CVSS: 6.1EPSS: 0%CPEs: 68EXPL: 0CVE-2008-5720
https://notcve.org/view.php?id=CVE-2008-5720
26 Dec 2008 — Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the default error page for the org.seasar.mayaa.impl.engine.PageNotFoundException exception and possibly other exceptions. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Mayaa antes de v1.1.23 permite a atacantes remotos inyectar secuencias de comandos web o HTML mediante vectores no especificados que involucran la página de er... • http://jvn.jp/en/jp/JVN17298485/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0CVE-2007-4595
https://notcve.org/view.php?id=CVE-2007-4595
29 Aug 2007 — Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.12 allows remote attackers to inject arbitrary web script or HTML in certain circumstances involving (1) lack of charset specification within a META element or (2) a META element that specifies an unrecognized charset, which trigger automatic character set recognition by the web browser, as demonstrated by improper handling of UTF-7 data. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Mayaa anterior a 1.1.12 permite a atacant... • http://jvn.jp/jp/JVN%2338199598/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
