Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-03-05 | CVE-2018-7663 | Cross-site Scripting vulnerability in Voten An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. | 6.1 |
2018-03-04 | CVE-2018-7653 | Cross-site Scripting vulnerability in Yzmcms 3.6 In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter. | 6.1 |
2018-03-04 | CVE-2018-7652 | Cross-site Scripting vulnerability in Zonemaster web GUI lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS. | 6.1 |
2018-03-02 | CVE-2017-9276 | Cross-site Scripting vulnerability in Netiq Access Manager Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter. | 6.1 |
2018-03-02 | CVE-2017-7438 | Cross-site Scripting vulnerability in Netiq Privileged Account Manager 3.1 NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter. | 6.1 |
2018-03-02 | CVE-2017-7419 | Cross-site Scripting vulnerability in Netiq Access Manager 4.2/4.3 A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider. | 6.1 |
2018-03-02 | CVE-2017-14801 | Cross-site Scripting vulnerability in Netiq Access Manager Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter. | 6.1 |
2018-03-01 | CVE-2017-6929 | Cross-site Scripting vulnerability in multiple products A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. | 6.1 |
2018-03-01 | CVE-2017-6927 | Cross-site Scripting vulnerability in multiple products Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically go through Twig autoescaping). | 6.1 |
2018-03-01 | CVE-2018-7049 | Cross-site Scripting vulnerability in Wowza Streaming Engine An issue was discovered in Wowza Streaming Engine before 4.7.1. | 6.1 |