Latest CVE Feed
-
4.3
MEDIUMCVE-2010-1755
Safari in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the Accept Cookies preference, which makes it easier for remote web servers to track users via a cookie.... Read more
- Published: Jun. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-7175
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote attackers to inject arbitrary web script or HTML via the picture description field in a page edit action.... Read more
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3153
Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, id pa... Read more
Affected Products : mp3_search_engine- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3120
Cross-site scripting (XSS) vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : bigace- Published: Sep. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2959
Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : buildbot- Published: Aug. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1852
Microsoft Internet Explorer, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP ... Read more
Affected Products : internet_explorer- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2887
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter.... Read more
Affected Products : president_bios- Published: Aug. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3003
Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, w... Read more
Affected Products : internet_explorer- Published: Aug. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-3003
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : insight_diagnostics- Published: Sep. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2945
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers ... Read more
Affected Products : webauth- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1907
The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory... Read more
- Published: May. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2907
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source before 4.2.x, Hyperic HQ 4.0 Enterprise before 4.0.3.2, and Hyperic HQ 4.1 Ente... Read more
- Published: Mar. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5211
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might ... Read more
Affected Products : subrion_cms- Published: Oct. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-7205
Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and earlier allows remote attackers to read arbitrary files via vectors related to a template file.... Read more
Affected Products : virtuemart- Published: Sep. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7185
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.... Read more
Affected Products : rhythmbox- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2823
The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.... Read more
- Published: Nov. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1940
Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging ... Read more
- Published: May. 14, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2882
Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) browse_ladies.php and (2) browse_men.php, the (3) gender parameter to search.php, and the (4)... Read more
Affected Products : matchmaking- Published: Aug. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2772
Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php.... Read more
Affected Products : pg_roomate_finder_solution- Published: Aug. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2783
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.... Read more
Affected Products : xoops- Published: Aug. 17, 2009
- Modified: Apr. 09, 2025