Latest CVE Feed
-
4.3
MEDIUMCVE-2010-2256
Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos... Read more
Affected Products : pay_per_minute_video_chat_script- Published: Jun. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2260
Multiple cross-site scripting (XSS) vulnerabilities in Gambit Design Bandwidth Meter, 0.72 and possibly 1.2, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) view_by_name.php or (2) view_by_ip.php in admin/. NOTE: so... Read more
Affected Products : bandwidth_meter- Published: Jun. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3266
Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or c... Read more
Affected Products : opera_browser- Published: Sep. 18, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-0773
Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : pivotx- Published: Feb. 04, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0741
Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor.... Read more
Affected Products : evolution- Published: Feb. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0746
Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the ... Read more
Affected Products : o2_dsl_router_classic- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-0842
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated... Read more
- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-7488
Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.... Read more
Affected Products : authconfig- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2010-3457
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] parameter in the post comments feature in articles/a-primer-to-symphony-2s-defaul... Read more
- Published: Sep. 17, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3470
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 and 4.0.2.x before 4.0.2.7-P8AE-FP007 allow remote attackers to inject arbitrary web script or HTML ... Read more
Affected Products : filenet_p8_application_engine- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4821
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.... Read more
Affected Products : phpmyfaq- Published: Oct. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-12399
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have.... Read more
- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0733
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header in an id=- query to a .cfm file.... Read more
Affected Products : coldfusion- Published: Feb. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-15712
rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal encoded "dot dot" sequences (%2f..%2f) in the path paramet... Read more
Affected Products : rconfig- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2258
Cross-site scripting (XSS) vulnerability in signupconfirm.php in phpBannerExchange 1.2 Arabic allows remote attackers to inject arbitrary web script or HTML via the bannerurl parameter.... Read more
Affected Products : phpbannerexchange- Published: Jun. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0734
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" atta... Read more
Affected Products : coldfusion- Published: Feb. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3465
Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.... Read more
Affected Products : xse_shopping_cart- Published: Sep. 17, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3472
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : filenet_p8_application_engine- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1464
Buffer overflow in the strval function in PHP before 5.3.6, when the precision configuration option has a large value, might allow context-dependent attackers to cause a denial of service (application crash) via a small numerical value in the argument.... Read more
Affected Products : php- Published: Mar. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1504
Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://downloads URI.... Read more
Affected Products : chrome- Published: Apr. 23, 2010
- Modified: Apr. 11, 2025