Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

46,203 CVEs tagged with CWE-79583 Critical, 5,017 High, 37,467 Medium, 3,100 Low, 36 Unrated.

CVE-2005-0563

Published Jun 14, 2005

Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1778

Published May 31, 2005

Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1619

Published May 16, 2005

Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1486

Published May 11, 2005

Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m paramet…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0251

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0896

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1006

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) the user login n…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0477

Published Mar 30, 2005

Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0485

Published Mar 30, 2005

Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0543

Published Feb 24, 2005

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerCh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1417

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1424

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1863

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2688

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2701

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2702

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2720

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript even…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2725

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2735

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in P4DB 2.01 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) SET_PREFERENCES parameter in SetPreference…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2738

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in check_user_id.php in ZeroBoard 4.1pl4 and earlier allows remote attackers to inject arbitrary web script or HTML via the user_id parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2741

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2742

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2752

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2755

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the quer…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 46,101-46,125 of 46,203 CVEsPage 1845 of 1849