Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3528
Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter.... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Nov. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-4591
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[access_forbiden] and (2) lang[ident_title] parameters.... Read more
Affected Products : phpwebgallery- Published: Oct. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-4278
Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : moodle- Published: Jul. 16, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1895
CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) at... Read more
Affected Products : forefront_unified_access_gateway- Published: Oct. 12, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4568
Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as demonstr... Read more
Affected Products : mediawiki- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1922
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers imp... Read more
Affected Products : unbound- Published: May. 31, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-0472
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : controllogix_1756-enbt\/a_ethernet\/_ip_bridge- Published: Feb. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-4045
Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document.... Read more
- Published: Apr. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1962
Microsoft Internet Explorer 6 through 9 does not properly handle unspecified character sequences, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers "inactive filtering," aka "Shift J... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_server_2003 windows_vista windows_xp- Published: Aug. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1416
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possi... Read more
Affected Products : contact_form_\&_lead_form_elementor_builder- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-1360
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified document... Read more
Affected Products : http_server- Published: Oct. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUM- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-4038
Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified... Read more
- Published: Feb. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5132
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."... Read more
Affected Products : mybb- Published: Aug. 30, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4598
The handle_request_info function in channels/chan_sip.c in Asterisk Open Source 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2, when automon is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via... Read more
Affected Products : asterisk- Published: Dec. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1941
Open redirect vulnerability in the redirector feature in phpMyAdmin 3.4.x before 3.4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.... Read more
Affected Products : phpmyadmin- Published: Jan. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3906
CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.... Read more
- Published: Sep. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-1953
Multiple cross-site scripting (XSS) vulnerabilities in common.php in Post Revolution before 0.8.0c-2 allow remote attackers to inject arbitrary web script or HTML via an attribute of a (1) P, a (2) STRONG, a (3) A, a (4) EM, a (5) I, a (6) IMG, a (7) LI, ... Read more
Affected Products : post_revolution- Published: Jun. 06, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0471
Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.... Read more
Affected Products : phpbb- Published: Jan. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-3441
libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.... Read more
Affected Products : iphone_os- Published: Nov. 11, 2011
- Modified: Apr. 11, 2025