NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
45396  CVE-2012-3870  Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) name or (2) description parameter.    3.5  Low  2017-01-19  2012-12-28  View
57684  CVE-2007-5621  Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.    3.5  Low  2017-01-07  2008-11-15  View
65364  CVE-2006-6821  myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account"s username in a modified MM_recordId parameter.    3.5  Low  2016-12-20  2011-03-07  View
1877  CVE-2008-1941  Cross-site scripting (XSS) vulnerability in the profile update feature in Akiva WebBoard 8.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in the form field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    3.5  Low  2017-01-03  2008-09-05  View
87893  CVE-2017-2146  Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.    3.5  Low  2017-07-18  2017-07-12  View

Page 2630 of 17672, showing 5 records out of 88360 total, starting on record 13146, ending on 13150

Actions