Latest CVE Feed
-
2.6
LOWCVE-2009-1614
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) or (2) the searchterm parameter (aka the search post form... Read more
Affected Products : leap- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1673
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.... Read more
Affected Products : vbug_tracker- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1674
Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-1675.... Read more
Affected Products : phpwebgallery- Published: Apr. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1748
Cross-site scripting (XSS) vulnerability in XMB Forum 1.9.5 allows remote attackers to inject arbitrary web script or HTML by uploading a Flash (.SWF) video that contains a getURL function call, which causes the video to be rendered without disabling Acti... Read more
Affected Products : xmb_forum- Published: Apr. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2653
Cross-site scripting (XSS) vulnerability in login_error.shtml for D-Link DSA-3100 allows remote attackers to inject arbitrary HTML or web script via an encoded uname parameter.... Read more
Affected Products : dsa-3100_airspot_gateway- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3921
Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buf... Read more
Affected Products : ios- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1745
Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third... Read more
Affected Products : bitweaver- Published: Apr. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1736
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link th... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1256
Cross-site scripting (XSS) vulnerability in guestbook.php in Soren Boysen (SkullSplitter) PHP Guestbook 2.6 allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
Affected Products : php_guestbook- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2729
Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained sol... Read more
Affected Products : photoalbum_bandw- Published: Jun. 01, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-1986
Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2011-4457
OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element.... Read more
Affected Products : owasp-java-html-sanitizer- Published: Nov. 17, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-4022
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache ... Read more
Affected Products : bind- Published: Nov. 25, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2009-4652
The (1) Conn_GetCipherInfo and (2) Conn_UsesSSL functions in src/ngircd/conn.c in ngIRCd 13 and 14, when SSL/TLS support is present and standalone mode is disabled, allow remote attackers to cause a denial of service (application crash) by sending the MOT... Read more
- Published: Feb. 26, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-1905
The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a dat... Read more
Affected Products : db2- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-2854
Multiple cross-site scripting (XSS) vulnerabilities in modfile.php in Event Horizon (EVH) 1.1.10, when magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) YourEmail and (2) VerificationNumber parameters,... Read more
Affected Products : event_horizon- Published: Jul. 25, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-1823
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.7 and 6.x before 6.x-1.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML by modifying a document head... Read more
- Published: May. 29, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-2114
Cross-site request forgery (CSRF) vulnerability in pbx/gate in Brekeke PBX 2.4.4.8 allows remote attackers to hijack the authentication of users for requests that change passwords via the pbxadmin.web.PbxUserEdit bean.... Read more
Affected Products : pbx- Published: May. 28, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-0475
Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLH... Read more
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-1721
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGES... Read more
Affected Products : sasl- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025