Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2014-10-31 CVE-2014-8578 Cross-Site Scripting vulnerability in Openstack Horizon
Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475.
network
openstack CWE-79
3.5
2014-10-31 CVE-2014-8577 Cross-Site Scripting vulnerability in Croogo
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Contact][title] parameter to admin/contacts/contacts/add page; (2) data[Block][title] or (3) data[Block][alias] parameter to admin/blocks/blocks/edit page; (4) data[Region][title] parameter to admin/blocks/regions/add page; (5) data[Menu][title] or (6) data[Menu][alias] parameter to admin/menus/menus/add page; or (7) data[Link][title] parameter to admin/menus/links/add/menu page.
network
croogo CWE-79
4.3
2014-10-31 CVE-2014-7987 Cross-Site Scripting vulnerability in Espocrm
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.
network
espocrm CWE-79
4.3
2014-10-31 CVE-2014-2336 Cross-Site Scripting vulnerability in Fortinet Fortianalyzer Firmware and Fortimanager
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2334 and CVE-2014-2335.
network
fortinet CWE-79
4.3
2014-10-31 CVE-2014-2335 Cross-Site Scripting vulnerability in Fortinet Fortianalyzer Firmware
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.
network
fortinet CWE-79
4.3
2014-10-31 CVE-2014-2334 Cross-Site Scripting vulnerability in Fortinet Fortianalyzer Firmware
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.
network
fortinet CWE-79
4.3
2014-10-31 CVE-2014-6150 Cross-Site Scripting vulnerability in IBM Tivoli Application Dependency Discovery Manager
Cross-site scripting (XSS) vulnerability in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.0 through 7.2.1.6 and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2014-10-31 CVE-2014-6101 Cross-Site Scripting vulnerability in IBM Business Process Manager
Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manager (BPM) Advanced 7.5 through 8.5.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
4.3
2014-10-31 CVE-2014-3375 Cross-Site Scripting vulnerability in Cisco Unified Communications Manager
Multiple cross-site scripting (XSS) vulnerabilities in the CCM Service interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90597.
network
cisco CWE-79
4.3
2014-10-31 CVE-2014-3374 Cross-Site Scripting vulnerability in Cisco Unified Communications Manager
Multiple cross-site scripting (XSS) vulnerabilities in the CCM admin interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90582.
network
cisco CWE-79
4.3