Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-03-15 CVE-2017-6908 Cross-site Scripting vulnerability in Concrete5
An issue was discovered in concrete5 <= 5.6.3.4.
network
low complexity
concrete5 CWE-79
6.1
2017-03-15 CVE-2017-6907 Cross-site Scripting vulnerability in Open.Gl Project Open.Gl 20170212
An issue was discovered in Open.GL before 2017-03-13.
network
low complexity
open-gl-project CWE-79
6.1
2017-03-15 CVE-2017-6906 Cross-site Scripting vulnerability in Siberiancms
An issue was discovered in SiberianCMS before 4.10.0.
network
low complexity
siberiancms CWE-79
6.1
2017-03-15 CVE-2017-6905 Cross-site Scripting vulnerability in Concrete5
An issue was discovered in concrete5 <= 5.6.3.4.
network
low complexity
concrete5 CWE-79
6.1
2017-03-14 CVE-2016-8019 Cross-site Scripting vulnerability in Mcafee Virusscan Enterprise
Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows unauthenticated remote attackers to inject arbitrary web script or HTML via a crafted user input.
network
low complexity
mcafee CWE-79
6.1
2017-03-14 CVE-2016-8011 Cross-site Scripting vulnerability in Intel Security Mcafee Endpoint Security web Control 10.2.0.408
Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to inject arbitrary web script or HTML via a crafted web site.
network
low complexity
intel-security-mcafee CWE-79
6.1
2017-03-14 CVE-2017-6877 Cross-site Scripting vulnerability in Lutim Project Lutim
Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script.
network
low complexity
lutim-project CWE-79
6.1
2017-03-13 CVE-2014-3926 Cross-site Scripting vulnerability in LG Project LG
Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9 allows remote attackers to inject arbitrary web script or HTML via the "addr" parameter.
network
low complexity
lg-project CWE-79
6.1
2017-03-13 CVE-2017-6807 Cross-site Scripting vulnerability in Uninett MOD Auth Mellon
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.
network
low complexity
uninett CWE-79
6.1
2017-03-13 CVE-2017-5621 Cross-site Scripting vulnerability in Zammad
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.
network
low complexity
zammad CWE-79
6.1