Latest CVE Feed
-
2.6
LOWCVE-2006-2311
Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in th... Read more
- Published: Jun. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1740
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the l... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1787
Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.... Read more
Affected Products : document_server- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4567
Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a mal... Read more
- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-7304
Cross-site scripting (XSS) vulnerability in the amoCRM module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP POST data.... Read more
Affected Products : amocrm- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2024-20911
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracl... Read more
Affected Products : audit_vault_and_database_firewall- Published: Feb. 17, 2024
- Modified: Mar. 27, 2025
-
2.6
LOWCVE-2009-4172
Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the body of a news article in an addnews act... Read more
- Published: Dec. 02, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2013-5309
Cross-site scripting (XSS) vulnerability in install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and earlier, when registering a new user, allows remote attackers to inject arbitrary web script or HTML via a custom profile field to index.php. N... Read more
- Published: Aug. 16, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-0723
PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.... Read more
Affected Products : magic_news_lite- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0760
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP... Read more
Affected Products : lighttpd- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2003-1306
Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header ... Read more
Affected Products : urlscan- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-1826
Cross-site scripting (XSS) vulnerability in the iThoughtsHD app 4.19 for iOS on iPad devices, when the WiFi Transfer feature is used, allows remote attackers to inject arbitrary web script or HTML via a crafted map name.... Read more
Affected Products : ithoughtshd- Published: Mar. 26, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2010-2852
Cross-site scripting (XSS) vulnerability in modules/headlines/magpierss/scripts/magpie_debug.php in RunCms 2.1, when the Headlines module is enabled, allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
Affected Products : runcms- Published: Jul. 25, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-3022
Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report access permissions, to inject arbitrary... Read more
Affected Products : devel_module- Published: Aug. 16, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-1176
Cross-site scripting (XSS) vulnerability in function/sideblock.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to inject arbitrary web script or HTML via the sideblock4 parameter.... Read more
Affected Products : affiliate_market- Published: Mar. 06, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2001-0324
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1753
The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and f... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2974
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b... Read more
Affected Products : email_server- Published: Jun. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-1792
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the... Read more
Affected Products : online_merchant- Published: May. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-1904
Cross-site scripting (XSS) vulnerability in index.php in AnimeGenesis Gallery allows remote attackers to inject arbitrary web script or HTML via the cat parameter.... Read more
Affected Products : gallery- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025