Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

45,610 CVEs tagged with CWE-79560 Critical, 4,831 High, 37,106 Medium, 3,075 Low, 38 Unrated.

CVE-2004-2725

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2735

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in P4DB 2.01 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) SET_PREFERENCES parameter in SetPreference…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2738

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in check_user_id.php in ZeroBoard 4.1pl4 and earlier allows remote attackers to inject arbitrary web script or HTML via the user_id parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2741

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2742

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2752

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2755

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the quer…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2756

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject arbitrary web script or HTML via the (1) forum…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2757

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote attackers to inject arb…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0203

Published Nov 23, 2004

Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0678

Published Aug 6, 2004

Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2030

Published May 22, 2004

Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demon…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1924

Published Apr 11, 2004

Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1875

Published Mar 30, 2004

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1865

Published Mar 26, 2004

Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or H…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0067

Published Feb 17, 2004

Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1347

Published Dec 31, 2003

Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) ui…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1348

Published Dec 31, 2003

Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1353

Published Dec 31, 2003

Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1370

Published Dec 31, 2003

Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook modu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1371

Published Dec 31, 2003

Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1384

Published Dec 31, 2003

Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Vo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1400

Published Dec 31, 2003

Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 45,526-45,550 of 45,610 CVEsPage 1822 of 1825