2 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

08 Dec 2010 — Multiple cross-site scripting (XSS) vulnerabilities in eSyndiCat Directory 2.3 allow remote attackers to inject arbitrary web script or HTML via the title parameter to (1) suggest-category.php and (2) suggest-listing.php. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en eSyndiCat Directory v2.3 permite a atacantes remotos inyectar código web o HTML de su elección a través del parámetro title en (1) suggest-category.php y (2) suggest-listing.php. • http://osvdb.org/69638 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 4

10 Aug 2009 — Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email, (3) password, (4) password2, (5) security_code, and (6) register parameters. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en register.php en eSyndiCat Directory v2.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante los parámetros (1) "username... • https://www.exploit-db.com/exploits/32045 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •