Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

Zstore 6.6.0 Cross Site Scripting

Zstore version 6.6.0 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#web#windows#apple#git#php#nginx#chrome#webkit
PHPJabbers Event Ticketing System Script 1.0 Cross Site Scripting

PHPJabbers Event Ticketing System Script version 1.0 suffers from a cross site scripting vulnerability.

PHPJabbers Travel Tours Script 1.0 Cross Site Scripting

PHPJabbers Travel Tours Script version 1.0 suffers from a cross site scripting vulnerability.

PHPJabbers Property Listing Script 3.1 Cross Site Scripting

PHPJabbers Property Listing Script version 3.1 suffers from a cross site scripting vulnerability.

CVE-2022-46087: Advisory_G37SYS73M/poc.md at main · G37SYS73M/Advisory_G37SYS73M

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.

CVE-2023-22333: EasyMail vulnerable to cross-site scripting

Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

CVE-2023-24065: GitHub - shihjay2/docker-nosh: NOSH ChartingSystem Dockerized

NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for health charting.

CVE-2016-15022: Correct XSS injection in check_system.php. · mosbth/cimage@401478c

A vulnerability was found in mosbth cimage up to 0.7.18. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file check_system.php. The manipulation of the argument $_SERVER['SERVER_SOFTWARE'] leads to cross site scripting. The attack can be launched remotely. Upgrading to version 0.7.19 is able to address this issue. The name of the patch is 401478c8393989836beeddfeac5ce44570af162b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-219715.

CVE-2009-10003

A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an unknown function of the file tag.php. The manipulation of the argument tag leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 0.7 is able to address this issue. The name of the patch is be23028633e8105de92f387036871c03f34d3124. It is recommended to upgrade the affected component. VDB-219714 is the identifier assigned to this vulnerability.

CVE-2023-0571

A vulnerability has been found in SourceCodester Canteen Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file createcustomer.php of the component Add Customer. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-219730 is the identifier assigned to this vulnerability.