• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-13392

February 26, 2023 by

A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote JavaScript in a victim’s browser via a specially crafted POST request. The application will reflect the recipient value if it is not in the NateMail recipient array. Note that this array is keyed via integers by default, so any string input will be invalid.

CVE-2019-13397

February 26, 2023 by

Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.

CVE-2019-13339

February 26, 2023 by

In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user’s cookie.

CVE-2019-13340

February 26, 2023 by

In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user’s cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.

CVE-2019-13341

February 26, 2023 by

In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user’s cookie.

CVE-2019-13345

February 26, 2023 by

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1178
  • Go to page 1179
  • Go to page 1180
  • Go to page 1181
  • Go to page 1182
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE