Latest CVE Feed
-
4.3
MEDIUMCVE-2008-7141
Cross-site scripting (XSS) vulnerability in setup.php in @lex Poll 2.1 allows remote attackers to inject arbitrary web script or HTML via the language_setup parameter. NOTE: the provenance of this information is unknown; the details are obtained solely f... Read more
Affected Products : \@lex_poll- Published: Sep. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4670
Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via the search box. NOTE: the provenance of this information is unknown; the details are obtained solely fr... Read more
Affected Products : clickbank_portal- Published: Oct. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4727
Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote attackers to inject arbitrary web script or HTML via the addr1 parameter. NOTE: this might be resultant fro... Read more
Affected Products : banner_student- Published: Oct. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4334
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the IP parameter.... Read more
Affected Products : php-stats- Published: Aug. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4751
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg parameter, a different vector than CVE-2005-4597.... Read more
Affected Products : ipei_guestbook- Published: Oct. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3016
Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a j... Read more
Affected Products : safari- Published: Aug. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4802
Cross-site scripting (XSS) vulnerability in complete.php in Simple PHP Scripts blog 0.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained sol... Read more
Affected Products : blog- Published: Oct. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3010
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS)... Read more
- Published: Aug. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3007
Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a vis... Read more
- Published: Aug. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4909
Cross-site request forgery (CSRF) vulnerability in CompactCMS 1.1 and earlier allows remote attackers to perform unauthorized actions as legitimate users via unspecified vectors.... Read more
Affected Products : compact_cms- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2920
Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component and (2) priority parameters to buglist.php; and the (3) Username (4) E-mail, (5) Pass, and (6) Confirm p... Read more
Affected Products : elvinbts- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2893
Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter.... Read more
Affected Products : xzero_community_classifieds- Published: Aug. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2433
Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.... Read more
- Published: Jul. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2771
Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/.... Read more
Affected Products : free_arcade_script- Published: Aug. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6969
Multiple cross-site scripting (XSS) vulnerabilities in checkout.php in Avactis Shopping Cart 1.8.0 and 1.8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) step_id and (2) CHECKOUT_CZ_BLOWFISH_KEY parameters.... Read more
Affected Products : avactis_shopping_cart- Published: Aug. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5061
Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL.... Read more
Affected Products : mini_web_calendar- Published: Nov. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6924
Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email, (3) password, (4) password2, (5) security_code, and (6) register ... Read more
Affected Products : esyndicat- Published: Aug. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5072
vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash) via a malformed FLV file.... Read more
Affected Products : mega_codec_pack- Published: Nov. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4945
Multiple cross-site scripting (XSS) vulnerabilities in LetterGrade allow remote attackers to inject arbitrary web script or HTML via (1) a student's email address, (2) the year parameter to genbrws/Student/cal_month.php3, and other unspecified vectors rel... Read more
Affected Products : lettergrade- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-1930
Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers... Read more
Affected Products : cyber_recruiter- Published: Feb. 10, 2014
- Modified: Apr. 11, 2025