Latest CVE Feed
-
4.3
MEDIUMCVE-2006-2750
Cross-site scripting (XSS) vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary web scripts or HTML via failed SQL queries, which is reflected in an ... Read more
Affected Products : open_searchable_image_catalogue- Published: Jun. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3110
Cross-site scripting (XSS) vulnerability in main.php in Chipmailer 1.09 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) betreff, (3) mail, and (4) text parameters.... Read more
Affected Products : chipmailer- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-13131
An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-tool) does not properly check embedded length fields during device communication. A malicious PIV token can misreport the returned length ... Read more
- Published: Jul. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-12027
All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling bu... Read more
Affected Products : factorytalk_view- Published: Jul. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-12397
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.... Read more
- Published: May. 22, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5168
Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : pebble- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4571
Cross-site scripting (XSS) vulnerability in the LiveSearch module in Plone before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the Description field for search results, as demonstrated using the onerror Javascript even in an IM... Read more
Affected Products : plone- Published: Oct. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3023
Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) block parameters.... Read more
Affected Products : uphotogallery- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-12025
Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.... Read more
Affected Products : studio_5000_logix_designer- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2611
Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in the variable handler in MediaWiki 1.6.x before r14349 allows remote attackers to inject arbitrary Javascript via unspecified vectors, possibly involving the usage of the | (pipe) charac... Read more
Affected Products : mediawiki- Published: May. 26, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2606
Cross-site scripting (XSS) vulnerability in Chatty, possibly 1.0.2 and other versions, allows remote attackers to inject arbitrary web script or HTML via the username.... Read more
Affected Products : chatty- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-4596
Cross-site scripting (XSS) vulnerability in Shindig-Integrator 5.x, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in generated pages.... Read more
Affected Products : shindig-integrator- Published: Oct. 17, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4591
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[access_forbiden] and (2) lang[ident_title] parameters.... Read more
Affected Products : phpwebgallery- Published: Oct. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-2584
Multiple cross-site scripting (XSS) vulnerabilities in post.php in SkyeBox 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameters. NOTE: the provenance of this information is unknown; the details ar... Read more
Affected Products : skyebox- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2635
Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary web script or HTML via malformed nested HTML tags such as "<scr<script>ipt>" in (1) offset and (2) days parameters in... Read more
Affected Products : tikiwiki_cms\/groupware- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2613
Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by... Read more
- Published: May. 26, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3026
Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (2) parentcurrentpage parameter in view_gallery.asp.... Read more
Affected Products : clickgallery- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-4536
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver1 1.4.6 and earlier, Ver1 Beta 1.5.0-beta and earlier, Ver2 2.1.2a and earlier, Ver2 Beta(RC) 2.2.0-beta and earlier, Community Edition 1.3.4 and earlier, and Community Edition Nightly-Build r17319 an... Read more
Affected Products : ec-cube- Published: Oct. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4637
Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors in the advanced search feature. NOTE: this is probably a variant of CVE-2008-4121.... Read more
Affected Products : cpcommerce- Published: Oct. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3095
Multiple cross-site scripting (XSS) vulnerabilities in iPostMX 2005 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the RETURNURL parameter in (1) userlogin.cfm and (2) account.cfm.... Read more
Affected Products : ipostmx_2005- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025