Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2006-02-20 CVE-2006-0800 Cross-Site Scripting vulnerability in Postnuke Software Foundation Postnuke
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
network
high complexity
postnuke-software-foundation CWE-79
2.6
2006-02-19 CVE-2006-0779 Cross-Site Scripting vulnerability in XMB Forum XMB
Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag.
network
xmb-forum CWE-79
4.3
2006-02-15 CVE-2006-0706 Cross-Site Scripting vulnerability in Gastebuch
Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.
network
gastebuch CWE-79
4.3
2006-02-13 CVE-2006-0663 Cross-Site Scripting vulnerability in IBM Lotus Domino Inotes Client 6.5.4/7.0
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java&#13;script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
network
ibm CWE-79
4.3
2006-02-08 CVE-2006-0603 Cross-Site Scripting vulnerability in Hinton Design PHPhg Guestbook 1.2
Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter.
network
low complexity
hinton-design CWE-79
6.4
2006-02-04 CVE-2006-0535 Cross-Site Scripting vulnerability in Communityserver.Org Community Server
Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
4.3
2006-02-04 CVE-2006-0533 Cross-Site Scripting vulnerability in Cpanel
Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.
network
cpanel CWE-79
4.3
2006-01-26 CVE-2006-0442 Cross-Site Scripting vulnerability in Mybb 1.0.2
Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in an editsig action.
network
mybb CWE-79
4.3
2006-01-22 CVE-2006-0364 Cross-Site Scripting vulnerability in Mybulletinboard
Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by "&#106&#97&#118&#97&#115&#99&#114&#105&#112&#116".
4.3
2006-01-18 CVE-2006-0233 Cross-Site Scripting vulnerability in Microblog 2.0Rc10
Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.
network
microblog CWE-79
4.3