VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 278 of 2,341
  • CVE-2018-15608MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.02

    Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

  • CVE-2018-15596MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.02

    An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't…

  • CVE-2018-0715MedAug 27, 2018
    risk 0.43cvss 6.1epss 0.03

    Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.

  • CVE-2018-15533MedAug 21, 2018
    risk 0.43cvss 6.1epss 0.03

    A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005.

  • CVE-2018-1000638MedAug 20, 2018
    risk 0.43cvss 6.1epss 0.02

    MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.

  • CVE-2018-13849MedJul 10, 2018
    risk 0.43cvss 6.1epss 0.02

    edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.

  • CVE-2018-8738MedJul 5, 2018
    risk 0.43cvss 6.1epss 0.02

    Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.

  • CVE-2018-13134MedJul 4, 2018
    risk 0.43cvss 6.1epss 0.02

    TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.

  • CVE-2018-12905MedJun 27, 2018
    risk 0.43cvss 6.1epss 0.42

    joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.

  • CVE-2018-12705MedJun 24, 2018
    risk 0.43cvss 6.1epss 0.02

    DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).

  • CVE-2018-12111MedJun 11, 2018
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.

  • CVE-2018-12090MedJun 11, 2018
    risk 0.43cvss 6.1epss 0.02

    There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change.

  • CVE-2018-11522MedJun 2, 2018
    risk 0.43cvss 6.1epss 0.04

    Yosoro 1.0.4 has stored XSS.

  • CVE-2018-11628MedJun 1, 2018
    risk 0.43cvss 6.1epss 0.03

    Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS.

  • CVE-2018-11443MedMay 25, 2018
    risk 0.43cvss 6.1epss 0.03

    The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.

  • CVE-2018-11415MedMay 24, 2018
    risk 0.43cvss 6.1epss 0.08

    SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.

  • CVE-2018-11404MedMay 24, 2018
    risk 0.43cvss 6.1epss 0.02

    DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.

  • CVE-2018-11339MedMay 22, 2018
    risk 0.43cvss 6.1epss 0.04

    An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.

  • CVE-2018-5230MedMay 14, 2018
    risk 0.43cvss 6.1epss 0.38

    The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting…

  • CVE-2018-6361MedMay 11, 2018
    risk 0.43cvss 6.1epss 0.40

    Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.