VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 277 of 2,341
  • CVE-2018-18775MedNov 1, 2018
    risk 0.43cvss 6.1epss 0.08

    Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.

  • CVE-2018-18548MedOct 24, 2018
    risk 0.43cvss 6.1epss 0.04

    ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.

  • CVE-2018-12650MedOct 24, 2018
    risk 0.43cvss 6.1epss 0.03

    Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlName' and 'prntFrmName'.

  • CVE-2018-18437MedOct 23, 2018
    risk 0.43cvss 6.1epss 0.02

    In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter.

  • CVE-2018-18324MedOct 15, 2018
    risk 0.43cvss 6.1epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.

  • CVE-2018-17784MedOct 10, 2018
    risk 0.43cvss 6.1epss 0.04

    Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.

  • CVE-2018-17443MedOct 8, 2018
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.

  • CVE-2018-17441MedOct 8, 2018
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.

  • CVE-2018-17593MedOct 2, 2018
    risk 0.43cvss 6.1epss 0.02

    AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

  • CVE-2018-17591MedOct 2, 2018
    risk 0.43cvss 6.1epss 0.02

    AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

  • CVE-2018-17590MedOct 2, 2018
    risk 0.43cvss 6.1epss 0.02

    AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

  • CVE-2018-17588MedOct 2, 2018
    risk 0.43cvss 6.1epss 0.02

    AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

  • CVE-2018-17587MedOct 2, 2018
    risk 0.43cvss 6.1epss 0.02

    AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

  • CVE-2018-17832MedOct 1, 2018
    risk 0.43cvss 6.1epss 0.02

    XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

  • CVE-2018-17313MedSep 26, 2018
    risk 0.43cvss 6.1epss 0.02

    On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

  • CVE-2018-17310MedSep 26, 2018
    risk 0.43cvss 6.1epss 0.02

    On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

  • CVE-2018-7355MedSep 26, 2018
    risk 0.43cvss 6.1epss 0.02

    All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS…

  • CVE-2018-12234MedSep 6, 2018
    risk 0.43cvss 6.1epss 0.03

    A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.

  • CVE-2018-16134MedAug 29, 2018
    risk 0.43cvss 6.1epss 0.04

    Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.

  • CVE-2018-15740MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.06

    Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.