VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,700)

page 578 of 1,135
  • CVE-2017-17988MedDec 30, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.

  • CVE-2017-17986MedDec 30, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.

  • CVE-2017-17985MedDec 30, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.

  • CVE-2017-17984MedDec 30, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.

  • CVE-2017-17940MedDec 28, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.

  • CVE-2017-17938MedDec 28, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.

  • CVE-2017-16768MedDec 27, 2017
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.

  • CVE-2017-17929MedDec 27, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.

  • CVE-2017-17925MedDec 27, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.

  • CVE-2017-17909MedDec 27, 2017
    risk 0.31cvss 4.8epss 0.00

    PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.

  • CVE-2017-17828MedDec 21, 2017
    risk 0.31cvss 4.8epss 0.00

    Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter.

  • CVE-2017-17825MedDec 21, 2017
    risk 0.31cvss 4.8epss 0.00

    The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it.

  • CVE-2017-17778MedDec 20, 2017
    risk 0.31cvss 4.8epss 0.00

    Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.

  • CVE-2017-15890MedDec 15, 2017
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.

  • CVE-2017-16789MedDec 11, 2017
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3 before 3.2.0 Hotfix 7, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or HTML via the users…

  • CVE-2017-17383MedDec 6, 2017
    risk 0.31cvss 4.7epss 0.00

    Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

  • CVE-2017-12345MedNov 30, 2017
    risk 0.31cvss 4.7epss 0.00

    Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a…

  • CVE-2017-13700MedNov 17, 2017
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.

  • CVE-2017-1000213MedNov 17, 2017
    risk 0.31cvss 4.8epss 0.00

    WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search

  • CVE-2017-15039MedNov 6, 2017
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.