| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter. |
| ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter. |
| ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI. |
| Open edX Ironwood.1 allows support/certificates?user= reflected XSS. |
| Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS. |
| ERPNext 11.1.47 allows blog?blog_category= Frame Injection. |
| service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter. |
| D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip parameter. |
| D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRestore or configServerip parameter. |
| cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533). |
| cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520). |
| An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated by shell metacharacters in the sysDNSHost parameter. |