Vulnerabilities (CVE)

Filtered by CWE-79
Total 27423 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-2700 1 Edgephp 1 Clickbank Affiliate Marketplace Script 2010-07-13 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CVE-2009-4934 1 Esoftpro 1 Online Photo Pro 2010-07-12 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
CVE-2009-4926 1 Esoftpro 1 Online Contact Manager 2010-07-12 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b) view.php, (c) email.php, (d) edit.php, and (e) delete.php.
CVE-2010-2671 1 Ez 1 Ez Publish 2010-07-09 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary web script or HTML via the subTreeItem parameter.
CVE-2010-2479 2 Htmlpurifier, Mahara 2 Htmlpurifier, Mahara 2010-07-07 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2009-4924 1 Dan Pascu 1 Python-cjson 2010-07-06 4.3 MEDIUM N/A
Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.
CVE-2009-4910 1 Cisco 1 Asa 5580 2010-06-30 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78418.
CVE-2010-2509 1 2daybiz 1 Web Template Software 2010-06-29 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php.
CVE-2010-2514 2 Dacian Strain, Joomla 2 Com Jfaq, Joomla\! 2010-06-29 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the JFaq (com_jfaq) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the question parameter in an add2 action to index.php.
CVE-2009-1798 1 Apc 2 Network Management Card, Switched Rack Pdu 2010-06-29 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username vector for Forms/login1 is already covered by CVE-2009-4406.
CVE-2010-2503 1 Splunk 1 Splunk 2010-06-29 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) redirects, aka SPL-31067; (2) unspecified "user->user or user->admin" vectors, aka SPL-31084; or (3) unspecified "user input," aka SPL-31085.
CVE-2010-2463 1 Jamroom 1 Jamroom 2010-06-28 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.
CVE-2010-1011 2 Tim Lochmueller, Typo3 2 Mydashboard, Typo3 2010-06-25 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the myDashboard (mydashboard) extension 0.1.13 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2010-1625 1 Malcom Box 1 Lxr Cross Referencer 2010-06-24 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer before 0.9.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the search body and the results page for a search, a different vulnerability than CVE-2009-4497 and CVE-2010-1448.
CVE-2010-2422 1 Plone 1 Plone 2010-06-24 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
CVE-2010-2325 1 Ibm 2 Websphere Application Server, Zos 2010-06-24 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
CVE-2003-1334 1 Kai Blankenhorn Bitfolge 1 Simple And Nice Index File 2010-06-23 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2010-2318 1 Phpcityportal 1 Phpcityportal 2010-06-18 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in cms_data.php in PHPCityPortal 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2010-2267 1 Accoria 1 Rock Web Server 2010-06-18 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Accoria Web Server (aka Rock Web Server) 1.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the getenv sample program, (2) the desc parameter to loadstatic.cgi, (3) the name parameter to httpdcfg.cgi, or (4) the dns parameter to servercfg.cgi.
CVE-2010-1382 1 Apple 2 Mac Os X, Mac Os X Server 2010-06-18 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field.