Latest CVE Feed
-
4.3
MEDIUMCVE-2012-1208
Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (... Read more
Affected Products : fork_cms- Published: Feb. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3056
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, ... Read more
Affected Products : phpmyadmin- Published: Aug. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-4256
index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred... Read more
Affected Products : application_framework- Published: Aug. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-1078
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for a... Read more
Affected Products : quiz_maker- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-3144
Cross-site scripting (XSS) vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Aug. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2383
Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL th... Read more
- Published: Jun. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4567
Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.... Read more
Affected Products : zen_cart- Published: Nov. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2624
Opera before 11.50 allows user-assisted remote attackers to cause a denial of service (application hang) via a large table, which is not properly handled during a print preview.... Read more
Affected Products : opera_browser- Published: Jul. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3186
CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.... Read more
- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4565
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag wi... Read more
Affected Products : xoops- Published: Nov. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1213
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.... Read more
Affected Products : zimbra- Published: Feb. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0849
Unspecified vulnerability in Oracle Java Dynamic Management Kit 5.1 allows remote attackers to affect integrity, related to HTML Adaptor.... Read more
Affected Products : java_dynamic_management_kit- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0909
Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.... Read more
- Published: Feb. 08, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3243
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.... Read more
- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-1595
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.... Read more
Affected Products : claroline- Published: Apr. 03, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-2599
Google Chrome 11 does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.... Read more
Affected Products : chrome- Published: Jun. 30, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0118
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request ... Read more
- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-2606
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165511.... Read more
Affected Products : rational_team_concert- Published: Jun. 30, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-1127
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album.... Read more
Affected Products : gallery- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-0837
Unspecified vulnerability in the Agile Technology Platform component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote attackers to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025