Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

45,531 CVEs tagged with CWE-79558 Critical, 4,810 High, 37,050 Medium, 3,075 Low, 38 Unrated.

CVE-2007-5433

Published Oct 12, 2007

Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Site-Up 2.64 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5434

Published Oct 12, 2007

Cross-site scripting (XSS) vulnerability in PRO-search 0.17.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5414

Published Oct 12, 2007

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5415

Published Oct 12, 2007

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5411

Published Oct 12, 2007

Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5386

Published Oct 12, 2007

Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5385

Published Oct 12, 2007

Multiple cross-site scripting (XSS) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5370

Published Oct 11, 2007

Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5312

Published Oct 9, 2007

Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) color parameter to pjirc/css.php…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5290

Published Oct 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5291

Published Oct 9, 2007

Cross-site scripting (XSS) vulnerability in Edit.asp in DB Manager 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5292

Published Oct 9, 2007

Cross-site scripting (XSS) vulnerability in photos.cfm in Directory Image Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the backwardDirectory para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5293

Published Oct 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta (aka Phoenix) allow remote attackers to inject arbitrary web script or HTML via the (1) err_msg parameter to…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5295

Published Oct 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in index.php in (a) Wikepage Opus 13 2007.2 and (b) TipiWiki 2 allow remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5296

Published Oct 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in dblisttest.asp in dbList 8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) db, (2) pagesize, (3)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5297

Published Oct 9, 2007

Cross-site scripting (XSS) vulnerability in index.php in Minki 1.30 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5302

Published Oct 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, all…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5303

Published Oct 9, 2007

Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5304

Published Oct 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) repertimage parameter to utili…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5280

Published Oct 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in AppFuse before 2.0 Final allow remote attackers to inject arbitrary web script or HTML via unspecified input…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5255

Published Oct 6, 2007

Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance 3.4.14 allows remote attackers to inject arbitrary web script or HTML via the ie parameter to the /search…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5235

Published Oct 6, 2007

Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject arbitrary web script or HTML via the f_email parameter. N…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5228

Published Oct 5, 2007

Cross-site scripting (XSS) vulnerability in the subscription functionality in the Project issue tracking module before 4.7.x-1.5, 4.7.x-2.x before 4.7.x-2.5, and 5.x-1.x before 5.…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-3918

Published Oct 5, 2007

Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 45,076-45,100 of 45,531 CVEsPage 1804 of 1822