Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-38423: myF5

A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE
#xss#vulnerability#java
Introduction To Web Pentesting

This archive holds a whitepaper called Introduction to Web Pentesting. It provides basic configuration for Burpsuite Proxy along with basic exploitation cross site scripting, SQL injection, cross site request forgery, and open redirects. Two copies of the whitepaper are included. One is in English and one is in Bulgarian.

Perch CMS 3.2 Cross Site Scripting

Perch CMS version 3.2 suffers from a persistent cross site scripting vulnerability.

Joomla JLex GuestBook 1.6.4 Cross Site Scripting

Joomla JLex GuestBook extension version 1.6.4 suffers from a cross site scripting vulnerability.

CREDITS PREVICINI CMS 1.02 Cross Site Scripting

CREDITS PREVICINI CMS version 1.02 suffers from a cross site scripting vulnerability.

CVE-2023-33257: Verint Live-chat HTML injection

Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.

CVE-2023-26316: 产品安全中心

A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.