VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 930 of 1,159
  • CVE-2017-1000495Jan 3, 2018
    risk 0.00cvss epss 0.00

    QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account

  • CVE-2017-1000491Jan 3, 2018
    risk 0.00cvss epss 0.00

    Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.

  • CVE-2017-1000425Jan 2, 2018
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.

  • CVE-2017-1000427Jan 2, 2018
    risk 0.00cvss epss 0.00

    marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

  • CVE-2017-1000426Jan 2, 2018
    risk 0.00cvss epss 0.00

    MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.

  • CVE-2017-1000431Jan 2, 2018
    risk 0.00cvss epss 0.00

    eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.

  • CVE-2017-1000442Jan 2, 2018
    risk 0.00cvss epss 0.00

    Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace

  • CVE-2015-7413Dec 21, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF19 and 8.5.0 through CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

  • CVE-2015-7518Dec 17, 2015
    risk 0.00cvss epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit…

  • CVE-2015-8247Dec 15, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remote attackers to inject arbitrary web script or HTML via the plan_name parameter to packagehistory/listusagesdata.

  • CVE-2015-4206Dec 15, 2015
    risk 0.00cvss epss 0.01

    Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266.

  • CVE-2015-6416Dec 14, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager 11.0(1) allows remote attackers to inject arbitrary web script or HTML a crafted URL, aka Bug ID CSCuw24479.

  • CVE-2015-6400Dec 13, 2015
    risk 0.00cvss epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.

  • CVE-2015-7348Dec 7, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in zTree 3.5.19.1 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to demo/en/asyncData/getNodesForBigData.php.

  • CVE-2015-6387Dec 5, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.

  • CVE-2015-6390Dec 3, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741.

  • CVE-2015-5326Nov 25, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.

  • CVE-2015-7777Nov 21, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in index.php in JosephErnest Void before 2015-10-02 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.

  • CVE-2015-7290Nov 21, 2015
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to inject arbitrary web script or HTML via the pwd parameter.

  • CVE-2015-7772Nov 20, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican…