Total
36294 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-3606 | 1 Redhat | 1 Jboss Application Server | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution. | |||||
CVE-2011-3595 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters. | |||||
CVE-2011-3373 | 1 Drupal | 1 Views Builk Operations | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack. | |||||
CVE-2011-3370 | 1 Status | 1 Statusnet | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
statusnet before 0.9.9 has XSS | |||||
CVE-2011-3352 | 1 Ziku | 1 Zikula | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website. | |||||
CVE-2011-3202 | 1 Jcow | 1 Jcow Cms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross-Site Scripting (XSS) vulnerability exists in the g parameter to index.php in Jcow CMS 4.2 and earlier. | |||||
CVE-2011-3183 | 1 Concretecms | 1 Concrete Cms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier. | |||||
CVE-2011-2935 | 1 Elgg | 1 Elgg | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Elgg through 1.7.10 has XSS | |||||
CVE-2011-2714 | 1 Drupal | 2 Data, Drupal | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display. | |||||
CVE-2011-2706 | 1 Snewscms | 1 Snews | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71. | |||||
CVE-2011-2670 | 1 Mozilla | 1 Firefox | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets | |||||
CVE-2011-2499 | 1 Mambo-foundation | 1 Mambo Cms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Mambo CMS through 4.6.5 has multiple XSS. | |||||
CVE-2011-1497 | 1 Rubyonrails | 1 Rails | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6. | |||||
CVE-2011-1150 | 1 Bbpress | 1 Bbpress | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter. | |||||
CVE-2011-1135 | 1 S9y | 1 Serendipity | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php. | |||||
CVE-2011-1133 | 1 S9y | 1 Serendipity | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php. | |||||
CVE-2011-1086 | 1 Openfiler | 1 Openfiler | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter. | |||||
CVE-2011-1084 | 1 Smoothwall | 1 Smoothwall Express | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in Smoothwall Express 3. | |||||
CVE-2011-1069 | 1 Phpshop | 1 Phpshop | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
PHPShop through 0.8.1 has XSS. | |||||
CVE-2011-1009 | 1 Vanillaforums | 1 Vanilla | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. |