VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 280 of 2,341
  • CVE-2018-5705MedJan 24, 2018
    risk 0.43cvss 6.1epss 0.01

    Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an…

  • CVE-2017-14096MedJan 19, 2018
    risk 0.43cvss 6.1epss 0.03

    A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload on vulnerable systems.

  • CVE-2018-5715MedJan 16, 2018
    risk 0.43cvss 6.1epss 0.07

    phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).

  • CVE-2018-5370MedJan 16, 2018
    risk 0.43cvss 6.1epss 0.02

    BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.

  • CVE-2018-5479MedJan 15, 2018
    risk 0.43cvss 6.1epss 0.02

    FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and…

  • CVE-2012-6667MedJan 11, 2018
    risk 0.43cvss 6.1epss 0.04

    Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.

  • CVE-2017-17752MedDec 20, 2017
    risk 0.43cvss 6.1epss 0.01

    Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.

  • CVE-2017-17737MedDec 18, 2017
    risk 0.43cvss 6.1epss 0.02

    The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.

  • CVE-2017-16884MedDec 7, 2017
    risk 0.43cvss 6.1epss 0.04

    Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.

  • CVE-2017-16962MedNov 27, 2017
    risk 0.43cvss 6.1epss 0.02

    The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location or details field of a Google Calendar invitation, (2) a crafted Outlook.com calendar (aka Hotmail Calendar) invitation, (3) e-mail granting…

  • CVE-2017-16841MedNov 16, 2017
    risk 0.43cvss 6.1epss 0.01

    LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.

  • CVE-2017-16836MedNov 16, 2017
    risk 0.43cvss 6.1epss 0.02

    Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.

  • CVE-2017-15878MedOct 24, 2017
    risk 0.43cvss 6.1epss 0.03

    A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.

  • CVE-2011-4333MedOct 23, 2017
    risk 0.43cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php or the (2) page_no parameter to recentchanges.php.

  • CVE-2017-15687MedOct 23, 2017
    risk 0.43cvss 6.1epss 0.01

    DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.

  • CVE-2017-7089MedOct 23, 2017
    risk 0.43cvss 6.1epss 0.07

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web…

  • CVE-2017-15291MedOct 20, 2017
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field.

  • CVE-2017-15646MedOct 19, 2017
    risk 0.43cvss 6.1epss 0.05

    Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then…

  • CVE-2017-15374MedOct 16, 2017
    risk 0.43cvss 6.1epss 0.05

    Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script code into the firstname, lastname, or order input fields to provoke persistent…

  • CVE-2017-15287MedOct 12, 2017
    risk 0.43cvss 6.1epss 0.06

    There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.