Latest CVE Feed
-
4.3
MEDIUMCVE-2006-1143
Cross-site scripting (XSS) vulnerability in FTPoed Blog Engine 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment_body parameter, as used by the comment field, when posting a comment.... Read more
Affected Products : ftpoed_blog_engine- Published: Mar. 10, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3403
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the _base_href parameter in translate.php, (2) the _base_path parameter in news.inc.php, and (3) th... Read more
Affected Products : atutor- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-54038
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low... Read more
Affected Products : connect- Published: Dec. 10, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2005-3352
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.... Read more
Affected Products : http_server- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1165
Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."... Read more
Affected Products : dokuwiki- Published: Mar. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-54004
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.... Read more
Affected Products : filesystem_list_parameter- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
4.3
MEDIUMCVE-2006-1157
Cross-site scripting (XSS) vulnerability in Vz Scripts ADP Forum 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Subject field (possibly messaggio parameter) when posting a new message in post.php.... Read more
Affected Products : adp_forum- Published: Mar. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3424
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.... Read more
Affected Products : gnump3d- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-53245
In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles, that has a username with the same name as a role with read acc... Read more
- Published: Dec. 10, 2024
- Modified: Mar. 06, 2025
-
4.3
MEDIUMCVE-2005-3665
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation.... Read more
Affected Products : phpmyadmin- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1199
Cross-site scripting (XSS) vulnerability in iframe.php in daverave Link Bank allows remote attackers to inject arbitrary web script or HTML via the site parameter.... Read more
Affected Products : link_bank- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1261
Multiple cross-site scripting (XSS) vulnerabilities in ASPPortal 3.00 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : aspportal- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1417
Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in st... Read more
Affected Products : web_quiz_pro- Published: Mar. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1196
Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) p... Read more
Affected Products : qwikiwiki- Published: Mar. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1264
Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.... Read more
Affected Products : discussion- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1215
Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the origin... Read more
Affected Products : burning_board- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1233
Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.... Read more
Affected Products : wmnews- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1230
Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was l... Read more
Affected Products : vcard- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3301
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.... Read more
Affected Products : phpmyadmin- Published: Oct. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1282
CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redi... Read more
Affected Products : mybulletinboard- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025