Latest CVE Feed
-
4.3
MEDIUMCVE-2008-6760
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishand... Read more
Affected Products : viart_shop- Published: Apr. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3929
Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the a parameter.... Read more
Affected Products : prestige_660h-61- Published: Jul. 31, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-1434
The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE... Read more
- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1772
Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web script or HTML via the re_route parameter to the login script.... Read more
Affected Products : activecollab- Published: May. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1732
Cross-site scripting (XSS) vulnerability in admin/usermanager in IPplan 4.91a allows remote attackers to inject arbitrary web script or HTML via the grp parameter.... Read more
Affected Products : ipplan- Published: May. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1700
The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a ... Read more
- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-2968
Cross-site scripting (XSS) vulnerability in search.php in PHP Labware LabWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input box (query parameter).... Read more
Affected Products : labwiki- Published: Jun. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-0769
QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) ICQ message, as demonstrated by an {\rtf\pict\&&} message. NOTE: the vulnerability may be in Sergey Tkach... Read more
Affected Products : qip- Published: Mar. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3201
Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than CVE-2007... Read more
Affected Products : media_player_classic- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4408
Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and possibly other versions before 1.13.2 allows remote attackers to inject arbitrary web script or HTML via the useskin parameter to an unspecified component.... Read more
Affected Products : mediawiki- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4485
Cross-site scripting (XSS) vulnerability in the ICAP patience page in Blue Coat Security Gateway OS (SGOS) 4.2 before 4.2.9, 5.2 before 5.2.5, and 5.3 before 5.3.1.7 allows remote attackers to inject arbitrary web script or HTML via the URL.... Read more
Affected Products : security_gateway_os- Published: Oct. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3196
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or HTML via the key parameter.... Read more
Affected Products : php_video_script- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3167
Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.... Read more
Affected Products : gazelle_cms- Published: Sep. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6742
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a download action and a large fs value.... Read more
Affected Products : foxy- Published: Apr. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3271
Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.... Read more
- Published: Sep. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-2951
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: US Federal Specific). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network acces... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3180
Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) pageid parameter or (2) PATH_INFO.... Read more
Affected Products : contentnow_cms- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-4056
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.... Read more
- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2644
Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and 1.4f allow remote attackers to inject arbitrary web script or HTML via the (1) data parameter to catalog.php, the (2) keyword parameter to search.php, the (3) page parameter to bb.php,... Read more
Affected Products : smeweb- Published: Jun. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2414
Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.... Read more
Affected Products : an_guestbook- Published: May. 22, 2008
- Modified: Apr. 09, 2025