Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown

CVE-2019-10219

Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Attacker Value
Unknown

CVE-2017-17620

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
0
Attacker Value
Unknown

CVE-2015-6752

Disclosure Date: August 31, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Search API Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when the search index is configured to use the HTML filter processor, allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the returned suggestions.
0
Attacker Value
Unknown

CVE-2014-8320

Disclosure Date: October 17, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the "Label text" field to the results configuration page.
0
Attacker Value
Unknown

CVE-2014-8745

Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary label.
0
Attacker Value
Unknown

CVE-2014-7870

Disclosure Date: October 06, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with the "administer custom search" permission to inject arbitrary web script or HTML via the "Label text" field to admin/config/search/custom_search/results.
0
Attacker Value
Unknown

CVE-2013-4384

Disclosure Date: October 09, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Google Site Search module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.10 for Drupal allows remote attackers to inject arbitrary web script or HTML by causing crafted data to be returned by the Google API.
0
Attacker Value
Unknown

CVE-2013-5307

Disclosure Date: August 16, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Faceted Search (ke_search) extension before 1.4.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-2715

Disclosure Date: March 27, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the admin view in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a crafted field name.
0
Attacker Value
Unknown

CVE-2013-0181

Disclosure Date: March 27, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.
0