Latest CVE Feed
-
3.5
LOWCVE-2006-3933
Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.2.2 allows remote authenticated users to inject arbitrary web script or HTML via the message body.... Read more
Affected Products : opencms- Published: Jul. 31, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2012-3167
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.... Read more
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0828
Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticated users to inject arbitrary web script or HTML by creating a page with a crafted URI.... Read more
Affected Products : moinmoin- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3390
lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block... Read more
Affected Products : moodle- Published: Jul. 23, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-5453
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using t... Read more
Affected Products : bugzilla- Published: Oct. 23, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-1924
Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variab... Read more
Affected Products : phpmyadmin- Published: Apr. 23, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-1775
Cross-site scripting (XSS) vulnerability in mindex.do in ManageEngine Firewall Analyzer 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the displayName parameter. NOTE: the provenance of this information is unknown; the details a... Read more
- Published: Apr. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-0351
A vulnerability classified as problematic has been found in SourceCodester Engineers Online Portal 1.0. This affects an unknown part. The manipulation leads to session fixiation. It is possible to initiate the attack remotely. The complexity of an attack ... Read more
Affected Products : engineers_online_portal- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2006-0810
Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.... Read more
Affected Products : skate_board- Published: Feb. 21, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2008-2105
email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally... Read more
Affected Products : bugzilla- Published: May. 07, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-2590
Unspecified vulnerability in the Instance Management component in Oracle Database 10.1.0.5 and Enterprise Manager 10.1.0.6 has unknown impact and remote authenticated attack vectors.... Read more
- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-10558
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : form_maker- Published: Mar. 24, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-3331
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.... Read more
Affected Products : mantis- Published: Jul. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2017-5930
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.... Read more
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2020-26220
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version... Read more
Affected Products : touchbase.ai- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-47612
DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-fai... Read more
Affected Products : datadump- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
3.5
LOWCVE-2019-19090
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.... Read more
Affected Products : esoms- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2011-1029
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.... Read more
Affected Products : rational_team_concert- Published: Feb. 14, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-2090
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter.... Read more
Affected Products : ilias- Published: Mar. 02, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-4762
Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or HTML by using the "source code" feature in the customer ... Read more
Affected Products : otrs- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025