Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2006-09-15 CVE-2006-4568 Cross-Site Scripting vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.
network
mozilla CWE-79
4.3
2006-09-13 CVE-2006-4755 Cross-Site Scripting vulnerability in Accomplishtechnology PHPmydirectory
Cross-site scripting (XSS) vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the letter parameter.
4.3
2006-09-12 CVE-2006-0032 Cross-Site Scripting vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
network
microsoft CWE-79
4.3
2006-09-12 CVE-2006-4712 Cross-Site Scripting vulnerability in Sage 1.3.6
Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScript in a content:encoded element within an item element in an RSS feed, as demonstrated by four example content:encoded elements that use XMLHttpRequest to read arbitrary local files, aka "Cross Context Scripting."
network
sage CWE-79
6.8
2006-09-05 CVE-2006-4542 Cross-Site Scripting vulnerability in multiple products
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
6.8
2006-08-23 CVE-2006-4308 Cross-Site Scripting vulnerability in Blackboard products
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML tags when posting to the Discussion Board.
network
blackboard CWE-79
4.3
2006-08-23 CVE-2006-4299 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.4
Cross-site scripting (XSS) vulnerability in tiki-searchindex.php in TikiWiki 1.9.4 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.
network
tiki CWE-79
4.3
2006-08-10 CVE-2006-4067 Cross-Site Scripting vulnerability in Cakefoundation Cakephp
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page.
4.3
2006-08-09 CVE-2006-4038 Cross-Site Scripting vulnerability in Chaossoft Gaestechaos
Multiple cross-site scripting (XSS) vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gastname or (2) gastwohnort parameters.
network
chaossoft CWE-79
4.3
2006-08-09 CVE-2006-3643 Cross-Site Scripting vulnerability in Microsoft IE and Internet Explorer
Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
network
microsoft CWE-79
6.0