Latest CVE Feed
-
4.3
MEDIUMCVE-2007-4301
Multiple cross-site scripting (XSS) vulnerabilities in the management interface in WebCart 2.20 through 2.25 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : webcart- Published: Aug. 13, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3120
Cross-site scripting (XSS) vulnerability in public/code/cp_dpage.php in All In One Control Panel (AIOCP) before 1.3.017 allows remote attackers to inject arbitrary web script or HTML via the aiocp_dp parameter. NOTE: some of these details are obtained fr... Read more
Affected Products : aiocp- Published: Jun. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5060
Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values.... Read more
Affected Products : xcms- Published: Sep. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3134
Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using "A... Read more
Affected Products : photoblog- Published: Jun. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4265
Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in ProjectSelected.... Read more
Affected Products : visionproject- Published: Aug. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5052
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Vigile CMS 1.8 allow remote attackers to inject arbitrary web script or HTML via a request to the wiki module with (1) the title parameter or (2) a "title=" sequence in the PATH_INFO, or ... Read more
Affected Products : vigile_cms- Published: Sep. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4980
The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via a large integer value in the Content-Length HTTP header, which triggers a fatal Java OutOfMemoryError.... Read more
Affected Products : gcaldaemon- Published: Sep. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4434
Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : text_file_search- Published: Aug. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3202
Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document.... Read more
Affected Products : web_wiz_rich_text_editor- Published: Jun. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3243
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.... Read more
Affected Products : bbpress- Published: Jun. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3240
Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. NOTE: this can be leveraged for PHP code exec... Read more
Affected Products : wordpress- Published: Jun. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3267
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.... Read more
Affected Products : fuzzylime_forum- Published: Jun. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3281
Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : php_hosting_biller- Published: Jun. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3288
Cross-site scripting (XSS) vulnerability in the skeltoac stats (Automattic Stats) 1.0 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer field.... Read more
Affected Products : automattic_stats- Published: Jun. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4945
Multiple cross-site scripting (XSS) vulnerabilities in LetterGrade allow remote attackers to inject arbitrary web script or HTML via (1) a student's email address, (2) the year parameter to genbrws/Student/cal_month.php3, and other unspecified vectors rel... Read more
Affected Products : lettergrade- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4482
Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).... Read more
Affected Products : pool- Published: Aug. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4912
Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to... Read more
Affected Products : invision_power_board- Published: Sep. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4844
X-Diesel Unreal Commander 0.92 build 565 and 573 does not properly react to an FTP server's behavior after sending a "CWD /" command, which allows remote FTP servers to cause a denial of service (infinite loop) by (1) repeatedly sending a 550 error respon... Read more
Affected Products : unreal_commander- Published: Sep. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4544
Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).... Read more
Affected Products : wordpress_mu- Published: Aug. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4541
Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in modules/core/uim.php and (2) [url] tags in a comment in modules/core/fldm.php.... Read more
Affected Products : olatedownload- Published: Aug. 27, 2007
- Modified: Apr. 09, 2025