Latest CVE Feed
-
4.3
MEDIUMCVE-2009-3916
Cross-site scripting (XSS) vulnerability in the Node Hierarchy module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a child node title.... Read more
- Published: Nov. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1539
Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in ... Read more
Affected Products : landkarten- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4161
Cross-site scripting (XSS) vulnerability in the [AN] Search it! (an_searchit) extension 2.4.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-5918
Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.... Read more
- Published: Sep. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-6090
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.... Read more
Affected Products : mini_hosting_panel- Published: Feb. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4563
Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 Beta and release candidates before 2.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web_toolkit- Published: Nov. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4318
Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : real_estate_manager- Published: Dec. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4365
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a blog via the add_blog action, (2) approve a comment via the ... Read more
Affected Products : ez_blog- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10134
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.... Read more
Affected Products : moodle- Published: Jun. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-26595
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site mem... Read more
- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0923
Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.... Read more
Affected Products : myphpnuke- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-0933
Cross-site scripting (XSS) vulnerability in the administrative interface in Dotclear before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : dotclear- Published: Mar. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10377
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins.... Read more
Affected Products : avatar- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1332
Cross-site scripting (XSS) vulnerability in PrettyBook PrettyFormMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : prettyformmail- Published: Apr. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0484
The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.... Read more
Affected Products : cognos_tm1- Published: Jun. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0523
IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a paddin... Read more
Affected Products : websphere_commerce- Published: Jun. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1606
Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal Script allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) Keywords, (3) Tags, or (4) Desired City field.... Read more
Affected Products : nct_jobs_portal_script- Published: Apr. 29, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1320
Multiple cross-site scripting (XSS) vulnerabilities in include/zstore.php in Zazzle Store Builder 1.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) gridPage and (2) gridSort parameters. NOTE: some of these details are obtain... Read more
Affected Products : store_builder- Published: Apr. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-11273
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be a... Read more
Affected Products : pivotal_container_service- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0985
Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.... Read more
Affected Products : wordpress- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025