized=admin; root=admin" value.
|
| CVE-2004-2688 |
Cross-site scripting (XSS) vulnerability in index.php in NewsPHP
allows remote attackers to inject arbitrary web script or HTML via the
cat_id parameter. NOTE: this issue might overlap vector 3 in
CVE-2006-3358.
|
| CVE-2004-2670 |
Multiple cross-site scripting (XSS) vulnerabilities in mod.php in
eNdonesia 8.3 allow remote attackers to inject arbitrary web script or
HTML via (1) the mod parameter in a viewcat operation or (2) the query
parameter in a search operation in the publisher module.
|
| CVE-2004-2667 |
Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before
6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject
arbitrary web script or HTML via unknown attack vectors.
|
| CVE-2004-2656 |
Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like
Automated Storytelling Homepage (Slash) (aka Slashcode) before
R_2_5_0_41 allow remote attackers to inject arbitrary web script or
HTML via (1) the topic parameter in search.pl and (2) the filter
parameter in submit.pl.
|
| CVE-2004-2651 |
Multiple cross-site scripting (XSS) vulnerabilities in YaCy before
0.32 allow remote attackers to inject arbitrary web script or HTML via
the (1) urlmaskfilter parameter to index.html or the (2) page
parameter to Wiki.html.
|
| CVE-2004-2625 |
Cross-site scripting (XSS) vulnerability in Outblaze Email allows
remote attackers to inject arbitrary web script or HTML via Javascript
in an attribute of an IMG tag.
|
| CVE-2004-2624 |
Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki
3.5 allows remote attackers to inject arbitrary web script or HTML via
the "phrase" parameter.
|
| CVE-2004-2618 |
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS)
0.2.2 allows remote attackers to inject arbitrary web script or HTML
via the URI, directly after the initial '/' (slash).
|
| CVE-2004-2604 |
Cross-site scripting (XSS) vulnerability in index.php in PHProxy
allows remote attackers to inject arbitrary web script or HTML via the
error parameter.
|
| CVE-2004-2603 |
Cross-site scripting (XSS) vulnerability in the Search module in
UberTec Help Center Live (HCL) allows remote attackers to inject
arbitrary web script or HTML via the find parameter to index.php.
|
| CVE-2004-2585 |
Cross-site scripting (XSS) vulnerability in frmCompose.aspx in
SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers
to inject arbitrary web script or HTML via Javascript to the "check
spelling" feature in the compose area.
|
| CVE-2004-2580 |
Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows
remote attackers to obtain login credentials via unspecified vectors.
|
| CVE-2004-2574 |
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare
0.9.14.005 and earlier allows remote attackers to inject arbitrary web
script or HTML via the date parameter in a calendar.uicalendar.planner
menuaction.
|
| CVE-2004-2568 |
Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1
allow remote attackers to inject arbitrary web script or HTML via the
(1) user id, (2) recipe id, (3) category id, and (4) other ID number
fields.
|
| CVE-2004-2566 |
Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld
products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat,
and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web
script or HTML via the q parameter in (a) search.jsp, (b)
findclub!execute.jspa, and (c) search!execute.jspa.
|
| CVE-2004-2564 |
Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server
6.1 Beta 2 on Windows, and possibly other versions on Linux, allow
remote attackers to inject arbitrary web script or HTML via (1) the
show parameter in show.asp and (2) the title parameter in
showperf.asp.
|
| CVE-2004-2563 |
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive
information such as user names, versions, and database information,
and conduct cross-site scripting (XSS) attacks, via a direct request
to tmtrack.dll with modified LoginPage and Template parameters.
|
| CVE-2004-2550 |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified
Perl scripts in SandSurfer before 1.7.1 allow remote attackers to
inject arbitrary web script or HTML, which is later executed by a
target who views reports containing the injected data.
|
| CVE-2004-2548 |
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1)
SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject
arbitrary web script or HTML via (a) a URI containing the script, or
(b) the username field in the login form. NOTE: it is possible that
the first attack vector is resultant from the error message issue
(CVE-2004-2547).
|
| CVE-2004-2528 |
Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam
Watchdog 4.0.1a allows remote attackers to inject arbitrary web script
or HTML via the cam parameter.
|
| CVE-2004-2525 |
Cross-site scripting (XSS) vulnerability in compat.php in Serendipity
before 0.7.1 allows remote attackers to inject arbitrary web script or
HTML via the searchTerm variable.
|
| CVE-2004-2522 |
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server
2003 1.1.10.0 allows remote attackers to inject arbitrary web script
or HTML via the (1) template or (2) language parameter.
|
| CVE-2004-2514 |
Cross-site scripting (XSS) vulnerability in
modules/private_messages/index.php in PowerPortal 1.x allows remote
attackers to inject arbitrary web script or HTML via the (1) SUBJECT
or (2) MESSAGE field.
|
| CVE-2004-2511 |
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal
5.3.2 and earlier allow remote attackers to inject arbitrary web
script or HTML via (1) the year, (2) month, and (3) day parameters in
calendar.php; (4) the cid and (5) url parameters in index.php; (6) the
cid parameter in annoucement.php; (7) the cid parameter in news.php;
(8) the cid parameter in contents.php; (9) the q parameter in
search.php; and (10) the country parameter in register.php.
|
| CVE-2004-2510 |
Cross-site scripting (XSS) vulnerability in showflat.php in Infopop
UBB.Threads before 6.5 allows remote attackers to inject arbitrary web
script or HTML via the Cat parameter.
|
| CVE-2004-2509 |
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2)
login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5
allow remote attackers to inject arbitrary web script or HTML via the
Cat parameter.
|
| CVE-2004-2508 |
Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B
Wireless-B Internet Video Camera allows remote attackers to inject
arbitrary web script or HTML via the next_file parameter.
|
| CVE-2004-2497 |
Cross-site scripting (XSS) vulnerability in the error handler in
Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and
earlier, when using the default error template and debug mode is set
to ON, allows remote attackers to inject arbitrary web script or HTML
via unknown attack vectors.
|
| CVE-2004-2494 |
Cross-site scripting (XSS) vulnerability in _error in Ability Mail
Server 1.18 allows remote attackers to inject arbitrary web script or
HTML via the erromsg parameter.
|
| CVE-2004-2492 |
Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web
(GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote
attackers to inject arbitrary web script or HTML via the QUERY
parameter.
|
| CVE-2004-2484 |
Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5
and earlier allows remote attackers to inject arbitrary web script or
HTML via the message parameter to (1) event.php or (2) index.php.
|
| CVE-2004-2475 |
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1
allows remote attackers to inject arbitrary web script via about.html
in the About section. NOTE: some followup posts suggest that the
demonstration code's use of the res:// protocol does not cross
privilege boundaries, since it is not allowed in the Internet Zone.
Thus this might not be a vulnerability.
|
| CVE-2004-2468 |
Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the search parameter.
|
| CVE-2004-2465 |
Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat
Server 1.2 allows remote attackers to inject arbitrary web script or
HTML via the username parameter.
|
| CVE-2004-2447 |
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01
allows remote attackers to inject arbitrary web script or HTML via the
Mailbox parameter to (1) viewmail.tagz, (2) the index script under
/user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6)
list.tagz.
|
| CVE-2004-2444 |
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3
allows remote attackers to inject arbitrary web script or HTML via the
action parameter.
|
| CVE-2004-2438 |
Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows
remote attackers to inject arbitrary web script or HTML via the (1)
Submit News, (2) Submit Link or (3) Submit Article field.
|
| CVE-2004-2435 |
Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources
Management System (HRMS) 7.0, when "web enabled" using HTML Access,
allows remote attackers to inject arbitrary web script or HTML via
unspecified (1) debugging or (2) utility scripts.
|
| CVE-2004-2411 |
The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart
4.0 through 5.0 does not sufficiently cleanse inputs, which allows
remote attackers to conduct cross-site scripting (XSS) attacks that do
not use <script> tags, as demonstrated via javascript in IMG tags to
(1) the cat parameter in shopdisplayproducts.asp or (2) the msg
parameter in shoperror.asp, and possibly other vectors.
|
| CVE-2004-2403 |
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP
1.3.2 allows remote attackers to perform unauthorized actions as the
administrative user via a link or IMG tag to YaBB.pl that specifies
the desired action, id, and moda parameters.
|
| CVE-2004-2402 |
Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP
1.3.2 allows remote attackers to inject arbitrary web script or HTML
via a hex-encoded to parameter. NOTE: some sources say that the board
parameter is affected, but this is incorrect.
|
| CVE-2004-2379 |
Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for
Windows allow remote attackers to inject arbitrary web script or HTML
via (1) the Displayed Name attribute in util.pl and (2) the Folder
attribute in showmail.pl.
|
| CVE-2004-2363 |
Validate-Before-Canonicalize vulnerability in the checkURI function in
functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to
conduct cross-site scripting (XSS) attacks via hex-encoded tags, which
bypass the check for literal "<", ">", "(", and ")" characters, as
demonstrated using the limit parameter to forums.php and a variety of
other vectors.
|
| CVE-2004-2358 |
Cross-site scripting (XSS) vulnerability in admin_words.php for phpBB
2.0.6c allows remote attackers to inject arbitrary web script or HTML
via the id parameter.
|
| CVE-2004-2355 |
Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help
(CSLH) before 2.7.4 allows remote attackers to inject arbitrary web
script or HTML via the name field of a livehelp or chat session.
|
| CVE-2004-2354 |
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5
through 6.9 allows remote attackers to modify SQL statements via the
entry parameter to modules.php, which can also facilitate cross-site
scripting (XSS) attacks when MySQL errors are triggered.
|
| CVE-2004-2352 |
Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0
allows remote attackers to inject arbitrary web script or HTML via
cookies that are stored in the $_COOKIE PHP variable, which is not
cleansed by PHP-Nuke.
|
| CVE-2004-2351 |
Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0
allows remote attackers to inject arbitrary web script or HTML via
multiple parameters, including (1) name, (2) email, (3) city, and (4)
message, which do not use the <script> and <style> tags, which are
filtered by PHP-Nuke.
|
| CVE-2004-2346 |
Multiple cross-site scripting (XSS) vulnerabilities in Forum Web
Server 1.6 and earlier allow remote attackers to inject arbitrary web
script or HTML via (1) the Subject field in post1.htm and (2) the File
Description field in postfile2.htm.
|
| CVE-2004-2334 |
Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail
5.2.7 allow remote attackers to inject arbitrary web script or HTML
via (1) a hex-encoded value to the variable parameter in emumail.fcgi,
(2) the folder parameter in emumail.fcgi, or Javascript in the (3)
username or (4) password field in the login page.
|
| CVE-2004-2332 |
Multiple cross-site scripting (XSS) vulnerabilities in CPAN WWW::Form
before 1.13 allow remote attackers to inject arbitrary web script or
HTML via unknown vectors.
|
| CVE-2004-2325 |
Cross-site scripting (XSS) vulnerability in EditModule.aspx for
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows
remote attackers to inject arbitrary web script or HTML.
|
| CVE-2004-2310 |
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus
Domino R6 6.5.1 allows remote attackers to inject arbitrary web script
or HTML via a Domino command in the Quick Console.
|
| CVE-2004-2308 |
Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly
earlier allows remote attackers to inject arbitrary web script or HTML
via the dir parameter in dohtaccess.html.
|
| CVE-2004-2294 |
Canonicalize-before-filter error in the send_review function in the
Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to
inject arbitrary web script or HTML via hex-encoded XSS sequences in
the text parameter, which is checked for dangerous sequences before it
is canonicalized, leading to a cross-site scripting (XSS)
vulnerability.
|
| CVE-2004-2293 |
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to
7.3 allow remote attackers to inject arbitrary web script or HTML via
the (1) eid parameter or (2) query parameter to the Encyclopedia
module, (3) preview_review function in the Reviews module as
demonstrated by the url, cover, rlanguage, and hits parameters, or (4)
savecomment function in the Reviews module, as demonstrated using the
uname parameter. NOTE: the Faq/categories and Encyclopedia/ltr issues
are already covered by CVE-2005-1023.
|
| CVE-2004-2288 |
Cross-site scripting (XSS) vulnerability in index.php in Jelsoft
vBulletin allows remote attackers to spoof parts of a website via the
loc parameter.
|
| CVE-2004-2279 |
Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3
Final allows remote attackers to execute arbitrary script as other
users via the pop parameter in a chat action to index.php.
|
| CVE-2004-2278 |
Unknown cross-site scripting (XSS) vulnerability in the web GUI in
vHost before 3.10r1 has unknown impact and attack vectors.
|
| CVE-2004-2267 |
Cross-site scripting (XSS) vulnerability in Ansel 2.1 and earlier
allows remote attackers to inject arbitrary HTML or web script via the
album name.
|
| CVE-2004-2261 |
Cross-site scripting (XSS) vulnerability in e107 allows remote
attackers to inject arbitrary script or HTML via the "login
name/author" field in the (1) news submit or (2) article submit
functions.
|
| CVE-2004-2246 |
Cross-site scripting (XSS) vulnerability in Goollery before 0.04b
allows remote attackers to inject arbitrary HTML or web script via the
conversation_id parameter to viewpic.php.
|
| CVE-2004-2245 |
Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows
remote attackers to inject arbitrary HTML or web script via the (1)
page parameter to viewalbum.php or (2) btopage parameter to
viewpic.php.
|
| CVE-2004-2242 |
Cross-site scripting (XSS) vulnerability in search.php in Phorum,
possibly 5.0.7 beta and earlier, allows remote attackers to inject
arbitrary HTML or web script via the subject parameter.
|
| CVE-2004-2241 |
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier
allows remote attackers to inject arbitrary HTML or web script via
search.php. NOTE: some sources have reported that the affected file is
read.php, but this is inconsistent with the vendor's patch.
|
| CVE-2004-2211 |
Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0
allows remote attackers to inject arbitrary web script or HTML via the
(1) forum_id, (2) method, or (3) forum_title parameters to post.asp,
(4) the forum_title parameter to forum.asp, or (5) the id parameter to
post.asp.
|
| CVE-2004-2210 |
Multiple cross-site scripting (XSS) vulnerabilities in Express-Web
Content Management System (CMS) allow remote attackers to steal
cookie-based authentication information and possibly perform other
exploits via the (1) n, (2) b, (3) e, or (4) a parameters to
default.asp, (5) the Referer header in an HTTP request to login.asp,
or (6) the email parameter to subscribe/default.asp.
|
| CVE-2004-2207 |
Cross-site scripting (XSS) vulnerability in Ideal Science IdealBB
1.4.9 through 1.5.3 allows remote attackers to inject arbitrary web
script or HTML via unknown vectors.
|
| CVE-2004-2200 |
Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through
3.1 allows remote attackers to inject arbitrary web script or HTML via
via the message text.
|
| CVE-2004-2199 |
Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0
allows remote attackers to inject arbitrary web script or HTML via the
message text.
|
| CVE-2004-2193 |
Cross-site scripting (XSS) vulnerability in trade.php for CJOverkill
4.0.3 allows remote attackers to inject arbitrary web script or HTML
via the (1) tms[0] or (2) url parameters.
|
| CVE-2004-2192 |
SQL injection vulnerability in tttadmin/settings.php in Turbo Traffic
Trader PHP 1.0 allows remote attackers to execute arbitrary SQL
commands via the ttt_admin parameter.
|
| CVE-2004-2191 |
Cross-site scripting (XSS) vulnerability in ttt-webmaster.php in Turbo
Traffic Trader PHP 1.0 allows remote attackers to inject arbitrary web
script or HTML via the (1) msg[0] or (2) siteurl parameters.
|
| CVE-2004-2188 |
Cross-site scripting (XSS) vulnerability in DMXReady Site Chassis
Manager allows remote attackers to inject arbitrary web script or HTML
via unknown vectors.
|
| CVE-2004-2185 |
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.5
allow remote attackers to execute arbitrary scripts and/or SQL queries
via (1) the UnicodeConverter extension, (2) raw page views, (3)
SpecialIpblocklist, (4) SpecialEmailuser, (5) SpecialMaintenance, and
(6) ImagePage.
|
| CVE-2004-2180 |
Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum
1.61 allow remote attackers to inject arbitrary web script or HTML via
the (1) country parameter to view_user.php, (2) show parameter to
view_forum.php, (3) letter parameter to view_user.php, (4) highlight
parameter to view_topic.php, (5) show parameter to index.php, (6) q
parameter to search.php, (7) Referer header to admin.php, or the (8)
user_email parameter to login.php.
|
| CVE-2004-2177 |
Cross-site scripting (XSS) vulnerability in DevoyBB Web Forum 1.0.0
allows remote attackers to inject arbitrary web script or HTML via
unknown vectors.
|
| CVE-2004-2174 |
Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact
ProductCart allows remote attackers to inject arbitrary Javascript via
the redirectUrl parameter.
|
| CVE-2004-2171 |
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8
allows remote attackers to inject arbitrary web script or HTML via the
URL, which is not properly quoted in the resulting error page.
|
| CVE-2004-2162 |
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow
remote attackers to inject arbitrary web script or HTML via (1) the
search field of the Address Module or (2) the t parameter to
app_new.php.
|
| CVE-2004-2157 |
Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity
0.7 beta1, and possibly other versions before 0.7-beta3, allows remote
attackers to inject arbitrary HTML and PHP code via the (1) email or
(2) username field.
|
| CVE-2004-2152 |
Cross-site scripting (XSS) vulnerability in 'raw' page output mode for
MediaWiki 1.3.4 and earlier allows remote attackers to inject
arbitrary web script or HTML.
|
| CVE-2004-2138 |
Cross-site scripting (XSS) vulnerability in AWSguest.php in
AllWebScripts MySQLGuest allows remote attackers to inject arbitrary
HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4)
Comments field.
|
| CVE-2004-2130 |
Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in
phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML
via the (1) folder or (2) mode variables.
|
| CVE-2004-2128 |
Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows
remote attackers to execute arbitrary script as other users via the
query string to ISAPISkeleton.dll.
|
| CVE-2004-2123 |
Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com
E-Commerce ASP Engine allow remote attackers to inject arbitrary web
script or HTML via the (1) level parameter of productdetail.asp, (2)
searchKey parameter of searchresults.asp, and possibly (3) level
parameter of ListCategories.asp.
|
| CVE-2004-2122 |
Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra
Forum allows remote attackers to inject arbitrary web script or HTML
via the (1) use_last_read or (2) forum parameters.
|
| CVE-2004-2119 |
Cross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows
remote attackers to inject arbitrary web script or HTML via the URL.
|
| CVE-2004-2115 |
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP
Server 1.3.22, based on Apache, allow remote attackers to execute
arbitrary script as other users via the (1) action, (2) username, or
(3) password parameters in an isqlplus request.
|
| CVE-2004-2113 |
Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows
remote attackers to inject arbitrary web script or HTML via the URL.
|
| CVE-2004-2112 |
Directory traversal vulnerability in BremsServer 1.2.4 allows remote
attackers to read arbitrary files via ".." (dot dot) sequences in the
URL.
|
| CVE-2004-2109 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to
execute arbitrary script and steal the user session ID via Javascript
in a URL.
|
| CVE-2004-2103 |
Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise
Web Server 5.1 and 6.0 allows remote attackers to process arbitrary
script or HTML as other users via (1) a malformed request for a Perl
program with script in the filename, (2) the User.id parameter to the
webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL
request for a .bas file with script in the filename.
|
| CVE-2004-2102 |
Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified
version of thttpd, allows remote attackers to inject arbitrary web
script or HTML via the test parameter.
|
| CVE-2004-2098 |
Cross-site scripting (XSS) vulnerability in the banner engine (TBE)
5.0 allows remote attackers to execute arbitrary script as other users
via the HTML banner view/preview capability.
|
| CVE-2004-2096 |
Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0
final allows remote attackers to execute arbitrary script as other
users by injecting arbitrary HTML or script into the URL.
|
| CVE-2004-2094 |
Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows
remote attackers to inject arbitrary HTML or web script as other users
via a URL that contains the script.
|
| CVE-2004-2085 |
Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears
phpCodeCabinet 0.4 and earlier allow remote attackers to inject
arbitrary web script or HTML via multiple parameters, including (1)
the sid parameter to comments.php, (2) the cid, cf, or rfd parameters
to category.php, or the cid parameter to (3) input.php, (4)
browse.php, (5) themes/facade/header.php, or (6)
themes/phpcc/header.php.
|
| CVE-2004-2084 |
Cross-site scripting (XSS) vulnerability in search.php in JShop
E-Commerce Server allows remote attackers to inject arbitrary web
script or HTML via the xSearch parameter.
|
| CVE-2004-2076 |
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft
vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web
script or HTML via the query parameter.
|
| CVE-2004-2072 |
Cross-site scripting (XSS) vulnerability in index.php for Mambo Open
Source 4.6, and possibly earlier versions, allows remote attackers to
execute script on other clients via the Itemid parameter.
|
| CVE-2004-2064 |
Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier
allows remote attackers to inject arbitrary web script via the (1)
Email or (2) Website fields.
|
| CVE-2004-2063 |
Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard
0.7.2 and earlier allows remote attackers to inject arbitrary HTML or
web script via the feedback parameter.
|
| CVE-2004-2062 |
SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and
earlier allows remote attackers to execute arbitrary SQL via the (1)
thread_id, (2) parent_id, or (3) mode parameters.
|
| CVE-2004-2055 |
Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4
and 2.0.9 allows remote attackers to inject arbitrary HTMl or web
script via the search_author parameter.
|
| CVE-2004-2040 |
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615
allow remote attackers to inject arbitrary web script or HTML via the
(1) LAN_407 parameter to clock_menu.php, (2) "email article to a
friend" field, (3) "submit news" field, or (4) avmsg parameter to
usersettings.php.
|
| CVE-2004-2038 |
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU)
before LDU 700 allows remote attackers to inject arbitrary web script
or HTML via a BBcode img tag in (1) functions.php, (2) header.php or
(3) auth.inc.php.
|
| CVE-2004-2031 |
Cross-site scripting (XSS) vulnerability in user.php in e107 allows
remote attackers to inject arbitrary web script or HTML via the (1)
URL, (2) MSN, or (3) AIM fields.
|
| CVE-2004-2030 |
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for
Liferay before 2.2.0 release 10/1/2004 allow remote attackers to
inject arbitrary web script or HTML, as demonstrated using the message
subject.
|
| CVE-2004-2028 |
Cross-site scripting (XSS) vulnerability in stats.php in e107 allows
remote attackers to inject arbitrary web script or HTML via the
referer parameter to log.php.
|
| CVE-2004-2020 |
Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 6.x
through 7.3 allow remote attackers to inject arbitrary HTML or web
script into the (1) optionbox parameter in the News module, (2) date
parameter in the Statistics module, (3) year, month, and month_1
parameters in the Stories_Archive module, (4) mode, order, and thold
parameters in the Surveys module, or (5) a SQL statement to
index.php, as processed by mainfile.php.
|
| CVE-2004-2017 |
Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic
Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML
or web script, as demonstrated via (1) the link parameter to ttt-out,
(2) the X-Forwarded-For header in a GET request to ttt-in, (3) the
Referer header in a GET request to ttt-in, or the (4) site name or (5)
site URL fields in the main control panel.
|
| CVE-2004-2015 |
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition
allows remote attackers to inject arbitrary HTML or web script via (1)
iframe, (2) img, or (3) object tags.
|
| CVE-2004-2007 |
Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes
1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web
script via the (1) cat parameter in a CatView function or (2) jokeid
parameter in a JokeView function.
|
| CVE-2004-1999 |
Cross-site scripting (XSS) vulnerability in the Downloads module in
Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary
HTML and web script via the (1) ttitle or (2) sid parameters to
modules.php.
|
| CVE-2004-1996 |
Cross-site scripting (XSS) vulnerability in Simple Machines Forum
(SMF) 1.0 allows remote attackers to inject arbitrary web script via
the size tag.
|
| CVE-2004-1985 |
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine
Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML
or web script via the CPG_URL parameter.
|
| CVE-2004-1980 |
Directory traversal vulnerability in glossary.php in PROPS 0.6.1
allows remote attackers to view arbitrary files via a .. (dot dot) in
(1) module or (2) format variables.
|
| CVE-2004-1979 |
Cross-site scripting (XSS) vulnerability in do_search.php in PROPS
0.6.1 allows remote attackers to inject arbitrary HTML or web script
via the search_string parameter.
|
| CVE-2004-1978 |
Cross-site scripting (XSS) vulnerability in help.php in Moodle before
1.3 allows remote attackers to inject arbitrary HTML and web script
via the text parameter.
|
| CVE-2004-1975 |
Cross-site scripting (XSS) vulnerability in the category module in
pafiledb.php for paFileDB 3.1 allows remote attackers to inject
arbitrary web script or HTML via the id parameter, a vulnerability
that is closely related to CVE-2004-1551.
|
| CVE-2004-1965 |
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin
Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject
arbitrary web script or HTML via the (1) redirect parameter to
member.php, (2) to parameter to myhome.php (3) TID parameter to
post.php, or (4) redirect parameter to index.php.
|
| CVE-2004-1964 |
Cross-site scripting (XSS) vulnerability in nqt.php in Network Query
Tool (NQT) 1.6 allows remote attackers to inject arbitrary web script
or HTML via the portNum parameter.
|
| CVE-2004-1963 |
nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to
obtain sensitive information via a string in the portNum parameter,
which reveals the full path in an error message.
|
| CVE-2004-1960 |
Cross-site scripting (XSS) vulnerability in blocker_query.php in
Protector System 1.15b1 allows remote attackers to inject arbitrary
web script or HTML via the (1) target or (2) portNum parameters.
|
| CVE-2004-1957 |
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726
allows remote attackers to inject arbitrary web script or HTML via the
(1) lid and query parameters to the Downloads module, (2) query
parameter to the Web_links module, or (3) hlpfile parameter to
openwindow.php.
|
| CVE-2004-1954 |
Cross-site scripting (XSS) vulnerability in modules.php in
phProfession 2.5 allows remote attackers to inject arbitrary web
script or HTML via the jcode parameter.
|
| CVE-2004-1939 |
Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows
remote attackers to inject arbitrary web script or HTML via double
encoded slashes (%252F) in the key parameter.
|
| CVE-2004-1935 |
Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows
remote attackers to inject arbitrary web script or HTML via onload,
onmouseover, and other Javascript events in an e-mail attachment.
|
| CVE-2004-1930 |
Cross-site scripting (XSS) vulnerability in the cookiedecode function
in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used,
allows remote attackers to inject arbitrary web script or HTML via a
base64-encoded user parameter or cookie.
|
| CVE-2004-1924 |
Multiple cross-site scripting (XSS) vulnerabilities in Tiki
CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to
inject arbitrary web script or HTML via via the (1) theme parameter to
tiki-switch_theme.php, (2) find and priority parameters to
messu-mailbox.php, (3) flag, priority, flagval, sort_mode, or find
parameters to messu-read.php, (4) articleId parameter to
tiki-read_article.php, (5) parentId parameter to
tiki-browse_categories.php, (6) comments_threshold parameter to
tiki-index.php (7) articleId parameter to tiki-print_article.php, (8)
galleryId parameter to tiki-list_file_gallery.php, (9) galleryId
parameter to tiki-upload_file.php, (10) faqId parameter to
tiki-view_faq.php, (11) chartId parameter to tiki-view_chart.php, or
(12) surveyId parameter to tiki-survey_stats_survey.php.
|
| CVE-2004-1913 |
Cross-site scripting (XSS) vulnerability in modules.php in
NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to
inject arbitrary web script or HTML via the eid parameter.
|
| CVE-2004-1911 |
Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1
allows remote attackers to inject arbitrary web script or HTML via the
(1) l parameter (aka language variable) to index.php or (2) id
parameter to view.php.
|
| CVE-2004-1882 |
Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in
CactuShop 5.x allows remote attackers to inject arbitrary web script
or HTML via the strImageTag parameter.
|
| CVE-2004-1879 |
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows
allows remote attackers to inject arbitrary web script or HTML via
forum messages.
|
| CVE-2004-1875 |
Multiple cross-site scripting (XSS) vulnerabilities in cPanel
9.1.0-R85 allow remote attackers to inject arbitrary web script or
HTML via the (1) email parameter to testfile.html, (2) file parameter
to erredit.html, (3) dns parameter to dnslook.html, (4) account
parameter to ignorelist.html, (5) account parameter to showlog.html,
(6) db parameter to repairdb.html, (7) login parameter to
doaddftp.html (8) account parameter to editmsg.htm, or (9) ip
parameter to del.html. NOTE: the dnslook.html vector was later
reported to exist in cPanel 10.
|
| CVE-2004-1874 |
Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp
and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote
attackers to inject arbitrary web script or HTML via the user
information forms.
|
| CVE-2004-1872 |
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition
4.1.1.5 allows remote attackers to inject arbitrary web script or HTML
via the @import URL function in a CSS style tag.
|
| CVE-2004-1871 |
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP
Pro 4.6.x and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) ppuser, (2) password, (3) stype, (4)
perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to
showmembers.php, or the (9) photo name, (10) photo description, (11)
album name, or (12) album description fields.
|
| CVE-2004-1867 |
Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest
Book allows remote attackers to inject arbitrary web script or HTML
via the Name field.
|
| CVE-2004-1865 |
Cross-site scripting (XSS) vulnerability in the administration panel
in bBlog 0.7.2 allows remote authenticated users with superuser
privileges to inject arbitrary web script or HTML via a blog name
($blogname). NOTE: if administrators are normally allowed to add HTML
by other means, e.g. through Smarty templates, then this issue would
not give any additional privileges, and thus would not be considered a
vulnerability.
|
| CVE-2004-1863 |
Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka
extreme message board) 1.9 beta (aka Nexus beta) allow remote
attackers to inject arbitrary web script or HTML via (1) the u2uheader
parameter in editprofile.php, the restrict parameter in (2)
member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary
parameter in phpinfo.php.
|
| CVE-2004-1862 |
Multiple cross-site scripting (XSS) vulnerabilities in Extreme
Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to
inject arbitrary web script or HTML via the (1) xmbuser parameter to
xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or
latest parameter to stats.php, (4) message or icons parameter to
post.php, (5) threadlist, pagelinks, forumlist, navigation, or (6)
forumdisplay parameter to forumdisplay.php.
|
| CVE-2004-1849 |
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0
allow remote attackers to inject arbitrary web script or HTML via the
(1) email parameter to dodelautores.html or (2) handle parameter to
addhandle.html.
|
| CVE-2004-1845 |
Multiple cross-site scripting (XSS) vulnerabilities in News Manager
Lite 2.5 allow remote attackers to inject arbitrary web script or HTML
via the (1) email parameter to comment_add.asp, (2) search parameter
to search.asp, or (3) n parameter to category_news_headline.asp.
|
| CVE-2004-1844 |
Cross-site scripting (XSS) vulnerability in Member Management System
2.1 allows remote attackers to inject arbitrary web script or HTML via
(1) the err parameter to error.asp or (2) register.asp.
|
| CVE-2004-1840 |
Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis
module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary
web script or HTML via the (1) screen parameter to modules.php, (2)
module_name parameter to title.php, (3) sortby parameter to
modules.php, or (4) overview parameter to modules.php.
|
| CVE-2004-1837 |
Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before
3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to
inject arbitrary web script or HTML via the certain survey fields or
error messages for malformed query strings.
|
| CVE-2004-1829 |
Multiple cross-site scripting (XSS) vulnerabilities in error.php in
Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to
inject arbitrary web script or HTML via the (1) pagetitle or (2) error
parameters, or (3) certain parameters in the error log.
|
| CVE-2004-1827 |
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and
YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web
script via the background:url property in (1) glow or (2) shadow tags.
|
| CVE-2004-1825 |
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open
Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject
arbitrary web script or HTML via the (1) return or (2)
mos_change_template parameters.
|
| CVE-2004-1824 |
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before
3.0 allows remote attackers to inject arbitrary web script or HTML via
the what parameter to memberlist.php.
|
| CVE-2004-1823 |
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft
vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to
inject arbitrary web script or HTML via the (1) page parameter to
showthread.php or (2) order parameter to forumdisplay.php.
|
| CVE-2004-1822 |
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1
through 5.0.3 beta allow remote attackers to inject arbitrary web
script or HTML via the (1) HTTP_REFERER parameter to login.php, (2)
HTTP_REFERER parameter to register.php, or (3) target parameter to
profile.php.
|
| CVE-2004-1818 |
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum
0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute
arbitrary script as other users by injecting arbitrary script into the
z parameter.
|
| CVE-2004-1817 |
Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke
7.1.0 allows remote attackers to inject arbitrary web script or HTML
via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4)
fname parameter, (5) ratenum parameter, or (6) search field.
|
| CVE-2004-1809 |
Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier
allows remote attackers to inject arbitrary web script or HTML via the
(1) postdays parameter to viewtopic.php or (2) topicdays parameter to
viewforum.php.
|
| CVE-2004-1807 |
Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore
5.0 allows remote attackers to inject arbitrary web script or HTML via
the URL.
|
| CVE-2004-1797 |
Cross-site scripting (XSS) vulnerability in search.php for FreznoShop
1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web
script or HTML via the search parameter.
|
| CVE-2004-1794 |
Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows
remote attackers to inject arbitrary web script or HTML via the
NICKNAME tag in a vCard.
|
| CVE-2004-1790 |
Cross-site scripting (XSS) vulnerability in the web management
interface in Edimax AR-6004 ADSL Routers allows remote attackers to
inject arbitrary web script or HTML via the URL.
|
| CVE-2004-1789 |
Cross-site scripting (XSS) vulnerability in the web management
interface in ZyWALL 10 4.07 allows remote attackers to inject
arbitrary web script or HTML via the rpAuth_1 page.
|
| CVE-2004-1779 |
Cross-site scripting (XSS) vulnerability in board.php for ThWboard
before beta 2.84 allows remote attackers to inject arbitrary web
script or HTML via the lastvisited parameter.
|
| CVE-2004-1747 |
Cross-site scripting (XSS) vulnerability in NetworkEverywhere NR041
running firmware 1.2 Release 03 allows remote attackers to inject
arbitrary web script or HTML via the DHCP HOSTNAME option.
|
| CVE-2004-1746 |
Cross-site scripting (XSS) vulnerability in index.php in PHP Code
Snippet Library allows remote attackers to inject arbitrary web script
or HTML via the (1) cat_select or (2) show parameters.
|
| CVE-2004-1738 |
Cross-site scripting (XSS) vulnerability in page.php in JShop allows
remote attackers to inject arbitrary web script or HTML via the xPage
parameter.
|
| CVE-2004-1735 |
Cross-site scripting (XSS) vulnerability in the create list option in
Sympa 4.1.x and earlier allows remote authenticated users to inject
arbitrary web script or HTML via the description field.
|
| CVE-2004-1730 |
Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows
remote attackers to inject arbitrary web script or HTML via (1) the
return parameter to login_page.php, (2) e-mail field in signup.php,
(3) action parameter to login_select_proj_page.php, or (4) hide_status
parameter to view_all_set.php.
|
| CVE-2004-1729 |
Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6
allows remote attackers to inject arbitrary web script or HTML via the
User-Agent HTTP header.
|
| CVE-2004-1719 |
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail
Server 5.2.7 allow remote attackers to inject arbitrary web script or
HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5)
showgroups, (6) or showlite parameters to address.html, or the (7)
spage or (8) autoresponder parameters to settings.html, the (9) folder
parameter to readmail.html, or the (10) attachmentpage_text_error
parameter to attachment.html, (11) folder, (12) ct, or (13) cv
parameters to calendar.html, (14) an <img> tag, or (15) the subject of
an e-mail message.
|
| CVE-2004-1716 |
Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows
remote attackers to inject arbitrary web script or HTML via the (1)
IRC Server or (2) AIM ID fields in the user profile.
|
| CVE-2004-1712 |
Cross-site scripting (XSS) vulnerability in TypePad allows remote
attackers to inject arbitrary Javascript via the name parameter.
|
| CVE-2004-1711 |
Cross-site scripting (XSS) vulnerability in post.php in Moodle before
1.3 allows remote attackers to inject arbitrary web script or HTML via
the reply parameter.
|
| CVE-2004-1700 |
Cross-site scripting (XSS) vulnerability in SettingsBase.php in
Pinnacle ShowCenter 1.51 build 121 allows remote attackers to inject
arbitrary HTML or web script via the Skin parameter, which is echoed
in an error message.
|
| CVE-2004-1692 |
Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5
(1.0.9) allows remote attackers to inject arbitrary web script or HTML
via the (1) Itemid, (2) mosmsg, or (3) limit parameters.
|
| CVE-2004-1690 |
Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me
3.0.0.4 allows remote attackers to execute arbitrary web script or
HTML via the URL.
|
| CVE-2004-1669 |
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5
with Icewarp Web Mail 5.2.7 and possibly other versions allows remote
attackers to execute arbitrary web script or HTML via the (1) User
name parameter to accountsettings.html or (2) Search string parameter
to search.html.
|
| CVE-2004-1665 |
Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1
allows remote attackers to inject arbitrary web script or HTML via the
no parameter.
|
| CVE-2004-1659 |
Cross-site scripting (XSS) vulnerability in index.php in CuteNews
1.3.6 and earlier allows remote attackers with Administrator, Editor,
Journalist or Commenter privileges to inject arbitrary web script or
HTML via the mod parameter.
|
| CVE-2004-1657 |
Cross-site scripting (XSS) vulnerability in the Activity and Events
Viewer for Newtelligence DasBlog allows remote attackers to inject
arbitrary web script or HTML via the (1) User Agent or (2) Referrer
HTTP headers.
|
| CVE-2004-1655 |
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and
earlier allows remote attackers to inject arbitrary web script or HTML
via the (1) CM_pid parameter in the comments module or (2) the subject
or message fields in the notes module.
|
| CVE-2004-1651 |
Multiple cross-site scripting (XSS) vulnerabilities in the
registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to
inject arbitrary web script or HTML via the (1) Name or (2) Lastname
fields during new user registration, or (3) the Schedule Name field.
|
| CVE-2004-1648 |
Cross-site scripting (XSS) vulnerability in (1) index.asp, (2)
ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in
Password Protect allows remote attackers to inject arbitrary web
script or HTML via the ShowMsg parameter.
|
| CVE-2004-1647 |
SQL injection vulnerability in Password Protect allows remote
attackers to execute arbitrary SQL statements and bypass
authentication via (1) admin or Pass parameter to index_next.asp, (2)
LoginId, OPass, or NPass to CPassChangePassword.asp, (3)
users_edit.asp, or (4) users_add.asp.
|
| CVE-2004-1645 |
Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote
attackers to execute arbitrary web script or HTML via the (1) username
parameter to test.x, (2) username parameter to TestServer.x, or (3)
param parameter to testgetrequest.x.
|
| CVE-2004-1640 |
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and
1.0 allow remote attackers to execute arbitrary web script and HTML
via the (1) terme parameter to search.php or (2) letter parameter to
letter.php.
|
| CVE-2004-1632 |
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8
and earlier allows remote attackers to inject arbitrary web script or
HTML via the arguments to wiki.php.
|
| CVE-2004-1630 |
Cross-site scripting (XSS) vulnerability in the login form in Open
WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute
arbitrary web script or HTML via the url parameter.
|
| CVE-2004-1621 |
** DISPUTED **
NOTE: this issue has been disputed by the vendor.
Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and
Domino R6, and possibly earlier versions, allows remote attackers to
execute arbitrary web script or HTML via square brackets at the
beginning and end of (1) computed for display, (2) computed when
composed, or (3) computed text element fields. NOTE: the vendor has
disputed this issue, saying that it is not a problem with Notes/Domino
itself, but with the applications that do not properly handle this
feature.
|
| CVE-2004-1599 |
Cross-site scripting (XSS) vulnerability in index.php in CoolPHP
1.0-stable allows remote attackers to execute arbitrary web script or
HTML via the (1) query or (2) nick parameters.
|
| CVE-2004-1594 |
Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote
attackers to execute arbitrary web script via an img src tag.
|
| CVE-2004-1593 |
Cross-site scripting (XSS) vulnerability in
render.UserLayoutRootNode.uP in SCT Campus Pipeline allows remote
attackers to inject arbitrary web script or HTML via the utf
parameter.
|
| CVE-2004-1589 |
Cross-site scripting (XSS) vulnerability in GoSmart Message Board
allows remote attackers to execute inject web script or HTML via the
(1) Category parameter to Forum.asp or (2) MainMessageID parameter to
ReplyToQuestion.asp.
|
| CVE-2004-1578 |
Cross-site scripting (XSS) vulnerability in index.php in Invision
Power Board 2.0.0 allows remote attackers to execute arbitrary web
script or HTML via the Referer field in the HTTP header.
|
| CVE-2004-1566 |
Cross-site scripting (XSS) vulnerability in index.php in Silent Storm
Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web
script or HTML via the module parameter.
|
| CVE-2004-1563 |
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow
remote attackers to execute arbitrary web script or HTML via the (1)
thread parameter to download_thread.php, (2) loginuser parameter to
login.php, or (3) userid parameter to forgot_password.php.
|
| CVE-2004-1559 |
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2
allow remote attackers to inject arbitrary web script or HTML via the
(1) redirect_to, text, popupurl, or popuptitle parameters to
wp-login.php, (2) redirect_url parameter to admin-header.php, (3)
popuptitle, popupurl, content, or post_title parameters to
bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s
parameter to edit.php, or (6) s or mode parameter to
edit-comments.php.
|
| CVE-2004-1551 |
Cross-site scripting (XSS) vulnerability in the (1) email or (2) file
modules in paFileDB 3.1 Final allows remote attackers to execute
arbitrary web script or HTML via the id parameter.
|
| CVE-2004-1544 |
Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki
2.1.120-cvs and earlier allows remote attackers to execute arbitrary
web script as other users via the query parameter.
|
| CVE-2004-1538 |
SQL injection vulnerability in include.php in PHPKIT 1.6.03 through
1.6.1 allows remote attackers to execute arbitrary SQL commands via
the id parameter.
|
| CVE-2004-1537 |
Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03
through 1.6.1 allows remote attackers to execute arbitrary web script
via the img parameter.
|
| CVE-2004-1529 |
Cross-site scripting (XSS) vulnerability in the Event Calendar module
2.13 for PHP-Nuke allows remote attackers to execute arbitrary web
script via the (1) type, (2) day, (3) month, or (4) year parameters in
a Preview operation, or (5) event comments.
|
| CVE-2004-1512 |
Cross-site scripting (XSS) vulnerability in Response_default.html in
04WebServer 1.42 allows remote attackers to execute arbitrary web
script or HTML via script code in the URL, which is not quoted in the
resulting default error page.
|
| CVE-2004-1506 |
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar
allow remote attackers to inject arbitrary web script via (1)
view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5)
trailer.php, or (6) styles.php, as demonstrated using img srg tags.
|
| CVE-2004-1499 |
Cross-site scripting (XSS) vulnerability in the compose message form
in HELM 3.1.19 and earlier allows remote attackers to execute
arbitrary web script or HTML via the Subject field.
|
| CVE-2004-1498 |
SQL injection vulnerability in the compose message form in HELM 3.1.19
and earlier allows remote attackers to execute arbitrary SQL commands
via the messageToUserAccNum parameter.
|
| CVE-2004-1477 |
Cross-site scripting (XSS) vulnerability in the Management Console in
JRun 4.0 allows remote attackers to execute arbitrary web script or
HTML and possibly hijack a user's session.
|
| CVE-2004-1467 |
Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare
1.0.00.003 and earlier allow remote attackers to inject arbitrary web
script or HTML via (1) date or search text field in the calendar
module, (2) Field parameter, Filter parameter, QField parameter, Start
parameter or Search field in the address module, (3) Subject field in
the message module or (4) Subject field in the Ticket module.
|
| CVE-2004-1443 |
Cross-site scripting (XSS) vulnerability in the inline MIME viewer in
Horde-IMP (Internet Messaging Program) 3.2.4 and earlier, when used
with Internet Explorer, allows remote attackers to inject arbitrary
web script or HTML via an e-mail message.
|
| CVE-2004-1442 |
Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in
IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web
script or HTML via a macro filename, which is not properly handled by
error messages such as "DTWP001E."
|
| CVE-2004-1441 |
Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power
2.04PF allows remote attackers to inject arbitrary web script or HTML
via the action parameter.
|
| CVE-2004-1424 |
Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2
and earlier allows remote attackers to inject arbitrary web script or
HTML via the search parameter.
|
| CVE-2004-1420 |
Multiple cross-site scripting (XSS) vulnerabilities in header.php in
WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) site_title or (2) http_images
parameter.
|
| CVE-2004-1418 |
Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and
earlier allows remote attackers to inject arbitrary web script or HTML
via an e-mail address, which is not quoted when a parsing error is
generated.
|
| CVE-2004-1417 |
Cross-site scripting (XSS) vulnerability in login.php in PsychoStats
2.2.4 Beta and earlier allows remote attackers to inject arbitrary web
script or HTML via the login parameter.
|
| CVE-2004-1412 |
Cross-site scripting (XSS) vulnerability in index.php in Kayako
eSupport 2.x allows remote attackers to inject arbitrary web script or
HTML via the searchm parameter.
|
| CVE-2004-1410 |
Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and
earlier allows remote attackers to inject arbitrary web script via a
URL, which is echoed in a popup window that displays a parsing error
message, a different vulnerability than CVE-2004-1229.
|
| CVE-2004-1397 |
Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows
remote attackers to inject arbitrary web script or HTML via an
argument to wiki.pl.
|
| CVE-2004-1384 |
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare
0.9.16.003 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5)
pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9)
fldball[acctnum] parameters to index.php or (10) ticket_id to
viewticket_details.php.
|
| CVE-2004-1341 |
Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9
allows remote attackers to inject arbitrary web script or HTML via the
arguments to info2www.
|
| CVE-2004-1318 |
Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu
2.0.13 and earlier allows remote attackers to inject arbitrary HTML
and web script via a query that starts with a tab ("%09") character,
which prevents the rest of the query from being properly sanitized.
|
| CVE-2004-1213 |
Cross-site scripting (XSS) vulnerability in index.php in Advanced
Guestbook 2.3.1, 2.2, and possibly other versions allows remote
attackers to inject arbitrary web script or HTML via the entry
parameter.
|
| CVE-2004-1210 |
Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop
1.4.1 and possibly other versions, allows remote attackers to inject
arbitrary web script or HTML via the (1) url or (2) part variables.
|
| CVE-2004-1203 |
parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug
modes enabled, allows remote attackers to gain sensitive information
via an invalid file parameter, which reveals the web server's
installation path.
|
| CVE-2004-1202 |
Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1
and earlier, with non-stealth and debug modes enabled, allows remote
attackers to inject arbitrary web script or HTML via the file
parameter.
|
| CVE-2004-1197 |
Cross-site scripting (XSS) vulnerability in inshop.pl in Insite inShop
allows remote attackers to inject arbitrary web script or HTML via the
screen parameter.
|
| CVE-2004-1196 |
Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail
allows remote attackers to inject arbitrary web script or HTML via the
acao parameter.
|
| CVE-2004-1177 |
Cross-site scripting (XSS) vulnerability in the driver script in
mailman before 2.1.5 allows remote attackers to inject arbitrary web
script or HTML via a URL, which is not properly escaped in the
resulting error page.
|
| CVE-2004-1146 |
Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and
(2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject
arbitrary HTML and web script.
|
| CVE-2004-1133 |
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who
ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and
web script via (1) HTTP headers such as "Connection" or (2) invalid
parameters whose values are echoed in the resulting error message.
|
| CVE-2004-1130 |
Cross-site scripting (XSS) vulnerability in admin.asp in CMailServer
5.2 allows remote attackers to execute arbitrary web script or HTML
via personal information fields, such as (1) username, (2) name, or
(3) comments.
|
| CVE-2004-1106 |
Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and
earlier allows remote attackers to execute arbitrary web script or
HTML via "specially formed URLs," possibly via the include parameter
in index.php.
|
| CVE-2004-1101 |
mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions,
allows remote attackers to cause a denial of service (server crash),
leak sensitive pathname information in the resulting error message,
and execute a cross-site scripting (XSS) attack via an HTTP request
that contains a / (backslash) and arbitrary webscript before the
requested file, which leaks the pathname and does not quote the script
in the resulting Visual Basic error message.
|
| CVE-2004-1100 |
Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost
5.1.1sv, and possibly earlier versions, when debug mode is enabled,
allows remote attackers to execute arbitrary web script or HTML via
the append parameter.
|
| CVE-2004-1075 |
Cross-site scripting (XSS) vulnerability in standard_error_message.dtml
for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject
arbitrary HTML and web script via a malformed URL, which is not
properly cleansed when generating an error message.
|
| CVE-2004-1062 |
Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2
allow remote attackers to inject arbitrary HTML and web script via
certain error messages.
|
| CVE-2004-1061 |
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18,
including 2.16.x before 2.16.11, allows remote attackers to inject
arbitrary HTML and web script via forced error messages, as
demonstrated using the action parameter.
|
| CVE-2004-1059 |
Multiple cross-site scripting (XSS) vulnerabilities in mnoGoSearch
3.2.26 and earlier allow remote attackers to inject arbitrary HTML and
web script via the (1) next and (2) prev result search pages, and the
(3) extended and (4) simple search forms.
|
| CVE-2004-1055 |
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin
2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web
script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows
parameter in read_dump.php, (3) the confirm form, or (4) an error
message generated by the internal phpMyAdmin parser.
|
| CVE-2004-1036 |
Cross-site scripting (XSS) vulnerability in the decoding of encoded
text in certain headers in mime.php for SquirrelMail 1.4.3a and
earlier, and 1.5.1-cvs before 23rd October 2004, allows remote
attackers to execute arbitrary web script or HTML.
|
| CVE-2004-0875 |
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware
(aka webdistro) 0.9.16.002 and earlier allow remote attackers to
insert arbitrary HTML or web script, as demonstrated with a request to
the wiki module.
|
| CVE-2004-0787 |
Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA
0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote
attackers to inject arbitrary web script or HTML via the form input
fields.
|
| CVE-2004-0781 |
Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast
internal web server (icecast-server) 1.3.12 and earlier allows remote
attackers to inject arbitrary web script via the UserAgent parameter.
|
| CVE-2004-0731 |
Cross-site scripting (XSS) vulnerability in index.php in the Search
module for Php-Nuke allows remote attackers to inject arbitrary script
as other users via the input field.
|
| CVE-2004-0730 |
Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8
allow remote attackers to inject arbitrary web script or HTML via (1)
the cat_title parameter in index.php, (2) the faq[0][0] parameter in
lang_faq.php as accessible from faq.php, or (3) the faq[0][0]
parameter in lang_bbcode.php as accessible from faq.php.
|
| CVE-2004-0729 |
PhpBB 2.0.8 allows remote attackers to gain sensitive information via
an invalid (1) category_rows parameter to index.php, (2) faq parameter
to faq.php, or (3) ranksrow parameter to profile.php, which reveal the
full path in an error message.
|
| CVE-2004-0725 |
Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2
and 1.4 dev allows remote attackers to inject arbitrary web script or
HTML via the file parameter.
|
| CVE-2004-0705 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4)
editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in
Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote
attackers to execute arbitrary JavaScript as other users via a URL
parameter.
|
| CVE-2004-0681 |
Multiple cross-site scripting (XSS) vulnerabilities in (1)
comersus_customerAuthenticateForm.asp, (2)
comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4)
comersus_message.asp in Comersus Cart 5.09 allow remote attackers to
execute web script as other users via the message parameter.
|
| CVE-2004-0678 |
Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in
12Planet Chat Server 2.9 allows remote attackers to execute arbitrary
script as other users via the page parameter.
|
| CVE-2004-0675 |
Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2)
c32web.exe in Cart32 shopping cart allows remote attackers to execute
arbitrary web script via the cart32 parameter to a GetLatestBuilds
command.
|
| CVE-2004-0673 |
Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server
3.4.9 allows remote attackers to execute arbitrary web script as other
users via an invalid request that is echoed in the resulting error
message.
|
| CVE-2004-0672 |
Multiple cross-site scripting (XSS) vulnerabilities in the primary and
management web interfaces in Netegrity IdentityMinder Web Edition 5.6
allows remote attackers to execute script as other users via (1)
script that starts with %00 in the numOfExpressions parameter or (2)
the mobjtype parameter.
|
| CVE-2004-0663 |
Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal
1.x allows remote attackers to inject arbitrary script or HTML via the
(1) id parameter to the (a) private_messages module; (2) search
parameter to the (b) links and (c) content modules; and (3) files
parameter to the gallery module.
|
| CVE-2004-0660 |
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2)
show_news.php, and possibly other php files in CuteNews 1.3.1 allows
remote attackers to inject arbitrary script or HTML via the id
parameter.
|
| CVE-2004-0639 |
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail
1.2.10 and earlier allow remote attackers to inject arbitrary HTML or
script via (1) the $mailer variable in read_body.php, (2) the
$senderNames_part variable in mailbox_display.php, and possibly other
vectors including (3) the $event_title variable or (4) the $event_text
variable.
|
| CVE-2004-0620 |
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2)
newthread.php in vBulletin 3.0.1 allows remote attackers to inject
arbitrary HTML or script as other users via the Edit-panel.
|
| CVE-2004-0617 |
Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows
remote attackers to inject arbitrary script or HTML via the rawURL
parameter.
|
| CVE-2004-0615 |
Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router
running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2,
and DI-624, allows remote attackers to inject arbitrary script or HTML
via the DHCP HOSTNAME option in a DHCP request.
|
| CVE-2004-0606 |
Cross-site scripting (XSS) vulnerability in Infoblox DNS One running
firmware 2.4.0-8 and earlier allows remote attackers to execute
arbitrary scripts as other users via the (1) CLIENTID or (2)
HOSTNAME option of a DHCP request.
|
| CVE-2004-0595 |
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to
5.0.0RC3, does not filter null (\0) characters within tag names when
restricting input to allowed tags, which allows dangerous tags to be
processed by web browsers such as Internet Explorer and Safari, which
ignore null characters and facilitate the exploitation of cross-site
scripting (XSS) vulnerabilities.
|
| CVE-2004-0591 |
Cross-site scripting (XSS) vulnerability in the print_header_uc
function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows
remote attackers to inject arbitrary web script or HRML via (1) e-mail
headers or (2) a message with a "message/delivery-status" MIME
Content-Type.
|
| CVE-2004-0588 |
Cross-site scripting (XSS) vulnerability in the web mail module for
Usermin 1.070 allows remote attackers to insert arbitrary HTML and
script via e-mail messages.
|
| CVE-2004-0584 |
Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a
"security fix," does not properly validate input, which allows remote
attackers to execute arbitrary script as other users via script or
HTML in an e-mail message, possibly triggering a cross-site scripting
(XSS) vulnerability.
|
| CVE-2004-0534 |
Cross-site scripting (XSS) vulnerability in Business Objects InfoView
5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows
remote attackers to inject arbitrary web script or HTML via document
names when uploading a document.
|
| CVE-2004-0520 |
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail
before 1.4.3 allows remote attackers to insert arbitrary HTML and
script via the content-type mail header, as demonstrated using
read_body.php.
|
| CVE-2004-0519 |
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail
1.4.2 allow remote attackers to execute arbitrary script as other
users and possibly steal authentication information via multiple
attack vectors, including the mailbox parameter in compose.php.
|
| CVE-2004-0379 |
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft
SharePoint Portal Server 2001 allow remote attackers to process
arbitrary web content and steal cookies via certain server scripts.
|
| CVE-2004-0359 |
Cross-site scripting (XSS) vulnerability in index.php for Invision
Power Board 1.3 final allows remote attackers to execute arbitrary
script as other users via the (1) c, (2) f, (3) showtopic, (4)
showuser, or (5) username parameters.
|
| CVE-2004-0358 |
Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro
1.0.3 allows remote attackers to execute arbitrary script as other
users via (1) the mainnews parameter in admin.php, (2) the expand
parameter in admin.php, (3) the id parameter in admin.php, (4) the
catid parameter in admin.php, or (5) an unnamed parameter during the
newslogo_upload action in admin.php.
|
| CVE-2004-0347 |
Cross-site scripting (XSS) vulnerability in delhomepage.cgi in
NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797)
allows remote authenticated users to execute arbitrary script as other
users via the row parameter.
|
| CVE-2004-0339 |
Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB,
possibly 2.0.6c and earlier, allows remote attackers to execute
arbitrary script or HTML as other users via the postorder parameter.
|
| CVE-2004-0337 |
Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro
allows remote attackers to execute arbitrary script or HTML as other
users via a URL to index.html, followed by a / (slash) and the desired
script. NOTE: the vendor states that this bug could not be
reproduced, so this issue may be REJECTed in the future.
|
| CVE-2004-0322 |
Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final
SP2 allow remote attackers to execute arbitrary script as other users
via the (1) member parameter in member.php, (2) uid parameter in
u2uadmin.php, (3) user parameter in editprofile.php, (4) an
onmouseover event in an align tag when bbcode is allowed, or (5) img
tag where bbcode is allowed.
|
| CVE-2004-0319 |
Cross-site scripting (XSS) vulnerability in the font tag in ezBoard
7.3u allows remote attackers to execute arbitrary script as other
users, as demonstrated using the background:url in a (1) font color or
(2) font face argument.
|
| CVE-2004-0314 |
Cross-site scripting (XSS) vulnerability in done.jsp in WebzEdit 1.9
and earlier allows remote attackers to execute arbitrary script as
other users via the message parameter.
|
| CVE-2004-0310 |
Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1
allows remote attackers to execute Javascript as other users via the
stylesheet, which does not strip the semicolon or parentheses, as
demonstrated using a background:url.
|
| CVE-2004-0305 |
Cross-site scripting (XSS) vulnerability in error.asp in WebCortex
WebStores 2000 6.0 allows remote attackers to execute arbitrary script
as other users and steal session IDs via the Message_id parameter.
|
| CVE-2004-0301 |
Cross-site scripting (XSS) vulnerability in more.php for Online Store
Kit 3.0 allows remote attackers to inject arbitrary HTML via the id
parameter.
|
| CVE-2004-0272 |
SQL injection vulnerability in MaxWebPortal allows remote attackers to
inject arbitrary SQL code and gain sensitive information via the
SendTo parameter in Personal Messages.
|
| CVE-2004-0271 |
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal
allow remote attackers to execute arbitrary web script as other users
via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo
parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or
(4) the image name of an Avatar in the register form.
|
| CVE-2004-0265 |
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke
6.x-7.1.0 allows remote attackers to execute arbitrary script as other
users via URL-encoded (1) title or (2) fname parameters in the News or
Reviews modules.
|
| CVE-2004-0259 |
The check_referer() function in Formmail.php 5.0 and earlier allows
remote attackers to bypass access restrictions via an empty or spoofed
HTTP Referer, as demonstrated using an application on the same web
server that contains a cross-site scripting (XSS) issue.
|
| CVE-2004-0254 |
Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x
allows remote attackers to execute arbitrary script as other users via
an img tag.
|
| CVE-2004-0251 |
Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote
attackers to execute arbitrary script as other users via the query
parameter.
|
| CVE-2004-0248 |
Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote
attackers to execute arbitrary script as other users by injecting
arbitrary HTML or script into (1) keywords argument of main.inc.php,
(2) body argument of help.inc.php, or (3) the subject field in
Personal Messages and Forum.
|
| CVE-2004-0203 |
Cross-site scripting (XSS) vulnerability in Outlook Web Access for
Exchange Server 5.5 Service Pack 4 allows remote attackers to insert
arbitrary script and spoof content in HTML email or web caches via an
HTML redirect query.
|
| CVE-2004-0192 |
Cross-site scripting (XSS) vulnerability in the Management Service for
Symantec Gateway Security 2.0 allows remote attackers to steal cookies
and hijack a management session via a /sgmi URL that contains
malicious script, which is not quoted in the resulting error page.
|
| CVE-2004-0191 |
Mozilla before 1.4.2 executes Javascript events in the context of a
new page while it is being loaded, allowing it to interact with the
previous page (zombie document) and enable cross-domain and cross-site
scripting (XSS) attacks, as demonstrated using onmousemove events.
|
| CVE-2004-0091 |
** DISPUTED **
NOTE: this issue has been disputed by the vendor.
Cross-site scripting (XSS) vulnerability in register.php for unknown
versions of vBulletin allows remote attackers to inject arbitrary HTML
or web script via the reg_site (or possibly regsite) parameter. NOTE:
the vendor has disputed this issue, saying "There is no hidden field
called 'reg_site', nor any $reg_site variable anywhere in the
vBulletin 2 or vBulletin 3 source code or templates, nor has it ever
existed. We can only assume that this vulnerability was found in a
site running code modified from that supplied by Jelsoft."
|
| CVE-2004-0067 |
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView
before 2.65 allow remote attackers to inject arbitrary HTML or web
script via (1) descendancy.php, (2) index.php, (3) individual.php, (4)
login.php, (5) relationship.php, (6) source.php, (7) imageview.php,
(8) calendar.php, (9) gedrecord.php, (10) login.php, and (11)
gdbi_interface.php. NOTE: some aspects of vector 10 were later
reported to affect 4.1.
|
| CVE-2004-0046 |
Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows
remote attackers to inject arbitrary web script or HTML via a GET
request containing a terminating '"' (double quote) character.
|
| CVE-2004-0034 |
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5
and earlier allow remote attackers to inject arbitrary HTML or web
script via (1) the phorum_check_xss function in common.php, (2) the
EditError variable in profile.php, and (3) the Error variable in
login.php.
|
| CVE-2004-0032 |
Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW
2.61 allows remote attackers to inject arbitrary HTML and web script
via the firstname parameter.
|
| CVE-2003-1587 |
Cross-site scripting (XSS) vulnerability in LoganPro allows remote
attackers to inject arbitrary web script or HTML via a crafted
User-Agent HTTP header.
|
| CVE-2003-1586 |
Cross-site scripting (XSS) vulnerability in WebExpert allows remote
attackers to inject arbitrary web script or HTML via a crafted
User-Agent HTTP header.
|
| CVE-2003-1585 |
Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote
attackers to inject arbitrary web script or HTML via a crafted client
domain name, related to an "Inverse Lookup Log Corruption (ILLC)"
issue.
|
| CVE-2003-1584 |
Cross-site scripting (XSS) vulnerability in SurfStats allows remote
attackers to inject arbitrary web script or HTML via a crafted client
domain name, related to an "Inverse Lookup Log Corruption (ILLC)"
issue.
|
| CVE-2003-1583 |
Cross-site scripting (XSS) vulnerability in WebTrends allows remote
attackers to inject arbitrary web script or HTML via a crafted client
domain name, related to an "Inverse Lookup Log Corruption (ILLC)"
issue.
|
| CVE-2003-1582 |
Microsoft Internet Information Services (IIS) 6.0, when DNS resolution
is enabled for client IP addresses, allows remote attackers to inject
arbitrary text into log files via an HTTP request in conjunction with
a crafted DNS response, as demonstrated by injecting XSS sequences,
related to an "Inverse Lookup Log Corruption (ILLC)" issue.
|
| CVE-2003-1581 |
The Apache HTTP Server 2.0.44, when DNS resolution is enabled for
client IP addresses, allows remote attackers to inject arbitrary text
into log files via an HTTP request in conjunction with a crafted DNS
response, as demonstrated by injecting XSS sequences, related to an
"Inverse Lookup Log Corruption (ILLC)" issue.
|
| CVE-2003-1577 |
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5,
when DNS resolution is enabled for client IP addresses, allows remote
attackers to inject arbitrary text into log files, and conduct
cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer,
via an HTTP request in conjunction with a crafted DNS response,
related to an "Inverse Lookup Log Corruption (ILLC)" issue, a
different vulnerability than CVE-2002-1315 and CVE-2002-1316.
|
| CVE-2003-1556 |
Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI
City CC GuestBook allows remote attackers to inject arbitrary web
script or HTML via the (1) name and (2) homepage_title (webpage title)
parameters.
|
| CVE-2003-1554 |
Cross-site scripting (XSS) vulnerability in scozbook/add.php in
ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary
web script or HTML via the (1) username, (2) useremail, (3) aim, (4)
msn, (5) sitename and (6) siteaddy variables.
|
| CVE-2003-1549 |
Cross-site scripting (XSS) vulnerability in header.php in
MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject
arbitrary web script or HTML via the ma_kw parameter.
|
| CVE-2003-1547 |
Cross-site scripting (XSS) vulnerability in block-Forums.php in the
Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject
arbitrary web script or HTML via the subject parameter.
|
| CVE-2003-1546 |
Cross-site scripting (XSS) vulnerability in gbook.php in Filebased
guestbook 1.1.3 allows remote attackers to inject arbitrary web script
or HTML via the comment section.
|
| CVE-2003-1543 |
Cross-site scripting (XSS) vulnerability in Bajie Http Web Server
0.95zxe, 0.95zxc, and possibly others, allows remote attackers to
inject arbitrary web script or HTML via the query string, which is
reflected in an error message.
|
| CVE-2003-1539 |
Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File
Manager (SFM) before 0.21 allows remote attackers to inject arbitrary
web script or HTML via (1) file names and (2) directory names.
|
| CVE-2003-1536 |
Multiple cross-site scripting (XSS) vulnerabilities in Codeworx
Technologies DCP-Portal 5.3.1 allow remote attackers to inject
arbitrary web script or HTML via (1) the q parameter to search.php and
(2) the year parameter to calendar.php.
|
| CVE-2003-1534 |
Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice
Guestbook 1.3 allows remote attackers to inject arbitrary web script
or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5)
location, and (6) comment variables.
|
| CVE-2003-1531 |
Cross-site scripting (XSS) vulnerability in testcgi.exe in Lilikoi
Software Ceilidh 2.70 and earlier allows remote attackers to inject
arbitrary web script or HTML via the query string.
|
| CVE-2003-1522 |
Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server
2.0e and 2.0f allows remote attackers to inject arbitrary web script
or HTML via the redirect parameter to the admin/index.html page.
|
| CVE-2003-1519 |
Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine
allows remote attackers to inject arbitrary web script or HTML via the
query parameter to the search program.
|
| CVE-2003-1513 |
Multiple cross-site scripting (XSS) vulnerabilities in example scripts
in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to
inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3)
session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name
or (6) comment fields to guestbook.jsp.
|
| CVE-2003-1511 |
Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server
0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web
script or HTML via (1) the query string to test.txt, (2) the guestName
parameter to the custMsg servlet, or (3) the cookiename parameter to
the CookieExample servlet.
|
| CVE-2003-1506 |
Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix
CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary
script as other users by injecting arbitrary HTML or script into the
DENIEDURL parameter.
|
| CVE-2003-1502 |
mod_throttle 3.0 allows local users with Apache privileges to access
shared memory that points to a file that is writable by the apache
user, which could allow local users to gain privileges.
|
| CVE-2003-1498 |
Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT
Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers
to inject arbitrary web script or HTML via the zoom_query parameter.
|
| CVE-2003-1479 |
Cross-site scripting (XSS) vulnerability in webcamXP 1.02.432 and
1.02.535 allows remote attackers to inject arbitrary web script or
HTML via the message field.
|
| CVE-2003-1467 |
Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php,
(2) register.php, (3) post.php, and (4) common.php in Phorum before
3.4.3 allow remote attackers to inject arbitrary web script or HTML
via unknown attack vectors.
|
| CVE-2003-1453 |
Cross-site scripting (XSS) vulnerability in the MytextSanitizer
function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1
allows remote attackers to inject arbitrary web script or HTML via a
javascript: URL in an IMG tag.
|
| CVE-2003-1420 |
Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with
automatic redirection disabled allows remote attackers to inject
arbitrary web script or HTML via the HTTP Location header.
|
| CVE-2003-1400 |
Cross-site scripting (XSS) vulnerability in the Your_Account module
for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject
arbitrary web script or HTML via the user_avatar parameter.
|
| CVE-2003-1384 |
Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor
1.0 allows remote attackers to insert arbitrary web script or HTML via
the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre
message fields.
|
| CVE-2003-1372 |
Cross-site scripting (XSS) vulnerability in links.php script in
myPHPNuke 1.8.8, and possibly earlier versions, allows remote
attackers to inject arbitrary HTML and web script via the (1) ratenum
or (2) query parameters.
|
| CVE-2003-1371 |
Nuked-Klan 1.3b, and possibly earlier versions, allows remote
attackers to obtain sensitive server information via an op parameter
set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.
|
| CVE-2003-1370 |
Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b
allow remote attackers to inject arbitrary HTML or web script via (1)
the Author field in the Guestbook module, (2) the Titre or Pseudo
fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox
module.
|
| CVE-2003-1353 |
Multiple cross-site scripting (XSS) vulnerabilities in Outreach
Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary
web script or HTML, as demonstrated using the news field.
|
| CVE-2003-1348 |
Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org
Guestbook 1.1 allows remote attackers to inject arbitrary web script
or HTML via the (1) comment, (2) name, or (3) title field.
|
| CVE-2003-1347 |
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7
allow remote attackers to inject arbitrary web script or HTML via the
(1) cid parameter to comment.php, (2) uid parameter to profiles.php,
(3) uid to users.php, and (4) homepage field.
|
| CVE-2003-1334 |
Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge
simple and nice index file (aka snif) before 1.2.7 allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2003-1317 |
Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2
allows remote attackers to inject arbitrary web script or HTML via the
mod parameter. NOTE: The provenance of this information is unknown;
the details are obtained solely from third party information.
|
| CVE-2003-1293 |
Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb
GuestBookHost allow remote attackers to inject arbitrary web script or
HTML via the (1) Name, (2) Email and (3) Message fields when signing
the guestbook.
|
| CVE-2003-1285 |
Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server
before 6.0 beta 6 allow remote attackers to inject arbitrary web
script or HTML via the query string to (1) isapi/testisa.dll, (2)
testcgi.exe, (3) environ.pl, (4) the query parameter to
samples/search.dll, (5) the price parameter to mortgage.pl, (6) the
query string in dumpenv.pl, (7) the query string to dumpenv.pl, and
(8) the E-Mail field of the guestbook script (book.pl).
|
| CVE-2003-1278 |
Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows
remote attackers to execute arbitrary script as other users and
possibly steal authentication information via cookies by injecting
arbitrary HTML or script into IMG tags.
|
| CVE-2003-1277 |
Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin
Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script
as other users and possibly steal authentication information via
cookies by injecting arbitrary HTML or script into (1) news_icon of
news_template.php, and (2) threadid and subject of index.html
|
| CVE-2003-1271 |
Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows
remote attackers to execute arbitrary web script or HTML as other
users via a URL containing the script.
|
| CVE-2003-1243 |
Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote
attackers to insert arbitrary HTML or web script via the mod
parameter.
|
| CVE-2003-1242 |
Sage 1.0 b3 allows remote attackers to obtain the root web server path
via a URL request for a non-existent module, which returns the path in
an error message.
|
| CVE-2003-1241 |
Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2)
admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in
MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code
by modifying the location parameter to reference a URL on a remote web
server that contains file.php via script injected into the pseudo,
email, and message parameters.
|
| CVE-2003-1238 |
Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and
earlier allows remote attackers to steal authentication information
via cookies by injecting arbitrary HTML or script into op of the (1)
Team, (2) News, and (3) Liens modules.
|
| CVE-2003-1237 |
Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and
earlier allows remote attackers to inject arbitrary HTML or web script
via a message post.
|
| CVE-2003-1231 |
Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 5.5
allows remote attackers to inject arbitrary web script or HTML via the
cat parameter.
|
| CVE-2003-1219 |
Cross-site scripting (XSS) vulnerability in the tep_href_link function
in html_output.php for osCommerce before 2.2-MS3 allows remote
attackers to inject arbitrary web script or HTML via the osCsid
parameter.
|
| CVE-2003-1211 |
Cross-site scripting (XSS) vulnerability in search.asp for
MaxWebPortal 1.30 and possibly earlier versions allows remote
attackers to inject arbitrary web script or HTML via the Search
parameter.
|
| CVE-2003-1204 |
Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site
Server 4.0.12 BETA and earlier allow remote attackers to execute
script on other clients via (1) the link parameter in
sectionswindow.php, the directory parameter in (2) gallery.php, (3)
navigation.php, or (4) uploadimage.php, the path parameter in (5)
view.php, (6) the choice parameter in upload.php, (7) the sitename
parameter in mambosimple.php, (8) the type parameter in upload.php, or
the id parameter in (9) emailarticle.php, (10) emailfaq.php, or (11)
emailnews.php.
|
| CVE-2003-1203 |
Cross-site scripting (XSS) vulnerability in index.php for Mambo Site
Server 4.0.10 allows remote attackers to execute script on other
clients via the ?option parameter.
|
| CVE-2003-1199 |
Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows
remote attackers to inject arbitrary web script or HTML via the URL.
|
| CVE-2003-1197 |
Cross-site scripting (XSS) vulnerability in index.php for
Ledscripts.com LedForums Beta 1 allows remote attackers to inject
arbitrary web script or HTML via the (1) top_message parameter or (2)
topic field of a new thread.
|
| CVE-2003-1194 |
Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3
allows remote attackers to inject arbitrary web script or HTML via the
error message.
|
| CVE-2003-1190 |
Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through
2.17 allows remote attackers to inject arbitrary web script or HTML
via a recipe.
|
| CVE-2003-1187 |
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT
1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web
script or HTML via the contact_email parameter.
|
| CVE-2003-1184 |
Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta
2.8 and 2.81 allow remote attackers to inject arbitrary web script or
HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3)
pictures, and (4) other "Diverse XSS Bugs."
|
| CVE-2003-1182 |
Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows
remote attackers to inject arbitrary web script or HTML via the lng
parameter.
|
| CVE-2003-1175 |
Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5
allows remote attackers to inject arbitrary web script or HTML via the
vo parameter.
|
| CVE-2003-1164 |
Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows
remote attackers to inject arbitrary web script or HTML via the URI,
which is injected into the HTML error page.
|
| CVE-2003-1157 |
Cross-site scripting (XSS) vulnerability in login.asp in Citrix
MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary
web script or HTML via the NFuse_Message parameter.
|
| CVE-2003-1151 |
Cross-site scripting (XSS) vulnerability in Fastream NETFile Server
6.0.3.588 allows remote attackers to inject arbitrary web script or
HTML via the URL, which is displayed on a "404 Not Found" error page.
|
| CVE-2003-1149 |
Cross-site scripting (XSS) vulnerability in Symantec Norton Internet
Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web
script or HTML via a URL to a blocked site, which is displayed on the
blocked sites error page.
|
| CVE-2003-1146 |
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo
Album 1.0 allows remote attackers to inject arbitrary web script or
HTML via the dir parameter.
|
| CVE-2003-1145 |
Cross-site scripting (XSS) vulnerability in friendmail.php in
OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary
web script or HTML via the listing parameter.
|
| CVE-2003-1136 |
Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook
1.51 allows remote attackers to inject arbitrary web script or HTML
via (1) HTML in a posted message or (2) Javascript in an onmouseover
attribute in an e-mail address or URL.
|
| CVE-2003-1100 |
Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird
CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject
arbitrary web script or HTML via certain vectors.
|
| CVE-2003-1089 |
index.php for Zorum 3.4 allows remote attackers to determine the full
path of the web root via invalid parameter names, which reveals the
path in a PHP error message.
|
| CVE-2003-1088 |
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4
and 3.5 allows remote attackers to inject arbitrary web script or HTML
via the method parameter.
|
| CVE-2003-1031 |
Cross-site scripting (XSS) vulnerability in register.php for vBulletin
3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web
script via optional fields such as (1) "Interests-Hobbies", (2)
"Biography", or (3) "Occupation."
|
| CVE-2003-0992 |
Cross-site scripting (XSS) vulnerability in the create CGI script for
Mailman before 2.1.3 allows remote attackers to steal cookies of other
users.
|
| CVE-2003-0981 |
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name
of a visiting host, which allows remote attackers to spoof the origin
of their incoming requests and facilitate cross-site scripting (XSS)
attacks.
|
| CVE-2003-0980 |
Cross-site scripting (XSS) vulnerability in FreeScripts VisitorBook LE
(visitorbook.pl) allows remote attackers to inject arbitrary HTML or
web script via (1) the "do" parameter, (2) via the "user" parameter
from a host with a malicious reverse DNS name, (3) via quote marks or
ampersands in other parameters.
|
| CVE-2003-0965 |
Cross-site scripting (XSS) vulnerability in the admin CGI script for
Mailman before 2.1.4 allows remote attackers to steal session cookies
and conduct unauthorized activities.
|
| CVE-2003-0801 |
Cross-site scripting (XSS) vulnerability in Nokia Electronic
Documentation (NED) 5.0 allows remote attackers to execute arbitrary
web script and steal cookies via a URL to the docs/ directory that
contains the script.
|
| CVE-2003-0769 |
Cross-site scripting (XSS) vulnerability in the ICQ Web Front
guestbook (guestbook.html) allows remote attackers to insert arbitrary
web script and HTML via the message field.
|
| CVE-2003-0768 |
Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site
Scripting (XSS) and Script Injection protection feature via a null
character in the beginning of a tag name.
|
| CVE-2003-0764 |
Escapade Scripting Engine (ESP) allows remote attackers to obtain
sensitive path information via a malformed request, which leaks the
information in an error message, as demonstrated using the PAGE
parameter.
|
| CVE-2003-0763 |
Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine
(ESP) allows remote attackers to inject arbitrary script via the
method parameter, as demonstrated using the PAGE parameter.
|
| CVE-2003-0749 |
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet
Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to
insert arbitrary web script and steal cookies via the ~service
parameter.
|
| CVE-2003-0738 |
The calendar module in phpWebSite 0.9.x and earlier allows remote
attackers to cause a denial of service (crash) via a long year
parameter.
|
| CVE-2003-0737 |
The calendar module in phpWebSite 0.9.x and earlier allows remote
attackers to obtain the full pathname of phpWebSite via an invalid
year, which generates an error from localtime() in TimeZone.php of the
Pear library.
|
| CVE-2003-0736 |
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite
0.9.x and earlier allow remote attackers to execute arbitrary web
script via (1) the day parameter in the calendar module, (2) the
fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in
the pagemaster module, (4) the PDA_limit parameter in the search, and
(5) possibly other parameters in the calendar, fatcat, and pagemaster
modules.
|
| CVE-2003-0735 |
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x
and earlier allows remote attackers to execute arbitrary SQL queries,
as demonstrated using the year parameter.
|
| CVE-2003-0733 |
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic
Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and
Express 5.1 through 7.0, allow remote attackers to execute arbitrary
web script and steal authentication credentials via (1) a forward
instruction to the Servlet container or (2) other vulnerabilities in
the WebLogic Server console application.
|
| CVE-2003-0712 |
Cross-site scripting (XSS) vulnerability in the HTML encoding for the
Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web
Access (OWA) allows remote attackers to execute arbitrary web script.
|
| CVE-2003-0629 |
Cross-site scripting (XSS) vulnerability in PeopleSoft IScript
environment for PeopleTools 8.43 and earlier allows remote attackers
to insert arbitrary web script via a certain HTTP request to IScript.
|
| CVE-2003-0624 |
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for
BEA WebLogic 8.1 and earlier allows remote attackers to inject
malicious web script via the person parameter.
|
| CVE-2003-0623 |
Cross-site scripting (XSS) vulnerability in the Administration Console
for BEA Tuxedo 8.1 and earlier allows remote attackers to inject
arbitrary web script via the INIFILE argument.
|
| CVE-2003-0615 |
Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm
allows remote attackers to insert web script via a URL that is fed
into the form's action parameter.
|
| CVE-2003-0614 |
Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1
through 1.3.4 allows remote attackers to insert arbitrary web script
via the searchstring parameter.
|
| CVE-2003-0602 |
Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x
before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to
insert arbitrary HTML or web script via (1) multiple default German
and Russian HTML templates or (2) ALT and NAME attributes in AREA tags
as used by the GraphViz graph generation feature for local dependency
graphs.
|
| CVE-2003-0590 |
Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote
attackers to insert arbitrary HTML and web script via the post icon
(image_subject) field.
|
| CVE-2003-0587 |
Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin
Board (UBB) 6.x allows remote authenticated users to execute arbitrary
web script and gain administrative access via the "displayed name"
attribute of the "ubber" cookie.
|
| CVE-2003-0526 |
Cross-site scripting (XSS) vulnerability in Microsoft Internet
Security and Acceleration (ISA) Server 2000 allows remote attackers to
inject arbitrary web script via a URL containing the script in the
domain name portion, which is not properly cleansed in the default
error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm
for "404 Not Found."
|
| CVE-2003-0523 |
Cross-site scripting (XSS) vulnerability in msg.asp for certain
versions of ProductCart allow remote attackers to execute arbitrary
web script via the message parameter.
|
| CVE-2003-0521 |
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote
attackers to insert arbitrary HTML and possibly gain cPanel
administrator privileges via script in a URL that is logged but not
properly quoted when displayed via the (1) Error Log or (2) Latest
Visitors screens.
|
| CVE-2003-0504 |
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware
0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary
HTML or web script, as demonstrated with a request to index.php in the
addressbook module.
|
| CVE-2003-0495 |
Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote
attackers to insert arbitrary web script via a news item.
|
| CVE-2003-0492 |
Cross-site scripting (XSS) vulnerability in search.asp for Snitz
Forums 3.4.03 and earlier allows remote attackers to execute arbitrary
web script via the Search parameter.
|
| CVE-2003-0488 |
Multiple cross-site scripting (XSS) vulnerabilities in Kerio
MailServer 5.6.3 allow remote attackers to insert arbitrary web script
via (1) the add_name parameter in the add_acl module, or (2) the alias
parameter in the do_map module.
|
| CVE-2003-0487 |
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote
authenticated users to cause a denial of service and possibly execute
arbitrary code via (1) a long showuser parameter in the do_subscribe
module, (2) a long folder parameter in the add_acl module, (3) a long
folder parameter in the list module, and (4) a long user parameter in
the do_map module.
|
| CVE-2003-0484 |
Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB
allows remote attackers to insert arbitrary web script via the
topic_id parameter.
|
| CVE-2003-0483 |
Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium
allow remote attackers to insert arbitrary script via (1) the member
parameter to member.php or (2) the action parameter to buddy.php.
|
| CVE-2003-0481 |
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow
remote attackers to insert arbitrary web script, as demonstrated using
the msg parameter to file_select.php.
|
| CVE-2003-0479 |
Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS
allows remote attackers to insert arbitrary web script via the (1)
Name, (2) Email, or (3) Message fields.
|
| CVE-2003-0446 |
Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly
in a component that is also used by other Microsoft products, allows
remote attackers to insert arbitrary web script via an XML file that
contains a parse error, which inserts the script in the resulting
error message.
|
| CVE-2003-0442 |
Cross-site scripting (XSS) vulnerability in the transparent SID
support capability for PHP before 4.3.2 (session.use_trans_sid) allows
remote attackers to insert arbitrary script via the PHPSESSID
parameter.
|
| CVE-2003-0416 |
Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4
allows remote attackers to insert arbitrary HTML or script via (1) the
year parameter in a showmonth action, (2) the month parameter in a
showmonth action, or (3) the host parameter in a showhost action.
|
| CVE-2003-0413 |
Cross-site scripting (XSS) vulnerability in the webapps-simple sample
application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP
or (2) Sun Java System Web Server 6.1 allows remote attackers to
insert arbitrary web script or HTML via an HTTP request that generates
an "Invalid JSP file" error, which inserts the text in the resulting
error message.
|
| CVE-2003-0404 |
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette
StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers
to insert arbitrary HTML and script via text variables, as
demonstrated using the errInfo parameter of the default login
template.
|
| CVE-2003-0389 |
Cross-site scripting (XSS) vulnerability in the secure redirect
function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows
remote attackers to insert arbitrary web script and possibly cause
users to enter a passphrase via a GET request containing the script.
|
| CVE-2003-0375 |
Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB
1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML
and web script via the "member" parameter.
|
| CVE-2003-0341 |
Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71
and earlier allows remote attackers to insert arbitrary script via the
Search field.
|
| CVE-2003-0318 |
Cross-site scripting (XSS) vulnerability in the Statistics module for
PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary
web script via the year parameter.
|
| CVE-2003-0310 |
Cross-site scripting (XSS) vulnerability in articleview.php for eZ
publish 2.2 allows remote attackers to insert arbitrary web script.
|
| CVE-2003-0295 |
Cross-site scripting (XSS) vulnerability in private.php for vBulletin
3.0.0 Beta 2 allows remote attackers to inject arbitrary web script
and HTML via the "Preview Message" capability.
|
| CVE-2003-0292 |
Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server
5.5.1 allows remote attackers to insert arbitrary web script or HTML
into an error page that appears to come from the domain that the
client is visiting, aka "Man-in-the-Middle" XSS.
|
| CVE-2003-0287 |
Cross-site scripting (XSS) vulnerability in Movable Type before 2.6,
and possibly other versions including 2.63, allows remote attackers to
insert arbitrary web script or HTML via the Name textbox, possibly
when the "Allow HTML in comments?" option is enabled.
|
| CVE-2003-0283 |
Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows
remote attackers to inject arbitrary web script and HTML tags via a
message with a "<<" before a tag name in the (1) subject, (2) author's
name, or (3) author's e-mail.
|
| CVE-2003-0278 |
Cross-site scripting (XSS) vulnerability in normal_html.cgi in
Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert
arbitrary web script via the file parameter.
|
| CVE-2003-0273 |
Cross-site scripting (XSS) vulnerability in the web interface for
Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to
execute script via message bodies.
|
| CVE-2003-0223 |
Cross-site scripting vulnerability (XSS) in the ASP function
responsible for redirection in Microsoft Internet Information Server
(IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL
containing script in a redirection message.
|
| CVE-2003-0217 |
Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual
Extranet (IVE) 3.01 and earlier allows remote attackers to insert
arbitrary web script and bypass authentication via a certain CGI
script.
|
| CVE-2003-0208 |
Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user
tracking capability allows remote attackers to insert arbitrary
Javascript via the clickTAG field.
|
| CVE-2003-0160 |
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail
before 1.2.11 allow remote attackers to inject arbitrary HTML code and
steal information from a client's web browser.
|
| CVE-2003-0154 |
Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query
tool allow remote attackers to execute arbitrary web script via (1)
the file, root, or rev parameters to cvslog.cgi, (2) the file or root
parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi,
(4) the person parameter to showcheckins.cgi, (5) the module parameter
to cvsqueryform.cgi, and (6) possibly other attack vectors as
identified by Mozilla bug #146244.
|
| CVE-2003-0153 |
bonsai Mozilla CVS query tool leaks the absolute pathname of the tool
in certain error messages generated by (1) cvslog.cgi, (2)
cvsview2.cgi, or (3) multidiff.cgi.
|
| CVE-2003-0053 |
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple
Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming
Server 4.1.1 allows remote attackers to insert arbitrary script via
the filename parameter, which is inserted into an error message.
|
| CVE-2003-0044 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1)
examples and (2) ROOT web applications for Jakarta Tomcat 3.x through
3.3.1a allow remote attackers to insert arbitrary web script or HTML.
|
| CVE-2003-0038 |
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1
allows remote attackers to inject script or HTML into web pages via
the (1) email or (2) language parameters.
|
| CVE-2003-0009 |
Cross-site scripting (XSS) vulnerability in Help and Support Center
for Microsoft Windows Me allows remote attackers to execute arbitrary
script in the Local Computer security context via an hcp:// URL with
the malicious script in the topic parameter.
|
| CVE-2003-0002 |
Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for
Microsoft Content Management Server (MCMS) 2001 allows remote
attackers to execute arbitrary script via the REASONTXT parameter.
|
| CVE-2002-2424 |
Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1
allows remote attackers to inject arbitrary web script or HTML via
Javascript in the style attribute of an HTML tag.
|
| CVE-2002-2422 |
Cross-site scripting (XSS) vulnerability in Compaq Insight Management
Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to
inject arbitrary web script or HTML via a URL, which inserts the
script into the resulting error message.
|
| CVE-2002-2418 |
Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP)
1.33 beta 7 allows remote attackers to inject arbitrary web script or
HTML via the URL, which is inserted into an error page.
|
| CVE-2002-2386 |
Cross-site scripting (XSS) vulnerability in the Quizz module for XOOPS
1.0, when allowing on-line question development, allows remote
attackers to inject arbitrary web script or HTML via a javascript: URL
in the SRC attribute of an IMG tag.
|
| CVE-2002-2378 |
Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows
remote attackers to inject arbitrary web script or HTML via a colon
(:) in the query string, which is inserted into the resulting error
page.
|
| CVE-2002-2377 |
Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3
allows remote attackers to inject arbitrary SSi directives, web
script, and HTML via the entry field.
|
| CVE-2002-2376 |
Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest
1.1 allows remote attackers to inject arbitrary SSI directives, web
script, and HTML via the (1) full name, (2) email, (3) homepage, and
(4) location parameters. NOTE: this issue might overlap
CVE-2005-1605.
|
| CVE-2002-2364 |
Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier
allows remote attackers to inject arbitrary web script or HTML via a
help ticket.
|
| CVE-2002-2362 |
Cross-site scripting (XSS) vulnerability in form_header.php in
MyMarket 1.71 allows remote attackers to inject arbitrary web script
or HTML via the noticemsg parameter.
|
| CVE-2002-2359 |
Cross-site scripting (XSS) vulnerability in the FTP view feature in
Mozilla 1.0 allows remote attackers to inject arbitrary web script or
HTML via the title tag of an ftp URL.
|
| CVE-2002-2358 |
Cross-site scripting (XSS) vulnerability in the FTP view feature in
Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject
arbitrary web script or HTML via the title tag of an FTP URL.
|
| CVE-2002-2350 |
Cross-site scripting (XSS) vulnerability in z_user_show.php in
dbtreelistproperty_method.php in Zorum 2.4 allows remote attackers to
inject arbitrary web script or HTML via the class parameter.
|
| CVE-2002-2348 |
Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR
allows remote attackers to inject arbitrary web script or HTML via the
command parameter.
|
| CVE-2002-2347 |
Cross-site scripting (XSS) vulnerability in Oracle Java Server Page
(OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3)
usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s
and 1.0.2 allows remote attackers to inject arbitrary web script or
HTML via the text entry field.
|
| CVE-2002-2343 |
Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5
allows remote attackers to inject arbitrary web script or HTML via
email messages.
|
| CVE-2002-2341 |
Cross-site scripting (XSS) vulnerability in content blocking in
SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary
web script or HTML via a blocked URL.
|
| CVE-2002-2340 |
Cross-site scripting (XSS) vulnerability in read.php in Phorum 3.3.2a
allows remote attackers to inject arbitrary web script or HTML via (1)
the t parameter or (2) the body of an email response.
|
| CVE-2002-2339 |
Cross-site scripting (XSS) vulnerability in configure.asp in
Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary
web script or HTML via a javascript: URL in (1) image, (2) img, (3)
image=right, (4) img=right, (5) image=left, and (6) img=left tags.
|
| CVE-2002-2330 |
Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25
allows remote attackers to inject arbitrary web script or HTML via (1)
HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html
and executed in client browsers.
|
| CVE-2002-2321 |
Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2)
addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject
arbitrary web script or HTML via the catid parameter.
|
| CVE-2002-2318 |
Cross-site scripting (XSS) vulnerability in Falcon web server
2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject
arbitrary web script or HTML via the URI, which is inserted into 301
error messages and executed by 404 error messages.
|
| CVE-2002-2296 |
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another
Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject
arbitrary web script or HTML via the num parameter.
|
| CVE-2002-2289 |
soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows
remote attackers to gain sensitive information including ODBC
passwords.
|
| CVE-2002-2278 |
Cross-site scripting (XSS) vulnerability in mod_search/index.php in
PortailPHP 0.99 allows remote attackers to inject arbitrary web script
or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4)
$Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables.
|
| CVE-2002-2276 |
Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the
physical path of the message board via a direct request to add.php,
which leaks the path in an error message.
|
| CVE-2002-2273 |
Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows
remote attackers to inject arbitrary web script or HTML via the URL.
|
| CVE-2002-2260 |
Cross-site scripting (XSS) vulnerability in the quips feature in
Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject
arbitrary web script or HTML via the "show all quips" page.
|
| CVE-2002-2255 |
Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3
and possibly earlier versions allows remote attackers to inject
arbitrary web script or HTML via the search_username parameter in
searchuser mode.
|
| CVE-2002-2246 |
Cross-site scripting (XSS) vulnerability in VisNetic Website before
3.5.15 allows remote attackers to inject arbitrary web script or HTML
via the HTTP referer header (HTTP_REFERER) to a non-existent page,
which is injected into the resulting 404 error page.
|
| CVE-2002-2235 |
member2.php in vBulletin 2.2.9 and earlier does not properly restrict
the $perpage variable to be an integer, which causes an error message
to be reflected back to the user without quoting, which facilitates
cross-site scripting (XSS) and possibly other attacks.
|
| CVE-2002-2231 |
Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows
remote attackers to inject arbitrary web script or HTML via (1) a
javascript: URL in a photo URL or (2) an X-Forwarded-For: header.
|
| CVE-2002-2230 |
Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows
remote attackers to inject arbitrary web script or HTML via a private
message with a javascript: URL in the IMG tag, in which the URL ends
in a ".gif" or ".jpg" string, a variant of CVE-2002-0328.
|
| CVE-2002-2193 |
Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7
allows remote attackers to inject arbitrary web script via the email
parameter.
|
| CVE-2002-2192 |
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1
allows remote attackers to execute arbitrary web script via (1) a
Host: header when DNS wildcards are supported or (2) the query string
in a "dir" request to indexed folders.
|
| CVE-2002-2189 |
Cross-site scripting (XSS) vulnerability in ActiveXperts Software
ActiveWebserver allows remote attackers to execute arbitrary web
script via a link.
|
| CVE-2002-2178 |
Cross-site scripting (XSS) vulnerability in article.php module for
phpWebSite 0.8.3 allows remote attackers to execute arbitrary
Javascript script via the sid parameter, as demonstrated using an IMG
tag.
|
| CVE-2002-2171 |
Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows
remote attackers to insert arbitrary HTML and web script via a URL,
possibly via a "%db" request in a URL.
|
| CVE-2002-2166 |
Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0
allows remote attackers to insert arbitrary HTML and web script.
|
| CVE-2002-2129 |
Cross-site scripting vulnerability (XSS) in editform.php for w-Agora
4.1.5 allows remote attackers to execute arbitrary web script via an
arbitrary form field name containing the script, which is echoed back
to the user when displaying the form.
|
| CVE-2002-2128 |
editform.php in w-Agora 4.1.5 allows local users to execute arbitrary
PHP code via .. (dot dot) sequences in the file parameter.
|
| CVE-2002-2115 |
Cross-site scripting (XSS) vulnerability in Hyper NIKKI System (HNS)
Lite before 0.9 and HNS before 2.10-pl2 allows remote attackers to
inject arbitrary web script or HTML.
|
| CVE-2002-2107 |
Cross-site scripting (XSS) vulnerability in the lookup script in
Veridis OpenKeyServer (OKS) 1.2 allows remote attackers to inject
arbitrary web script or HTML via the search parameter.
|
| CVE-2002-2086 |
Multiple cross-site scripting (XSS) vulnerabilities in magicHTML of
SquirrelMail before 1.2.6 allow remote attackers to inject arbitrary
web script or HTML via (1) "<<script" in unspecified input fields or
(2) a javascript: URL in the src attribute of an IMG tag.
|
| CVE-2002-2073 |
Cross-site scripting (XSS) vulnerability in the default ASP pages on
Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to
inject arbitrary web script or HTML via the (1) ctr parameter in
Default.asp and (2) the query string to formslogin.asp.
|
| CVE-2002-2062 |
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet
Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder
view for FTP sites" and "Enable Web content in folders" selected,
allows remote attackers to inject arbitrary web script or HTML via the
hostname portion of an FTP URL.
|
| CVE-2002-2056 |
Cross-site scripting (XSS) vulnerability in TeeKai Forum 1.2 allows
remote attackers to inject arbitrary web script or HTML via the
valid_username_online cookie.
|
| CVE-2002-2055 |
Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai
Tracking Online 1.0 allows remote attackers to inject arbitrary web
script or HTML via the id parameter.
|
| CVE-2002-2044 |
Cross-site scripting (XSS) vulnerability in x_stat_admin.php in x-stat
2.3 and earlier allows remote attackers to inject arbitrary web script
or HTML via a parameter to the phpinfo action.
|
| CVE-2002-2021 |
Cross-site scripting (XSS) vulnerability in WoltLab Burning Board
(wbboard) 1.1.1 allows remote attackers to inject arbitrary web script
or HTML via the message parameter.
|
| CVE-2002-2011 |
Cross-site scripting (XSS) vulnerability in the fom CGI program
(fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to
inject arbitrary web script or HTML via the file parameter.
|
| CVE-2002-2010 |
Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig
(ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject
arbitrary web script or HTML via the words parameter.
|
| CVE-2002-1996 |
Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
(1) name parameter in modules.php and (2) catid parameter in
index.php.
|
| CVE-2002-1995 |
Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke
allows remote attackers to inject arbitrary web script or HTML via the
filnavn parameter.
|
| CVE-2002-1965 |
Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix
Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web
script or HTML via the (1) Javascript events, as demonstrated via an
onerror event in an IMG SRC tag or (2) User-Agent field in an HTTP GET
request.
|
| CVE-2002-1960 |
Cross-site scripting (XSS) vulnerability in Cybozu Share360 1.1 allows
remote attackers to inject arbitrary web script or HTML via an HTML
link.
|
| CVE-2002-1958 |
Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b
allows remote attackers to inject arbitrary web script or HTML via (1)
javascript in onmouseover or other attributes in "safe" HTML tags such
as the "b" tag, or (2) the Subject field.
|
| CVE-2002-1954 |
Cross-site scripting (XSS) vulnerability in the phpinfo function in
PHP 4.2.3 allows remote attackers to inject arbitrary web script or
HTML via the query string argument, as demonstrated using soinfo.php.
|
| CVE-2002-1950 |
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote
attackers to inject arbitrary web script or HTML via the (1) the email
parameter of add.php or (2) the banner URL (banurl parameter) in the
main list.
|
| CVE-2002-1931 |
Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3
and 2.1.1 allows remote attackers to inject arbitrary web script or
HTML via Javascript in the search string.
|
| CVE-2002-1929 |
Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena
paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary
web script or HTML via the query string in the (1) rate, (2) email, or
(3) download actions.
|
| CVE-2002-1922 |
Cross-site scripting (XSS) vulnerability in global.php in Jelsoft
vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject
arbitrary web script or HTML via the (1) $scriptpath or (2) $url
variables.
|
| CVE-2002-1917 |
CRLF injection vulnerability in the "User Profile: Send Email" feature
in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail
addresses by injecting a CRLF into the Subject field and adding a BCC
mail header.
|
| CVE-2002-1901 |
Cross-site scripting (XSS) vulnerability in Bodo Bauer BBGallery 1.0
allows remote attackers to inject arbitrary web script or HTML via
image tags.
|
| CVE-2002-1900 |
Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote
attackers to inject arbitrary web script or HTML via tasklists.
|
| CVE-2002-1899 |
Cross-site scripting (XSS) vulnerability in IceWarp Web Mail 3.3.3 and
3.4.5 allows remote attackers to inject arbitrary web script or HTML
via the "Full Name" (addressname) parameter.
|
| CVE-2002-1894 |
Cross-site scripting (XSS) vulnerability in viewtopic.php in phpBB
2.0.3 allows remote attackers to inject arbitrary web script or HTML
via the highlight parameter.
|
| CVE-2002-1893 |
Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro
1.8.1.9 allows remote attackers to inject arbitrary web script or HTML
via the e-mail message.
|
| CVE-2002-1853 |
Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1
allows remote attackers to inject arbitrary web script or HTML via the
subject of a newsgroup post, which is not properly handled by (1)
myarticles.php, (2) search.php, (3) stats.php, or (4)
standard.lib.php.
|
| CVE-2002-1852 |
Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote
attackers to inject arbitrary web script or HTML via (1) the URL or
(2) a parameter to test2.pl.
|
| CVE-2002-1845 |
Cross-site scripting (XSS) vulnerability in index.php in Yet Another
Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject
arbitrary web script or HTML via the password (passwrd) parameter.
|
| CVE-2002-1829 |
Cross-site scripting (XSS) vulnerability in codeparse.php in Open
Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject
arbitrary web script or HTML via (1) myhome.php, (2) an onerror
attribute in an IMG tag (a variant of CVE-2002-0330), or (3) a glow
tag.
|
| CVE-2002-1808 |
Cross-site scripting (XSS) vulnerability in Meunity Community System
1.1 allows remote attackers to inject arbitrary web script or HTML via
Javascript in an IMG tag when creating a topic.
|
| CVE-2002-1807 |
Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows
remote attackers to inject arbitrary web script or HTML via Javascript
in an IMG tag.
|
| CVE-2002-1806 |
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote
attackers to inject arbitrary web script or HTML via Javascript in an
IMG tag.
|
| CVE-2002-1805 |
Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote
attackers to inject arbitrary web script or HTML via Javascript in an
IMG tag.
|
| CVE-2002-1804 |
Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote
attackers to inject arbitrary web script or HTML via Javascript in an
IMG tag.
|
| CVE-2002-1803 |
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote
attackers to inject arbitrary web script or HTML via Javascript in an
IMG tag.
|
| CVE-2002-1802 |
Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows
remote attackers to inject arbitrary web script or HTML via Javascript
in an IMG tag when submitting news.
|
| CVE-2002-1799 |
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote
attackers to inject arbitrary web script or HTML via the (1) email
parameter to add.php or (2) banurl parameter.
|
| CVE-2002-1795 |
Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft
Terminal Services Advanced Client (TSAC) ActiveX control allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2002-1785 |
Cross-site scripting (XSS) vulnerability in Zeus Administration Server
in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users
to inject arbitrary web script or HTML via the section parameter to
index.fcgi.
|
| CVE-2002-1733 |
Cross-site scripting (XSS) vulnerability in the web-based message
board in Prospero Technologies allows remote attackers to inject
arbitrary web script or HTML via a message board post.
|
| CVE-2002-1732 |
Multiple cross-site scripting (XSS) vulnerabilities in Actinic Catalog
4.7.0 allow remote attackers to inject arbitrary web script or HTML
via (1) the query string argument to certain .pl files, (2) the
REFPAGE parameter to ca000007.pl, (3) PRODREF parameter to
ss000007.pl, or (4) hop parameter to ca000001.pl.
|
| CVE-2002-1729 |
Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00
allows remote attackers to execute arbitrary script as other users via
the "web site" parameter in a guestbook message.
|
| CVE-2002-1727 |
Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2)
as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to
execute arbitrary script as other users via a URL.
|
| CVE-2002-1724 |
Cross-site scripting vulnerability (XSS) in phpimageview.php for
PHPImageView 1.0 allows remote attackers to execute arbitrary script
as other users via the pic parameter.
|
| CVE-2002-1708 |
Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10
allows remote attackers to execute arbitrary script as other users by
injecting script into the (1) subject or (2) message fields.
|
| CVE-2002-1703 |
Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft
NetAuction 3.0 allows remote attackers to execute arbitrary script as
other users via the Term parameter.
|
| CVE-2002-1702 |
Cross-site scripting vulnerability (XSS) in DeltaScripts PHP
Classifieds 6.0.5 allows remote attackers to execute arbitrary script
as other users via the URL parameter.
|
| CVE-2002-1700 |
Cross-site scripting vulnerability (XSS) in the missing template
handler in Macromedia ColdFusion MX allows remote attackers to execute
arbitrary script as other users by injecting script into the HTTP
request for the name of a template, which is not filtered in the
resulting 404 error message.
|
| CVE-2002-1685 |
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition
and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute
arbitrary script as other users by injecting script into ext.dll
ISAPI.
|
| CVE-2002-1683 |
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition
1.7.3 allows remote attackers to execute arbitrary script as other
users by injecting script into the cleanSearchString() function.
|
| CVE-2002-1681 |
Cross-site scripting (XSS) vulnerability in Slashcode CVS releases
June 17 through July 1 2002 allows remote attackers to execute
arbitrary script as other users by injecting script into the paragraph
<P> tag.
|
| CVE-2002-1680 |
Cross-site scripting (XSS) vulnerability in CGI Online Worldweb
Shopping 1.1 (a.k.a. COWS) allows remote attackers to execute
arbitrary script as other users by injecting script into (1)
diagnose.cgi or (2) compatible.cgi.
|
| CVE-2002-1679 |
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 2.2.0
allows remote attackers to execute arbitrary script as other users by
injecting script into a bulletin board message.
|
| CVE-2002-1678 |
Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft
vBulletin 2.0 rc 2 through 2.2.4 allows remote attackers to steal
authentication credentials by injecting script into $letterbits.
|
| CVE-2002-1662 |
Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site
Server 4.0.11 allow remote attackers to execute arbitrary script on
other clients via (1) search.php and (2) the "Your name" field during
account registration.
|
| CVE-2002-1651 |
Cross-site scripting (XSS) vulnerability in Verity Search97 allows
remote attackers to insert arbitrary web content and steal sensitive
information from other clients, possibly due to certain error messages
from template pages that use the (1) vformat or (2) vfilter functions.
|
| CVE-2002-1649 |
Cross-site scripting (XSS) vulnerability in read_body.php in
SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary
Javascript via a javascript: URL in an IMG tag.
|
| CVE-2002-1640 |
Multiple cross-site scripting (XSS) vulnerabilities in Oracle
Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote
attackers to inject arbitrary web script or HTML via (1) Text Features
in the DHTML UI or (2) the test parameter to the
oracle.apps.cz.servlet.UiServlet servlet.
|
| CVE-2002-1636 |
Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for
Oracle 9i Application Server (9iAS) allows remote attackers to inject
arbitrary web script or HTML via the cbuf parameter to htp.print.
|
| CVE-2002-1567 |
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows
remote attackers to execute arbitrary web script and steal cookies via
a URL with encoded newlines followed by a request to a .jsp file whose
name contains the script.
|
| CVE-2002-1533 |
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine
allows remote attackers to insert arbitrary HTML or script via an HTTP
request to a .jsp file whose name contains the malicious script and
some encoded linefeed characters (%0a).
|
| CVE-2002-1529 |
Cross-site scripting (XSS) vulnerability in msgError.asp for the
administrative web interface (STEMWADM) for SurfControl SuperScout
Email Filter allows remote attackers to insert arbitrary script or
HTML via the Reason parameter.
|
| CVE-2002-1527 |
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine
the full pathname for emumail.cgi via a malformed string containing
script, which generates a regular expression matching error that
includes the pathname in the resulting error message.
|
| CVE-2002-1526 |
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU
Webmail 5.0 allows remote attackers to inject arbitrary HTML or script
via the email address field.
|
| CVE-2002-1497 |
Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and
earlier allows remote attackers to insert arbitrary HTML into a "404
Not Found" response.
|
| CVE-2002-1495 |
Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows
remote attackers to insert arbitrary script or HTML via (1) attached
file names in the Read Mail feature, (2) text/html mails that are
displayed in a pop-up window, and (3) certain malicious attributes
within otherwise safe tags, such as onMouseOver.
|
| CVE-2002-1494 |
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows
remote attackers to insert arbitrary HTML or script by inserting the
script after a trailing / character, which inserts the script into the
resulting error message.
|
| CVE-2002-1493 |
Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook
allows remote attackers to inject arbitrary script via (1) STYLE
attributes or (2) SRC attributes in an IMG tag.
|
| CVE-2002-1480 |
Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows
remote attackers to inject arbitrary HTML or script into guestbook
pages, which is executed when the administrator deletes the entry.
|
| CVE-2002-1464 |
Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool
allows remote attackers to insert arbitrary HTML or script via the GPC
variable.
|
| CVE-2002-1460 |
L-Forum 2.40 and earlier does not properly verify whether a file was
uploaded or if the associated variables were set by POST (attachment,
attachment_name, attachment_size and attachment_type), which allows
remote attackers to read arbitrary files.
|
| CVE-2002-1459 |
Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when
the "Enable HTML in messages" option is off, allows remote attackers
to insert arbitrary script or HTML via message fields including (1)
From, (2) E-Mail, and (3) Subject.
|
| CVE-2002-1458 |
Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when
the "Enable HTML in messages" option is on, allows remote attackers to
insert arbitrary script or HTML via message fields including (1) From,
(2) E-Mail, (3) Subject and (4) Body.
|
| CVE-2002-1455 |
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow
remote attackers to insert script or HTML into web pages via (1)
test.php, (2) test.shtml, or (3) redir.exe.
|
| CVE-2002-1453 |
Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows
remote attackers to insert script and HTML via a long request followed
by the malicious script, which is echoed back to the user in an error
message.
|
| CVE-2002-1445 |
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows
remote attackers to execute script as other users via a link to a
non-existent page whose name contains the script, which is inserted
into the resulting error page.
|
| CVE-2002-1434 |
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail
module of Kerio MailServer 5.0 allow remote attackers to execute HTML
script as other users via certain URLs.
|
| CVE-2002-1388 |
Cross-site scripting (XSS) vulnerability in MHonArc before 2.5.14
allows remote attackers to inject arbitrary HTML into web archive
pages via HTML mail messages.
|
| CVE-2002-1341 |
Cross-site scripting (XSS) vulnerability in read_body.php for
SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to
insert script and HTML via the (1) mailbox and (2) passed_id
parameters.
|
| CVE-2002-1335 |
Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape
an HTML tag in a frame, which allows remote attackers to insert
arbitrary web script or HTML and access files or cookies.
|
| CVE-2002-1334 |
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01
and earlier allows remote attackers to execute arbitrary web script as
other users via (1) the direct parameter in imageFolio.cgi, or (2)
nph-build.cgi.
|
| CVE-2002-1316 |
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11,
allows the web administrator to execute arbitrary commands via shell
metacharacters in the dir parameter, and possibly allows remote
attackers to exploit this vulnerability via a separate XSS issue
(CVE-2002-1315).
|
| CVE-2002-1315 |
Cross-site scripting (XSS) vulnerability in the Admin Server for
iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute
web script or HTML as the iPlanet administrator by injecting the
desired script into error logs, and possibly escalating privileges by
using the XSS vulnerability in conjunction with another issue
(CVE-2002-1316).
|
| CVE-2002-1307 |
Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier
allows remote attackers to insert script or HTML via an email message
with the script in a MIME header name.
|
| CVE-2002-1276 |
An incomplete fix for a cross-site scripting (XSS) vulnerability in
SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value
but does not save the result back to that variable, leaving it open to
cross-site scripting attacks.
|
| CVE-2002-1195 |
Cross-site scripting vulnerability (XSS) in the PHP interface for
ht://Check 1.1 allows remote web servers to insert arbitrary HTML,
including script, via a web page.
|
| CVE-2002-1187 |
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01
through 6.0 allows remote attackers to read and execute files on the
local system via web pages using the <frame> or <iframe> element and
javascript, aka "Frames Cross Site Scripting," as demonstrated using
the PrivacyPolicy.dlg resource.
|
| CVE-2002-1181 |
Multiple cross-site scripting (XSS) vulnerabilities in the
administrative web pages for Microsoft Internet Information Server
(IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as
other users through (1) a certain ASP file in the IISHELP virtual
directory, or (2) possibly other unknown attack vectors.
|
| CVE-2002-1168 |
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express
Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote
attackers to execute script as other users via an HTTP request that
contains an Location: header with a "%0a%0d" (CRLF) sequence, which
echoes the Location as an HTTP header in the server response.
|
| CVE-2002-1167 |
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express
Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote
attackers to execute script as other users via an HTTP GET request.
|
| CVE-2002-1132 |
SquirrelMail 1.2.7 and earlier allows remote attackers to determine
the absolute pathname of the options.php script via a malformed
optpage file argument, which generates an error message when the file
cannot be included in the script.
|
| CVE-2002-1131 |
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and
earlier allows remote attackers to execute script as other web users
via (1) addressbook.php, (2) options.php, (3) search.php, or (4)
help.php.
|
| CVE-2002-1060 |
Cross-site scripting (XSS) vulnerability in Blue Coat Systems
(formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security
Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers
to inject arbitrary web script or HTML via a URL to a nonexistent
hostname that includes the HTML, which is inserted into the resulting
error page.
|
| CVE-2002-1053 |
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server
before 2.2.1 allows remote attackers to execute arbitrary script via a
URL that contains a reference to a nonexistent host followed by the
script, which is included in the resulting error message.
|
| CVE-2002-1036 |
Cross-site scripting vulnerability in search.pl for Fluid Dynamics
Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to
execute web script via the (1) Rank or (2) Match parameters.
|
| CVE-2002-1009 |
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as
included in Lil' HTTP web server, allows remote attackers to execute
arbitrary web script in other web browsers via the (1) "Name" or (2)
"E-mail" parameters.
|
| CVE-2002-1006 |
Cross-site scripting (XSS) vulnerability in BBC Education Text to
Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote
attackers to execute arbitrary web script via parserl.pl.
|
| CVE-2002-0961 |
Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote
attackers to conduct unauthorized operations as other users, e.g. by
deleting clients via dltclnt.php, possibly in a SQL injection attack.
|
| CVE-2002-0960 |
Multiple cross-site scripting vulnerabilities in Voxel Dot Net CBMS
0.7 and earlier allows remote attackers to execute arbitrary script as
other CBMS users.
|
| CVE-2002-0959 |
Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote
attackers to execute arbitrary script as other users via an [img] tag
with a closing quote followed by the script.
|
| CVE-2002-0938 |
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows
remote attackers to execute arbitrary script or HTML as other web
users via the action argument in a link to setup.exe.
|
| CVE-2002-0840 |
Cross-site scripting (XSS) vulnerability in the default error page of
Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when
UseCanonicalName is "Off" and support for wildcard DNS is present,
allows remote attackers to execute script as other web page visitors
via the Host: header, a different vulnerability than CAN-2002-1157.
|
| CVE-2002-0590 |
Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows
remote attackers to execute arbitrary script and steal cookies as
other IcrediBB users via the (1) title or (2) body of posts.
|
| CVE-2002-0530 |
Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows
remote attackers to execute arbitrary script as other Web Search users
via the search parameter.
|
| CVE-2002-0326 |
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows
remote attackers to execute arbitrary script and possibly additional
commands via a URL that contains Javascript.
|
| CVE-2002-0074 |
Cross-site scripting vulnerability in Help File search facility for
Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote
attackers to embed scripts into another user's session.
|
| CVE-2001-1526 |
Cross-site scripting (XSS) vulnerability in the comments action in
index.php in easyNews 1.5 and earlier allows remote attackers to
inject arbitrary web script or HTML via the zeit parameter.
|
| CVE-2001-1524 |
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier
allows remote attackers to inject arbitrary web script or HTML via the
(1) uname parameter in user.php, (2) ttitle, letter and file
parameters in modules.php, (3) subject, story and storyext parameters
in submit.php, (4) upload parameter in admin.php and (5) fname
parameter in friend.php.
|
| CVE-2001-1523 |
Cross-site scripting (XSS) vulnerability in the DMOZGateway module for
PHP-Nuke allows remote attackers to inject arbitrary web script or
HTML via the topic parameter.
|
| CVE-2001-1522 |
Cross-site scripting (XSS) vulnerability in im.php in IMessenger for
PHP-Nuke allows remote attackers to inject arbitrary web script or
HTML via a message.
|
| CVE-2001-1521 |
Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64
allows remote attackers to inject arbitrary web script or HTML via the
uname parameter.
|
| CVE-2001-1516 |
Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and
earlier allows remote attackers to inject arbitrary web script or HTML
via user-submitted reviews.
|
| CVE-2001-1441 |
Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5
Professional allows remote attackers to execute JavaScript on other
clients via the URL, which injects the script in the resulting error
message.
|
| CVE-2001-1416 |
Multiple cross-site scripting (XSS) vulnerabilities in the log
messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4
allow remote attackers to execute arbitrary web script or HTML via an
image in the (1) DATA, (2) STYLE, or (3) BINARY tags.
|
| CVE-2000-1205 |
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11
allow remote attackers to execute script as other web site visitors
via (1) the printenv CGI (printenv.pl), which does not encode its
output, (2) pages generated by the ap_send_error_response function
such as a default 404, which does not add an explicit charset, or (3)
various messages that are generated by certain Apache modules or core
code. NOTE: the printenv issue might still exist for web browsers
that can render text/plain content types as HTML, such as Internet
Explorer, but CVE regards this as a design limitation of those
browsers, not Apache. The printenv.pl/acuparam vector, discloser on
20070724, is one such variant.
|