CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
30937 | CVE-2008-0820 | Candidate | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in Etomite 0.6.1.4 Final allows remote attackers to inject arbitrary web script or HTML via $_SERVER["PHP_INFO"]. NOTE: the vendor disputes this issue in a followup, stating that the affected variable is $_SERVER["PHP_SELF"], and "This is not an Etomite specific exploit and I would like the report rescinded." | Assigned (20080219) | None (candidate not yet proposed) | View | |
17200 | CVE-2006-1096 | Candidate | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher"s blog, but research by CVE suggests that this might be a legitimate problem. | Assigned (20060309) | None (candidate not yet proposed) | View | |
53094 | CVE-2011-5182 | Candidate | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor disputes this issue, stating "Lanoba"s plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user"s behalf." | Assigned (20120919) | None (candidate not yet proposed) | View | |
19357 | CVE-2006-3253 | Candidate | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer." | Assigned (20060627) | None (candidate not yet proposed) | View | |
18577 | CVE-2006-2473 | Candidate | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product. The vendor states "You cannot insert code in a wikipage or via URL parameters as they are all escaped before usage, so nothing can be compromised at other sites." | Assigned (20060519) | None (candidate not yet proposed) | View |
Page 13 of 20943, showing 5 records out of 104715 total, starting on record 61, ending on 65