VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 275 of 2,341
  • CVE-2019-10685MedMay 24, 2019
    risk 0.43cvss 6.1epss 0.02

    A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.

  • CVE-2019-10846MedMay 23, 2019
    risk 0.43cvss 6.1epss 0.05

    Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter.

  • CVE-2019-12189MedMay 21, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.

  • CVE-2019-8928MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.

  • CVE-2019-8927MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup,…

  • CVE-2019-8926MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.

  • CVE-2019-8924MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.

  • CVE-2019-8391MedMay 14, 2019
    risk 0.43cvss 6.1epss 0.03

    qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.

  • CVE-2019-8390MedMay 14, 2019
    risk 0.43cvss 6.1epss 0.10

    qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

  • CVE-2019-11398MedMay 8, 2019
    risk 0.43cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to…

  • CVE-2019-11564MedMay 8, 2019
    risk 0.43cvss 6.1epss 0.03

    A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request.

  • CVE-2019-7541MedMay 7, 2019
    risk 0.43cvss 6.1epss 0.03

    Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.

  • CVE-2018-20503MedMay 7, 2019
    risk 0.43cvss 6.1epss 0.04

    Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.

  • CVE-2018-20824MedMay 3, 2019
    risk 0.43cvss 6.1epss 0.38

    The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.

  • CVE-2019-11193MedApr 30, 2019
    risk 0.43cvss 6.1epss 0.02

    The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.

  • CVE-2019-11537MedApr 25, 2019
    risk 0.43cvss 6.1epss 0.05

    In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can…

  • CVE-2019-11358MedApr 20, 2019
    risk 0.43cvss 6.1epss 0.87

    jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

  • CVE-2019-10887MedApr 5, 2019
    risk 0.43cvss 6.1epss 0.06

    A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attackers to inject arbitrary HTML elements via a /DataLog.csv?log= or /AlarmLog.csv?log= or /waitlog.cgi?name= or /chart.shtml?data= or…

  • CVE-2018-12653MedMar 25, 2019
    risk 0.43cvss 6.1epss 0.03

    A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious JavaScript code in /RPT/SSRSDynamicEditReports.aspx via 'ReportId' parameter.

  • CVE-2019-7438MedMar 21, 2019
    risk 0.43cvss 6.1epss 0.04

    cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.