NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61168  CVE-2006-2473  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product. The vendor states "You cannot insert code in a wikipage or via URL parameters as they are all escaped before usage, so nothing can be compromised at other sites."    4.3  Medium  2016-12-20  2009-08-20  View
61932  CVE-2006-3253  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer."    2.6  Low  2016-12-20  2008-09-05  View
11442  CVE-2011-5182  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor disputes this issue, stating "Lanoba"s plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user"s behalf."    4.3  Medium  2017-01-07  2012-09-20  View
59818  CVE-2006-1096  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher"s blog, but research by CVE suggests that this might be a legitimate problem.    4.3  Medium  2016-12-20  2011-03-07  View
791  CVE-2008-0820  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in Etomite 0.6.1.4 Final allows remote attackers to inject arbitrary web script or HTML via $_SERVER["PHP_INFO"]. NOTE: the vendor disputes this issue in a followup, stating that the affected variable is $_SERVER["PHP_SELF"], and "This is not an Etomite specific exploit and I would like the report rescinded."    4.3  Medium  2017-01-03  2011-12-08  View

Page 17660 of 17672, showing 5 records out of 88360 total, starting on record 88296, ending on 88300

Actions