Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2016-04-08 CVE-2016-1180 Cross-site Scripting vulnerability in Cyber-Will Social-Button Premium 1.0
Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
cyber-will CWE-79
6.1
2016-04-08 CVE-2016-3978 Cross-site Scripting vulnerability in Fortinet Fortios
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."
network
low complexity
fortinet CWE-79
6.1
2016-04-07 CVE-2016-2789 Cross-site Scripting vulnerability in Citrix Xenmobile Server 10.0/10.1/10.3
Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
citrix CWE-79
6.1
2016-04-07 CVE-2016-2511 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.
network
low complexity
debian websvn CWE-79
6.1
2016-04-07 CVE-2016-3975 Cross-site Scripting vulnerability in SAP Netweaver Application Server Java
Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigation.testComponent.NavigationURLTester, aka SAP Security Note 2238375.
network
low complexity
sap CWE-79
6.1
2016-04-06 CVE-2016-1173 Cross-site Scripting vulnerability in Hiniarata Casebook Plugin 0.9.2
Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
hiniarata CWE-79
6.1
2016-04-06 CVE-2016-1171 Cross-site Scripting vulnerability in Hiniarata Casebook Plugin 0.9.2
Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
hiniarata CWE-79
6.1
2016-04-06 CVE-2016-1169 Cross-site Scripting vulnerability in Hiniarata Casebook Plugin 0.9.2/0.9.3
Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
hiniarata CWE-79
6.1
2016-04-06 CVE-2016-3969 Cross-site Scripting vulnerability in Mcafee Email Gateway
Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote attackers to inject arbitrary web script or HTML via an attachment in a blocked email.
network
low complexity
mcafee CWE-79
6.1
2016-04-06 CVE-2016-3968 Cross-site Scripting vulnerability in Sophos products
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM appliance with firmware 10.6.2 Build 378 allow remote attackers to inject arbitrary web script or HTML via the (1) ipFamily parameter to corporate/webpages/trafficdiscovery/LiveConnections.jsp; the (2) ipFamily, (3) applicationname, or (4) username parameter to corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp; or the (5) X-Forwarded-For HTTP header.
network
low complexity
sophos CWE-79
6.1