Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-04-20 CVE-2016-4849 Cross-site Scripting vulnerability in Geeklog Project Geeklog 2.1.1
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog IVYWE edition 2.1.1 allow remote attackers to inject arbitrary web script or HTML by leveraging use of the COM_getCurrentURL function in (1) public_html/layout/default/header.thtml, (2) public_html/layout/bento/header.thtml, (3) public_html/layout/fotos/header.thtml, or (4) public_html/layout/default/article/article.thtml.
network
low complexity
geeklog-project CWE-79
6.1
2017-04-20 CVE-2016-4847 Cross-site Scripting vulnerability in Ossec web UI 0.3/0.8
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.
network
low complexity
ossec CWE-79
6.1
2017-04-18 CVE-2017-7897 Cross-site Scripting vulnerability in Mantisbt 2.3.0/2.3.1
A cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x before 2.3.2) Timeline include page, used in My View (my_view_page.php) and User Information (view_user_page.php) pages, allows remote attackers to inject arbitrary code (if CSP settings permit it) through crafted PATH_INFO in a URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
network
low complexity
mantisbt CWE-79
6.1
2017-04-18 CVE-2017-7896 Cross-site Scripting vulnerability in Trendmicro Interscan Messaging Security Virtual Appliance 8.5.1.1516/9.0/9.1
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
network
low complexity
trendmicro CWE-79
6.1
2017-04-17 CVE-2017-1160 Cross-site Scripting vulnerability in IBM Financial Transaction Manager
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-04-17 CVE-2016-3038 Cross-site Scripting vulnerability in IBM Cognos Business Intelligence 10.1/10.2/10.2.2
IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-04-17 CVE-2015-8256 Cross-site Scripting vulnerability in Axis Network Camera Firmware
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
network
low complexity
axis CWE-79
6.1
2017-04-17 CVE-2016-4870 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.
network
low complexity
cybozu CWE-79
5.4
2017-04-17 CVE-2016-4866 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.
network
low complexity
cybozu CWE-79
4.8
2017-04-17 CVE-2016-4865 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.
network
low complexity
cybozu CWE-79
4.8