Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

45,969 CVEs tagged with CWE-79569 Critical, 4,932 High, 37,342 Medium, 3,090 Low, 36 Unrated.

CVE-2006-6977

Published Feb 8, 2007

Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FreeTextBox allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6978

Published Feb 8, 2007

Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) h…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0830

Published Feb 7, 2007

Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary w…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0537

Published Jan 29, 2007

The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0519

Published Jan 26, 2007

Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0478

Published Jan 25, 2007

WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0364

Published Jan 19, 2007

Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6942

Published Jan 19, 2007

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0175

Published Jan 11, 2007

Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0136

Published Jan 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4220

Published Dec 31, 2006

Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4727

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remot…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6832

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6882

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in golden book allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7233

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.6.0, and possibly other versions before 3.5.3, allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6824

Published Dec 29, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6746

Published Dec 27, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6733

Published Dec 26, 2006

Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6734

Published Dec 26, 2006

Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6729

Published Dec 26, 2006

Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6687

Published Dec 21, 2006

Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6451

Published Dec 10, 2006

Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6401

Published Dec 10, 2006

Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 45,701-45,725 of 45,969 CVEsPage 1829 of 1839