NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 53940 | CVE-2007-1768 | Cross-site scripting (XSS) vulnerability in app/helpers/application_helper.rb in Mephisto 0.7.3 and Mephisto Edge 20070325 allows remote attackers to inject arbitrary web script or HTML via the author name field in a comment. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-13 | View | |
| 21120 | CVE-2016-6319 | Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugins, allows remote attackers to inject arbitrary web script or HTML via the label parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-08-22 | View | |
| 29026 | CVE-2014-0089 | Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark. | 2 | 4.3 | Medium | 2017-01-19 | 2014-03-27 | View | |
| 26612 | CVE-2015-5460 | Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the title (cls.name variable) when creating a classification. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-21 | View | |
| 8611 | CVE-2011-1723 | Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2011-09-21 | View |
Page 2998 of 17672, showing 5 records out of 88360 total, starting on record 14986, ending on 14990