VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 276 of 2,341
  • CVE-2018-17997MedMar 21, 2019
    risk 0.43cvss 6.1epss 0.04

    LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).

  • CVE-2019-9834MedMar 15, 2019
    risk 0.43cvss 6.1epss 0.05

    The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing…

  • CVE-2019-9593MedMar 6, 2019
    risk 0.43cvss 6.1epss 0.04

    A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2019-9592MedMar 6, 2019
    risk 0.43cvss 6.1epss 0.05

    A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

  • CVE-2019-9591MedMar 6, 2019
    risk 0.43cvss 6.1epss 0.05

    A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.

  • CVE-2014-10078MedFeb 23, 2019
    risk 0.43cvss 6.1epss 0.03

    Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.

  • CVE-2019-7400MedFeb 5, 2019
    risk 0.43cvss 6.1epss 0.06

    Rukovoditel before 2.4.1 allows XSS.

  • CVE-2018-19041MedJan 31, 2019
    risk 0.43cvss 6.1epss 0.03

    The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.

  • CVE-2018-19782MedJan 30, 2019
    risk 0.43cvss 6.1epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.

  • CVE-2019-1642MedJan 23, 2019
    risk 0.43cvss 6.1epss 0.04

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software.…

  • CVE-2019-2413MedJan 16, 2019
    risk 0.43cvss 6.1epss 0.06

    Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2018-20326MedJan 2, 2019
    risk 0.43cvss 6.1epss 0.05

    ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter.

  • CVE-2018-19799MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.04

    Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.

  • CVE-2018-20485MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

  • CVE-2018-20484MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

  • CVE-2018-19933MedDec 17, 2018
    risk 0.43cvss 6.1epss 0.03

    Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.

  • CVE-2018-19828MedDec 17, 2018
    risk 0.43cvss 6.1epss 0.02

    Artica Integria IMS 5.0.83 has XSS via the search_string parameter.

  • CVE-2018-18774MedNov 20, 2018
    risk 0.43cvss 6.1epss 0.05

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.

  • CVE-2018-19136MedNov 9, 2018
    risk 0.43cvss 6.1epss 0.07

    DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.

  • CVE-2018-18776MedNov 1, 2018
    risk 0.43cvss 6.1epss 0.02

    Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.