VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (22,700)

page 579 of 1,135
  • CVE-2017-1000144MedNov 3, 2017
    risk 0.31cvss 4.8epss 0.00

    Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.

  • CVE-2017-1000132MedNov 3, 2017
    risk 0.31cvss 4.8epss 0.00

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.

  • CVE-2017-15948MedOct 28, 2017
    risk 0.31cvss 4.8epss 0.00

    Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account.

  • CVE-2017-15911MedOct 26, 2017
    risk 0.31cvss 4.8epss 0.00

    The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as the possibility of…

  • CVE-2017-15881MedOct 24, 2017
    risk 0.31cvss 4.8epss 0.00

    Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.

  • CVE-2017-15872MedOct 24, 2017
    risk 0.31cvss 4.8epss 0.00

    phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.

  • CVE-2017-15728MedOct 22, 2017
    risk 0.31cvss 4.8epss 0.00

    In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.

  • CVE-2017-15284MedOct 12, 2017
    risk 0.31cvss 5.4epss 0.02

    Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account.

  • CVE-2017-15188MedOct 11, 2017
    risk 0.31cvss 4.8epss 0.00

    A persistent (stored) XSS vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the hosts array parameter to module/admin_device/index.php.

  • CVE-2015-2148MedOct 6, 2017
    risk 0.31cvss 4.8epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

  • CVE-2015-2144MedOct 6, 2017
    risk 0.31cvss 4.8epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) project name parameter to project.php; the (2) use_js parameter to user.php; the (3) use_js…

  • CVE-2017-15008MedOct 4, 2017
    risk 0.31cvss 4.8epss 0.00

    PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element.

  • CVE-2017-9537MedOct 3, 2017
    risk 0.31cvss 4.8epss 0.01

    Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaScript into various vulnerable parameters.

  • CVE-2017-14983MedOct 3, 2017
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the object parameter to module/admin_conf/index.php.

  • CVE-2017-14651MedSep 21, 2017
    risk 0.31cvss 4.8epss 0.04

    WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.

  • CVE-2017-14597MedSep 19, 2017
    risk 0.31cvss 4.8epss 0.00

    AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the txtDomainName field to adminpanel/modules/pro/inc/ajax.php during addition of a domain.

  • CVE-2015-9230MedSep 12, 2017
    risk 0.31cvss 4.8epss 0.01

    In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPress, XSS is possible for remote authenticated administrators via the DBTablePrefix parameter.

  • CVE-2015-9229MedSep 12, 2017
    risk 0.31cvss 4.8epss 0.00

    In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.

  • CVE-2015-3161MedSep 6, 2017
    risk 0.31cvss 4.8epss 0.00

    The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape tags in string literals when producing JSON.

  • CVE-2016-0713MedAug 31, 2017
    risk 0.31cvss 4.7epss 0.00

    Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.