Latest CVE Feed
-
4.3
MEDIUMCVE-2009-2224
Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter.... Read more
Affected Products : an_guestbook- Published: Jun. 26, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7039
Cross-site scripting (XSS) vulnerability in admin/comments.php in Gelato CMS 0.95 allows remote attackers to inject arbitrary web script or HTML via the content parameter in a comment. NOTE: some of these details are obtained from third party information... Read more
Affected Products : gelatocms- Published: Aug. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-3015
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.... Read more
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-2283
Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web Console in Solaris 10, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1288
Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login ... Read more
- Published: Apr. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1315
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter to groups_profile.php, (2) cat_id and (3) razd_id parameters to adv_cat.php, and the (4) URL to bl... Read more
Affected Products : ablespace- Published: Apr. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4372
Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML via the aIDS parameter.... Read more
Affected Products : availscript_article_script- Published: Oct. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1309
Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, w... Read more
- Published: Apr. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1343
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.5 and 6.x before 6.x-1.5, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via content titles.... Read more
- Published: Apr. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-2853
Multiple cross-site scripting (XSS) vulnerabilities in GuppY 4.5.3a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pg parameter to printfaq.php, or the (2) Referer or (3) User-Agent HTTP headers, which are not proper... Read more
Affected Products : guppy- Published: Sep. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-1413
Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arrange... Read more
Affected Products : chrome- Published: Apr. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-2750
Cross-site scripting (XSS) vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary web scripts or HTML via failed SQL queries, which is reflected in an ... Read more
Affected Products : open_searchable_image_catalogue- Published: Jun. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-6453
Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.... Read more
Affected Products : 6rbscript- Published: Mar. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1999
Unspecified vulnerability in the Business Intelligence Enterprise Edition component in unspecified Oracle Application Server versions allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : application_server- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5172
Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg parameter to (b) error.jsp and (c) userAccount.jsp. NO... Read more
Affected Products : yazd_forum_software- Published: Nov. 19, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2292
Cross-site scripting (XSS) vulnerability in Appleple a-News 2.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : a-news- Published: Jul. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5361
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionT... Read more
- Published: Dec. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5330
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject... Read more
- Published: Dec. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0057
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP sess... Read more
Affected Products : unified_communications_manager- Published: Jan. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5433
Cross-site scripting (XSS) vulnerability in login.php in PunBB 1.3 and 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the password field.... Read more
Affected Products : punbb- Published: Dec. 11, 2008
- Modified: Apr. 09, 2025