Latest CVE Feed
-
3.5
LOWCVE-2009-2083
Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy te... Read more
- Published: Jun. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-2173
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) via a crafted HTTP request to TCP port 28012.... Read more
Affected Products : carom3d- Published: Jun. 23, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-2048
Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script... Read more
Affected Products : crs customer_response_applications ip_qm unified_ccx unified_ip_contact_center_express unified_ip_ivr- Published: Jul. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-3737
Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while usin... Read more
Affected Products : db2- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4322
Cross-site scripting (XSS) vulnerability in gwtTeaming.rpc in Novell Vibe OnPrem 3 BETA allows remote authenticated users to inject arbitrary web script or HTML via the Micro Blog (aka What Are You Working On?) field.... Read more
Affected Products : vibe_onprem- Published: Jan. 07, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-0084
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-1548
The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished n... Read more
Affected Products : ctools- Published: May. 21, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0697
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML vi... Read more
- Published: Feb. 23, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0716
_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated user... Read more
Affected Products : sharepoint_server- Published: Feb. 26, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2048
Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: May. 25, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4355
Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2, when the insert or edit feature is enabled, allows remote authenticated users to inject arbitrary web script or HTML via the select_single parameter.... Read more
Affected Products : dadabik- Published: Dec. 01, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-2327
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.... Read more
Affected Products : kervinet_forum- Published: Jul. 05, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-3303
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.3 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) a plugin name, related to manage_plugin_uninstall.php; (2) an enumeration value or (3) a ... Read more
Affected Products : mantisbt- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0606
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.... Read more
Affected Products : osticket- Published: Feb. 11, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-2074
Cross-site scripting (XSS) vulnerability in Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via vocabulary names.... Read more
- Published: Jun. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-2697
Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are ... Read more
Affected Products : community_software- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0801
Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authenticated users, with "Public Back-end" group permissions, to read arbitrary files via directory traversal sequences in the controller p... Read more
- Published: Mar. 02, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2080
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : otrs- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4425
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.3.2, 10.1.3.4.0, and 10.1.3.4.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2802
Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.2 allows remote authenticated users to inject arbitrary web script or HTML via an HTML document with a .gif filename extension, related to inline attachments.... Read more
Affected Products : mantisbt- Published: Sep. 07, 2010
- Modified: Apr. 11, 2025