Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-02-20 | CVE-2006-0800 | Cross-Site Scripting vulnerability in Postnuke Software Foundation Postnuke Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php. | 2.6 |
2006-02-19 | CVE-2006-0779 | Cross-Site Scripting vulnerability in XMB Forum XMB Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag. | 4.3 |
2006-02-15 | CVE-2006-0706 | Cross-Site Scripting vulnerability in Gastebuch Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter. | 4.3 |
2006-02-13 | CVE-2006-0663 | Cross-Site Scripting vulnerability in IBM Lotus Domino Inotes Client 6.5.4/7.0 Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename. | 4.3 |
2006-02-08 | CVE-2006-0603 | Cross-Site Scripting vulnerability in Hinton Design PHPhg Guestbook 1.2 Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter. | 6.4 |
2006-02-04 | CVE-2006-0535 | Cross-Site Scripting vulnerability in Communityserver.Org Community Server Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | 4.3 |
2006-02-04 | CVE-2006-0533 | Cross-Site Scripting vulnerability in Cpanel Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter. | 4.3 |
2006-01-26 | CVE-2006-0442 | Cross-Site Scripting vulnerability in Mybb 1.0.2 Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in an editsig action. | 4.3 |
2006-01-22 | CVE-2006-0364 | Cross-Site Scripting vulnerability in Mybulletinboard Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by "javascript". | 4.3 |
2006-01-18 | CVE-2006-0233 | Cross-Site Scripting vulnerability in Microblog 2.0Rc10 Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag. | 4.3 |