Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2007-01-03 CVE-2007-0045 Cross-Site Scripting vulnerability in Adobe Acrobat, Acrobat 3D and Acrobat Reader
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
network
adobe CWE-79
4.3
2006-12-31 CVE-2006-7233 Cross-Site Scripting vulnerability in Ignite Realtime Openfire 2.6.0
Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.6.0, and possibly other versions before 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the url parameter.
4.3
2006-12-31 CVE-2006-6882 Cross-Site Scripting vulnerability in Golden Book Golden Book
Cross-site scripting (XSS) vulnerability in golden book allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2006-12-31 CVE-2006-6832 Cross-Site Scripting vulnerability in Joomla
Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.
network
joomla CWE-79
4.3
2006-12-31 CVE-2006-4727 Cross-Site Scripting vulnerability in Tumbleweed Email Firewall 6.2.2Build4123
Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remote attackers to inject arbitrary web script or HTML via the (1) lineId and (2) sort parameters.
network
tumbleweed CWE-79
4.3
2006-12-31 CVE-2006-4220 Cross-Site Scripting vulnerability in Novell Groupwise and Groupwise Webaccess
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
network
novell CWE-79
4.3
2006-12-29 CVE-2006-6824 Cross-Site Scripting vulnerability in PHP Icalendar PHP Icalendar
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php, (f) rss/index.php, (g) print.php, and (h) preferences.php; the (2) cpath parameter in (i) day.php, (j) month.php, (k) year.php, (l) week.php, and (m) search.php; the (3) query parameter in search.php; and possibly the cpath, (4) unset, and (5) set parameters in a setcookie action in preferences.php; different vectors than CVE-2006-3319.
4.3
2006-12-27 CVE-2006-6746 Cross-Site Scripting vulnerability in Dreaxteam Xt-News 0.1
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
network
dreaxteam CWE-79
4.3
2006-12-26 CVE-2006-6734 Cross-Site Scripting vulnerability in Obie Website Mini web Shop 2.1.C
Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to inject arbitrary web script or HTML via the catname parameter.
4.3
2006-12-26 CVE-2006-6733 Cross-Site Scripting vulnerability in Osticket STS 1.2.7/1.3Beta
Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter.
network
osticket CWE-79
4.3