Page 34 of 290 results (0.013 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en las páginas Activities en el subsistema Mobile en IBM Lotus Connections v2.5.0.0, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores no especificados. • http://secunia.com/advisories/37106 http://www-01.ibm.com/support/docview.wss?uid=swg24024303 http://www-1.ibm.com/support/docview.wss?uid=swg1LO43637 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 3%CPEs: 1EXPL: 1

Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. Vulnerabilidad de ejecución de secuencias de comandos remotos en tistios cruzados (XSS) en profiles/html/simpleSearch.do en IBM Lotus Connections v2.0.1, permite a atacantes remotos ejecutar secuencias de comandos web o HTML de su elección a través del parámetro "name". • https://www.exploit-db.com/exploits/33254 http://osvdb.org/58320 http://secunia.com/advisories/36849 http://www-01.ibm.com/support/docview.wss?uid=swg24024414 http://www-1.ibm.com/support/docview.wss?uid=swg1LO44244 http://www.securityfocus.com/bid/36513 http://www.securitytracker.com/id?1022945 http://www.vupen.com/english/advisories/2009/2760 https://exchange.xforce.ibmcloud.com/vulnerabilities/53460 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1.0 services for WebSphere Portal allow remote attackers to inject arbitrary web script or HTML via the filename of a .odt file in a Lotus Quickr place, related to the Library template. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en IBM Lotus Quickr v8.1.0 servicios para WebSphere Portal permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del nombre de fichero de un fichero .odt en Lotus Quickr place, relacionado con la plantilla Library. • http://osvdb.org/58384 http://secunia.com/advisories/36899 http://www-01.ibm.com/support/docview.wss?uid=swg1LO36646 http://www-01.ibm.com/support/docview.wss?uid=swg21405163 http://www.securityfocus.com/bid/36527 http://www.securitytracker.com/id?1022952 http://www.vupen.com/english/advisories/2009/2779 https://exchange.xforce.ibmcloud.com/vulnerabilities/53489 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K. El widget RSS reader en Lotus Notes de IBM versiones 8.0 y 8.5, guarda elementos de una fuente RSS como documentos HTML locales, lo que permite a los atacantes remotos ejecutar scripts arbitrarios en la Local Machine Zone de Internet Explorer por medio de un feed diseñado, también se conoce como SPR RGAU7RDJ9K. • http://secunia.com/advisories/36813 http://www-01.ibm.com/support/docview.wss?uid=swg21403834 http://www.scip.ch/?vuldb.4021 http://www.securityfocus.com/archive/1/506296/100/0/threaded http://www.securityfocus.com/bid/36305 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 0

Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. Vulnerabilidad no especificada en nserver.exe en el servidor de IBM Lotus Domino v8.0 para Windows Server 2003, permite a atacantes remotos provocar una denegación de servicio (caída del demonio) a través de vectores desconocidos, como se ha demostrado en cierto módulo de VulnDisco Pack Professional 8.11. NOTA: a fecha de 03/09/2009, este aviso no cuenta con más información. • http://intevydis.com/vd-list.shtml http://secunia.com/advisories/36556 •