Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

46,203 CVEs tagged with CWE-79583 Critical, 5,017 High, 37,467 Medium, 3,100 Low, 36 Unrated.

CVE-2008-2698

Published Jun 13, 2008

Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2675

Published Jun 12, 2008

Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the prov…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2677

Published Jun 12, 2008

Cross-site scripting (XSS) vulnerability in edit1.php in Telephone Directory 2008 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2680

Published Jun 12, 2008

Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Cmpct…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2668

Published Jun 12, 2008

Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php, or the n…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2644

Published Jun 10, 2008

Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and 1.4f allow remote attackers to inject arbitrary web script or HTML via the (1) data parameter to catalog.php…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2646

Published Jun 10, 2008

Multiple cross-site scripting (XSS) vulnerabilities in meBiblio 0.4.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sql parameter to dbadd.inc.php, (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2637

Published Jun 10, 2008

Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2561

Published Jun 6, 2008

Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to (a) register.php, (b) rem…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2563

Published Jun 6, 2008

Multiple cross-site scripting (XSS) vulnerabilities in (1) dsp_main.php and (2) dsp_task_editor.php in SamTodo 1.1 allow remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2566

Published Jun 6, 2008

Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2567

Published Jun 6, 2008

Cross-site scripting (XSS) vulnerability in Fenriru Sleipnir 2.7.1 Release2 and earlier, Portable Sleipnir 2.7.1 Release2 and earlier, and Grani 3.1 and earlier allows remote atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2571

Published Jun 6, 2008

Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2557

Published Jun 5, 2008

Cross-site scripting (XSS) vulnerability in CRE Loaded 6.2.13.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Links and (2) Links Submit p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2553

Published Jun 5, 2008

Cross-site scripting (XSS) vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to inject arbitrar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1947

Published Jun 4, 2008

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2525

Published Jun 3, 2008

Cross-site scripting (XSS) vulnerability in the Event Database (aka rlmp_eventdb) extension before 1.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2526

Published Jun 3, 2008

Cross-site scripting (XSS) vulnerability in the WT Gallery (aka wt_gallery) extension 2.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2533

Published Jun 3, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ltarget pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2518

Published Jun 3, 2008

Cross-site scripting (XSS) vulnerability in the advanced search mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 3 allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2505

Published May 29, 2008

Cross-site scripting (XSS) vulnerability in result.php in Simpel Side Weblosning 1 through 4 allows remote attackers to inject arbitrary web script or HTML via the search paramete…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2507

Published May 29, 2008

Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear Software Calcium 3.10 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the Calen…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2508

Published May 29, 2008

Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb" parameter in voir mode.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 45,176-45,200 of 46,203 CVEsPage 1808 of 1849