Latest CVE Feed
-
4.3
MEDIUMCVE-2008-1987
Cross-site scripting (XSS) vulnerability in search.php in EncapsGallery 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : encapsgallery- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-48318
Cross-Site Request Forgery (CSRF) vulnerability in shen2 多说社会化评论框 allows Cross Site Request Forgery. This issue affects 多说社会化评论框: from n/a through 1.2.... Read more
Affected Products :- Published: Aug. 28, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2006-0243
Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the "Search Site" field. NOTE: the provenance of this information is unknown; the details are o... Read more
Affected Products : smbcms- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-1897
The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i b... Read more
Affected Products : asterisk_business_edition open_source asterisk_appliance_developer_kit asterisknow s800i- Published: Apr. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2006
Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a .ics file containing (1) a large 16-bit i... Read more
- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1955
Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER MyBoard 1.0.12 allows remote attackers to inject arbitrary web script or HTML via the id parameter. information.... Read more
Affected Products : myboard- Published: Apr. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2026
Cross-site scripting (XSS) vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258, and other versions before 5.3.3.378, allows remote attackers to inject arbitrary web script or HTML via a URL-encoded postdata parameter. NOTE: thi... Read more
Affected Products : authentication_agent- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2024
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.... Read more
Affected Products : minibb- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-5477
Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)... Read more
- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2009
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree fun... Read more
- Published: May. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1892
Cross-site scripting (XSS) vulnerability in bs_auth.php in Blogator-script 0.95 and 1.01 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained s... Read more
Affected Products : blogator_script- Published: Apr. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1291
ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.... Read more
- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4187
Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.... Read more
Affected Products : proactive_cms- Published: Sep. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2182
Cross-site scripting (XSS) vulnerability in the powermail extension before 1.1.10 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2212
Multiple cross-site scripting (XSS) vulnerabilities in Maian Cart 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_adminheader, (2) msg_adminheader2, (3) msg_adminheader3, (4) msg_adminheader4, and unspecified other parame... Read more
Affected Products : maian_cart- Published: May. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2048
Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web script or HTML via the sayfa parameter.... Read more
Affected Products : angelo-emlak- Published: May. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2070
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to s... Read more
Affected Products : cpanel- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2028
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.... Read more
Affected Products : minibb- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2001
Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that triggers an out-of-bounds access, possibly due to a NULL pointer dereference.... Read more
Affected Products : safari- Published: Apr. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2066
Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web script or HTML via the whatus parameter in a searchusers2 action. NOTE: it was later reported that other versions before 3.0.1 are als... Read more
Affected Products : minibb- Published: May. 02, 2008
- Modified: Apr. 09, 2025