Nessus 的 CGI abuses : XSS 系列

ID名稱嚴重性
36184Atlassian JIRA < 3.13.3 DWR 「c0-id」XSS
medium
36072SAP DB / MaxDB WebDBM 多個參數 XSS
medium
35806Tomcat Sample App cal2.jsp 'time' 參數 XSS
medium
35726Novell GroupWise < 7.03HP2 / 8.0HP1 WebAccess 多個 XSS 弱點
medium
35556Mono ASP.NET 動作屬性 XSS
medium
35452Apache Jackrabbit 「q」參數 XSS
medium
35299Apache Roller q 參數 XSS
medium
35281IceWarp Merak Mail Server < 9.4.0 IMG 標籤 XSS
medium
35258Kerio MailServer < 6.6.2 多個 XSS (KSEC-2008-12-16-01)
medium
34994WordPress wp-includes/feed.php self_link() 函式主機標頭 RSS 摘要 XSS
medium
34849MDaemon WorldClient < 10.0.2 電子郵件處理 XSS
medium
34694HP System Management Homepage < 2.1.15.210 不明 XSS
medium
34336MailMarshal Spam Quarantine Management (SQM) 多個元件 XSS
low
33947CiscoWorks Server 一般服務登入頁面 XSS
medium
33945Cisco Secure Access Control Server (ACS) CSUserCGI.exe 說明工具 XSS
medium
33928MS Site Server < 3.0 Formslogin.asp url 參數 XSS
medium
33548HP System Management Homepage < 2.1.12 不明 XSS
medium
33279CGIWrap 字元集規格弱點錯誤訊息 XSS
medium
33273Resin viewfile Servlet 檔案參數 XSS
medium
33220Adobe Flex 3 歷程記錄管理 historyFrame.html XSS
medium
33219Lyris ListManager read/search/results words 參數 XSS
medium
32506dotCMS search-results.dot search_query 參數 XSS
medium
32480Xerox DocuShare dsweb Servlet 多個 XSS
medium
32434Barracuda 垃圾郵件防火牆 cgi-bin/ldap_test.cgi email 參數 XSS
medium
32319Django 管理應用程式登入表單 XSS
medium
32136Sun Java System Web Server 搜尋模組 XSS
medium
31787SmarterMail 主旨欄位 XSS
medium
31133OSSIM Framework session/login.php dest 參數 XSS
medium
31120BEA Plumtree Portal/server.pt name 參數 XSS
medium
31117ProjectPier index.php 多個參數 XSS
medium
30217F5 BIG-IP Web 管理多個 XSS
medium
29926Sun Java System Identity Manager 多個 XSS
medium
29895IceWarp Mail Server admin/index.html message 參數 XSS
medium
29834Atlassian JIRA 500page.jsp XSS
medium
29306Websense 報告工具 WsCgiLogin.exe 使用者名稱參數 XSS
medium
29225NetScaler Web Management ws/generic_api_call.pl standalone 參數 XSS
medium
29219Mort Bay Jetty Dump Servlet (webapps/test/jsp/dump.jsp) XSS
medium
28334ht: //dig htsearch sort 參數 XSS
medium
27818ManageEngine OpManager Login.do 多個參數 XSS
medium
26927GForge account/verify.php confirm_hash 參數 XSS
medium
26196Google Mini Search Appliance search 指令碼 ie 參數 XSS
medium
26070Apache Tomcat Sample App cal2.jsp「time」參數 XSS (CVE-2006-7196)
medium
26069IceWarp Merak Mail Server < 9.0.0 BODY 元素 XSS
medium
25995Apache Tomcat SendMailServlet sendmail.jsp「mailfrom」參數 XSS
medium
25823Joomla! com_content 元件「order」參數 XSS
medium
25553FuseTalk 多個指令碼 XSS 弱點
medium
25546Apache MyFaces Tomahawk JSF 應用程式自動捲動多個 XSS 弱點
medium
25525Apache Tomcat snoop.jsp URI XSS
medium
25352HP System Management Homepage < 2.1.2 不明 XSS
medium
25289Tomcat Sample App hello.jsp 測試參數 XSS
medium