Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2005-11-16 CVE-2005-3552 Cross-Site Scripting vulnerability in PHPkit
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.
network
phpkit CWE-79
4.3
2005-11-06 CVE-2005-3511 Cross-Site Scripting vulnerability in Spymac web OS 4.0
Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter in blog_newentry.php, (5) entry parameter in blog_newentry_comment.php, (6) entry parameter in blog_edit_entry.php, or (7) caldate parameter in blog.php; and (b) the notes module, including the (1) forwardid parameter in a noteform action; (2) del_folder parameter in a delete_folder action; (3) isread, (4) dateorder, (5) subjectorder, (6) curr, (7) fromorder, or (8) action parameters; (9) ppp or (10) totalreplies parameter in an Inbox action; (11) totalnotes parameter; or (12) touserid parameter in a noteform action.
network
spymac CWE-79
4.3
2005-11-04 CVE-2005-3496 Cross-Site Scripting vulnerability in PHP Handicapper PHP Handicapper
Cross-site scripting (XSS) vulnerability in PHP Handicapper allows remote attackers to inject arbitrary web script or HTML via the msg parameter to msg.php.
4.3
2005-10-23 CVE-2005-3283 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
tiki CWE-79
4.3
2005-10-14 CVE-2005-3205 Cross-Site Scripting vulnerability in Oracle Database Server 9.0.2.4
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.
network
oracle CWE-79
3.5
2005-09-24 CVE-2005-3047 Cross-Site Scripting vulnerability in PHPmyfaq 1.5.1
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.
network
phpmyfaq CWE-79
4.3
2005-09-20 CVE-2005-2981 Cross-Site Scripting vulnerability in Orionserver Orion Application Server 1.3.8/1.4.5
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
4.3
2005-09-07 CVE-2005-2818 Cross-Site Scripting vulnerability in Eric Fichot Downfile 1.3
Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.
4.3
2005-08-01 CVE-2005-2406 Cross-site Scripting vulnerability in Opera Browser 8.01
Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.
network
opera CWE-79
4.3
2005-07-13 CVE-2005-2254 Cross-Site Scripting vulnerability in Gianluca Baldo PHPauction 2.5
Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php.
4.3