Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1453 Cross-Site Scripting vulnerability in Xoops
Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.
network
xoops CWE-79
4.3
2003-12-31 CVE-2003-1420 Cross-site Scripting vulnerability in Opera Browser
Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.
network
opera CWE-79
4.3
2003-12-31 CVE-2003-1400 Cross-Site Scripting vulnerability in Francisco Burzi PHP-Nuke
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.
4.3
2003-12-31 CVE-2003-1384 Cross-Site Scripting vulnerability in PY Software Py-Livredor 1.0
Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.
4.3
2003-12-31 CVE-2003-1372 Cross-Site Scripting vulnerability in Myphpnuke 1.8.8
Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.
4.3
2003-12-31 CVE-2003-1371 Cross-Site Scripting vulnerability in Nuked-Klan 1.3Beta
Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.
network
nuked-klan CWE-79
4.3
2003-12-31 CVE-2003-1370 Cross-Site Scripting vulnerability in Nuked-Klan 1.2Beta
Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.
network
nuked-klan CWE-79
4.3
2003-12-31 CVE-2003-1353 Cross-Site Scripting vulnerability in Lanifex Outreach Project Tool 0.946B
Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.
network
lanifex CWE-79
4.3
2003-12-31 CVE-2003-1348 Cross-Site Scripting vulnerability in Ftls Guestbook 1.1
Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.
network
ftls CWE-79
4.3
2003-12-31 CVE-2003-1347 Cross-Site Scripting vulnerability in Geeklog 1.3.7
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.
network
geeklog CWE-79
4.3