Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

46,116 CVEs tagged with CWE-79578 Critical, 4,982 High, 37,424 Medium, 3,096 Low, 36 Unrated.

CVE-2008-1967

Published Apr 27, 2008

Cross-site scripting (XSS) vulnerability in CFLogon/CFLogon.asp in Cezanne 6.5.1 and 7 allows remote attackers to inject arbitrary web script or HTML via the SleUserName parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1969

Published Apr 27, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun paramet…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1972

Published Apr 27, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the user account creation feature in Exponent CMS 0.96.6-GA20071003 and earlier, when the Allow Registration? configuration…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1953

Published Apr 25, 2008

Cross-site scripting (XSS) vulnerability in the Sitedesigner before 1.1.5 search template in Magnolia Enterprise Edition allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1955

Published Apr 25, 2008

Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER MyBoard 1.0.12 allows remote attackers to inject arbitrary web script or HTML via the id parameter. informati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1956

Published Apr 25, 2008

Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbitrary web script or HTML via the wiki parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1960

Published Apr 25, 2008

Cross-site scripting (XSS) vulnerability in cgi-bin/contray/search.cgi in ContRay 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1941

Published Apr 25, 2008

Cross-site scripting (XSS) vulnerability in the profile update feature in Akiva WebBoard 8.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecifi…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1385

Published Apr 23, 2008

Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1386

Published Apr 23, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the installer in Serendipity (S9Y) 1.3 allow remote attackers to inject arbitrary web script or HTML via (1) unspecified pat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1916

Published Apr 23, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to inject arbitrary web script or HTML via text…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1917

Published Apr 23, 2008

Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1906

Published Apr 22, 2008

Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a view.year a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1892

Published Apr 18, 2008

Cross-site scripting (XSS) vulnerability in bs_auth.php in Blogator-script 0.95 and 1.01 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1894

Published Apr 18, 2008

Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1896

Published Apr 18, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1888

Published Apr 18, 2008

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka pi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1025

Published Apr 17, 2008

Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1873

Published Apr 17, 2008

Cross-site scripting (XSS) vulnerability in the private message feature in Nuke ET 3.2 and 3.4, when using Internet Explorer, allows remote authenticated users to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1846

Published Apr 16, 2008

The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1848

Published Apr 16, 2008

Cross-site scripting (XSS) vulnerability in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1850

Published Apr 16, 2008

Multiple cross-site scripting (XSS) vulnerabilities in login.php in Omnistar Interactive OSI Affiliate allow remote attackers to inject arbitrary web script or HTML via the (1) lo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1787

Published Apr 15, 2008

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Poplar Gedcom Viewer 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) text and (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 45,201-45,225 of 46,116 CVEsPage 1809 of 1845