Latest CVE Feed
-
2.6
LOWCVE-2010-4783
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl and (2) urlbanner paramet... Read more
Affected Products : easy_banner_free- EPSS Score: %4.38
- Published: Apr. 07, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-4549
The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the BuildSlide... Read more
Affected Products : imageshack_toolbar- EPSS Score: %6.72
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1904
Cross-site scripting (XSS) vulnerability in index.php in AnimeGenesis Gallery allows remote attackers to inject arbitrary web script or HTML via the cat parameter.... Read more
Affected Products : gallery- EPSS Score: %0.30
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1944
Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.... Read more
Affected Products : communimail- EPSS Score: %0.95
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1224
Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.... Read more
Affected Products : guppy- EPSS Score: %9.20
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-5588
The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the... Read more
- EPSS Score: %0.21
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-1854
Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field. NOTE: the vendor has disputed this... Read more
Affected Products : bluepay_manager- EPSS Score: %0.30
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-3807
Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors.... Read more
Affected Products : sitescape_forum- EPSS Score: %0.48
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1843
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this information is unknown; the details are obtai... Read more
Affected Products : shoutbook- EPSS Score: %0.34
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3073
Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary w... Read more
- EPSS Score: %0.98
- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1818
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: por... Read more
Affected Products : warforge.news- EPSS Score: %0.35
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0870
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.... Read more
Affected Products : internet_explorer- EPSS Score: %9.12
- Published: Oct. 01, 1998
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2013-0466
Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is... Read more
Affected Products : websphere_message_broker- EPSS Score: %0.27
- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-1999-0861
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.... Read more
Affected Products : internet_information_server site_server site_server_commerce commercial_internet_system- EPSS Score: %5.46
- Published: Aug. 11, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-2723
Cross-site scripting (XSS) vulnerability in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with maestro admin permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.43
- Published: Jun. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-1999-0793
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.... Read more
Affected Products : internet_explorer- EPSS Score: %21.09
- Published: Nov. 17, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-0266
Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks. NOTE: either the old password must be known, or the attacker mu... Read more
Affected Products : eticket- EPSS Score: %0.40
- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2011-1068
Microsoft Windows Azure Software Development Kit (SDK) 1.3.x before 1.3.20121.1237, when Full IIS and a Web Role are used with an ASP.NET application, does not properly support the use of cookies for maintaining state, which allows remote attackers to obt... Read more
Affected Products : windows_azure_sdk- EPSS Score: %15.95
- Published: Feb. 23, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-1999-0827
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.... Read more
- EPSS Score: %0.88
- Published: Nov. 01, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1898
Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote attackers to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name. NOTE: the "Access... Read more
Affected Products : tinyphpforum- EPSS Score: %0.43
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025