CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199). |
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198). |
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197). |
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217). |
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262). |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269). |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266). |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265). |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263). |
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282). |
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336). |
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes. |
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username user3 and and a long password consisting of a repetition of the string 0123456789. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes. |
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes. |
phpFK lite has XSS via the faq.php, members.php, or search.php query string or the user.php user parameter. |
LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel. |
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs. |
The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar |
nZEDb v0.7.3.3 has XSS in the 404 error page. |
Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0. |