Search Results (42857 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-2623 1 Telaen Project 1 Telaen 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.
CVE-2013-2622 1 Uebimiau 1 Uebimiau 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in UebiMiau 2.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the "selected_theme" parameter in error.php.
CVE-2013-2572 1 Tp-link 8 Tl-sc 3130, Tl-sc 3130 Firmware, Tl-sc 3130g and 5 more 2024-11-21 7.5 High
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.
CVE-2013-2567 1 Zavio 4 F3105, F3105 Firmware, F312a and 1 more 2024-11-21 7.5 High
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.
CVE-2013-2294 1 Viewgit Project 1 Viewgit 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php or (3) Heads table in plates/summary.php.
CVE-2013-2101 2 Redhat, Theforeman 2 Satellite, Katello 2024-11-21 5.4 Medium
Katello has multiple XSS issues in various entities
CVE-2013-2092 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.
CVE-2013-2008 1 Automattic 1 Wp Super Cache 2024-11-21 6.1 Medium
WordPress Super Cache Plugin 1.3 has XSS.
CVE-2013-1951 3 Debian, Linux, Mediawiki 3 Debian Linux, Linux Kernel, Mediawiki 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
CVE-2013-1938 1 Zimbra 1 Zimbra 2024-11-21 6.1 Medium
Zimbra 2013 has XSS in aspell.php
CVE-2013-1934 2 Debian, Mantisbt 2 Debian Linux, Mantisbt 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.
CVE-2013-1932 1 Mantisbt 1 Mantisbt 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
CVE-2013-1931 2 Fedoraproject, Mantisbt 2 Fedora, Mantisbt 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
CVE-2013-1760 1 Thebuggenie 1 The Bug Genie 2024-11-21 6.1 Medium
The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities
CVE-2013-1642 1 Quixplorer Project 1 Quixplorer 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in QuiXplorer before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) dir, (2) item, (3) order, (4) searchitem, (5) selitems[], or (6) srt parameter to index.php or (7) the QUERY_STRING to index.php.
CVE-2013-1603 1 Dlink 34 Dcs-1100, Dcs-1100 Firmware, Dcs-1100l and 31 more 2024-11-21 5.3 Medium
An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03 due to hard-coded credentials that serve as a backdoor, which allows remote attackers to access the RTSP video stream.
CVE-2013-1426 1 Mahara 1 Mahara 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.
CVE-2013-1420 1 Get-simple 1 Getsimple Cms 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to filebrowser.php in admin/. NOTE: the path parameter in admin/upload.php vector is already covered by CVE-2012-6621.
CVE-2013-1410 1 Perforce 1 P4web 2024-11-21 6.1 Medium
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
CVE-2013-1353 1 Orangehrm 1 Orangehrm 2024-11-21 5.4 Medium
Orange HRM 2.7.1 allows XSS via the vacancy name.