Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

46,006 CVEs tagged with CWE-79570 Critical, 4,943 High, 37,366 Medium, 3,091 Low, 36 Unrated.

CVE-2007-3339

Published Jun 21, 2007

Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3291

Published Jun 20, 2007

Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2450

Published Jun 14, 2007

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 thro…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-3227

Published Jun 14, 2007

Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2391

Published Jun 14, 2007

Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windo…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2007-3156

Published Jun 11, 2007

Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3137

Published Jun 8, 2007

Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3056

Published Jun 6, 2007

Cross-site scripting (XSS) vulnerability in filedetails.php in WebSVN 2.0rc4, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the path par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3064

Published Jun 6, 2007

Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2910

Published May 30, 2007

Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.6.7 PL1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2914

Published May 30, 2007

Multiple cross-site scripting (XSS) vulnerabilities in PsychoStats 3.0.6b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) awards.php, (2) lo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2811

Published May 22, 2007

Cross-site scripting (XSS) vulnerability in OSK Advance-Flow 4.41 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2745

Published May 17, 2007

Cross-site scripting (XSS) vulnerability in printcal.pl in vDesk Webmail 4.03 allows remote attackers to inject arbitrary web script or HTML via the type parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1262

Published May 11, 2007

Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7196

Published May 10, 2007

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1358

Published May 10, 2007

Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web s…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0220

Published May 8, 2007

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scrip…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2524

Published May 8, 2007

Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2337

Published Apr 27, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url paramete…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2248

Published Apr 25, 2007

Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2206

Published Apr 24, 2007

Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leadin…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 45,676-45,700 of 46,006 CVEsPage 1828 of 1841