Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

45,946 CVEs tagged with CWE-79569 Critical, 4,930 High, 37,323 Medium, 3,088 Low, 36 Unrated.

CVE-2007-4975

Published Sep 19, 2007

Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4977

Published Sep 19, 2007

Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the re…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-4981

Published Sep 19, 2007

Cross-site scripting (XSS) vulnerability in the save function in Obedit 3.03 allows user-assisted remote attackers to inject arbitrary web script or HTML via unknown vectors, as d…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4958

Published Sep 18, 2007

Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) index.php, (2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4959

Published Sep 18, 2007

Cross-site scripting (XSS) vulnerability in catalog_products_with_images.php in osCMax 2.0.0-RC3-0-1 allows remote attackers to inject arbitrary web script or HTML via the URI. N…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4945

Published Sep 18, 2007

Multiple cross-site scripting (XSS) vulnerabilities in LetterGrade allow remote attackers to inject arbitrary web script or HTML via (1) a student's email address, (2) the year pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4929

Published Sep 18, 2007

Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_inc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4912

Published Sep 17, 2007

Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary we…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4917

Published Sep 17, 2007

Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online acti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4896

Published Sep 14, 2007

Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4899

Published Sep 14, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to fo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4900

Published Sep 14, 2007

Cross-site scripting (XSS) vulnerability in the logon page in RSA EnVision 3.3.6 Build 0115 allows remote attackers to inject arbitrary web script or HTML via the username field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4465

Published Sep 14, 2007

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attac…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4882

Published Sep 14, 2007

Multiple cross-site scripting (XSS) vulnerabilities in TechExcel CustomerWise (formerly TechExcel CRM) allow remote attackers to inject arbitrary web script or HTML via unspecifie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4883

Published Sep 14, 2007

Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 1.7.x and earlier before SVN 20070910 allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4828

Published Sep 12, 2007

Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0 through 1.10.1, and the 1.11 development ver…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4830

Published Sep 12, 2007

Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the user p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4831

Published Sep 12, 2007

Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-4836

Published Sep 12, 2007

Cross-site scripting (XSS) vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4819

Published Sep 11, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4811

Published Sep 11, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to inject arbitrary web script or HTML via (1) the val parameter to alphabet.php in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4813

Published Sep 11, 2007

Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4779

Published Sep 10, 2007

Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4512

Published Sep 10, 2007

Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 45,551-45,575 of 45,946 CVEsPage 1823 of 1838