Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-08-24 CVE-2017-9510 Cross-site Scripting vulnerability in Atlassian Fisheye
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.
network
low complexity
atlassian CWE-79
5.4
2017-08-24 CVE-2017-9509 Cross-site Scripting vulnerability in Atlassian Crucible
The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.
network
low complexity
atlassian CWE-79
5.4
2017-08-24 CVE-2017-9508 Cross-site Scripting vulnerability in Atlassian Crucible and Fisheye
Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.
network
low complexity
atlassian CWE-79
5.4
2017-08-24 CVE-2017-9507 Cross-site Scripting vulnerability in Atlassian Crucible
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.
network
low complexity
atlassian CWE-79
5.4
2017-08-23 CVE-2017-12971 Cross-site Scripting vulnerability in Apache2Triad 1.5.4
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.
network
low complexity
apache2triad CWE-79
6.1
2017-08-23 CVE-2017-13138 Cross-site Scripting vulnerability in Qodeinteractive Bridge
DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript.
network
low complexity
qodeinteractive CWE-79
6.1
2017-08-23 CVE-2017-12844 Cross-site Scripting vulnerability in Icewarp Mail Server 10.4.4
Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user name.
network
low complexity
icewarp CWE-79
4.8
2017-08-22 CVE-2014-6189 Cross-site Scripting vulnerability in IBM products
Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
ibm CWE-79
6.1
2017-08-21 CVE-2017-7422 Cross-site Scripting vulnerability in Microfocus Enterprise Developer and Enterprise Server
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features, if this component is configured.
network
low complexity
microfocus CWE-79
5.4
2017-08-21 CVE-2017-7421 Cross-site Scripting vulnerability in Microfocus products
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.
network
low complexity
microfocus CWE-79
6.1