CGI abuses : XSS Family for Nessus

IDNameSeverity
38649Atmail WebMail <= 5.6.0 (5.60) Email Body Injection
medium
38208Apache Struts 2 s:a / s:url Tag href Element XSS
low
38199BlackBerry Enterprise Server MDS Connection Service XSS
medium
36184Atlassian JIRA < 3.13.3 DWR 'c0-id' XSS
medium
36072SAP DB / MaxDB WebDBM Multiple Parameter XSS
medium
35806Tomcat Sample App cal2.jsp 'time' Parameter XSS
medium
35726Novell GroupWise < 7.03HP2 / 8.0HP1 WebAccess Multiple XSS
medium
35611ESET Remote Administrator < 3.0.105 Additional Report Settings XSS
medium
35556Mono ASP.NET action Attribute XSS
medium
35452Apache Jackrabbit 'q' Parameter XSS
medium
35299Apache Roller q Parameter XSS
medium
35281IceWarp Merak Mail Server < 9.4.0 IMG Tag XSS
medium
35258Kerio MailServer < 6.6.2 Multiple XSS (KSEC-2008-12-16-01)
medium
34994WordPress wp-includes/feed.php self_link() Function Host Header RSS Feed XSS
medium
34849MDaemon WorldClient < 10.0.2 Email Handling XSS
medium
34694HP System Management Homepage < 2.1.15.210 Unspecified XSS
medium
34336MailMarshal Spam Quarantine Management (SQM) Multiple Component XSS
low
33947CiscoWorks Server Common Services Login Page XSS
medium
33945Cisco Secure Access Control Server (ACS) CSUserCGI.exe Help Facility XSS
medium
33928MS Site Server < 3.0 formslogin.asp url Parameter XSS
medium
33548HP System Management Homepage < 2.1.12 Unspecified XSS
medium
33279CGIWrap Charset Specification Weakness Error Message XSS
medium
33273Resin viewfile Servlet file Parameter XSS
medium
33220Adobe Flex 3 History Management historyFrame.html XSS
medium
33219Lyris ListManager read/search/results words Parameter XSS
medium
32506dotCMS search-results.dot search_query Parameter XSS
medium
32480Xerox DocuShare dsweb Servlet Multiple XSS
medium
32434Barracuda Spam Firewall cgi-bin/ldap_test.cgi email Parameter XSS
medium
32319Django Administration Application Login Form XSS
medium
32136Sun Java System Web Server Search Module XSS
medium
31787SmarterMail Subject Field XSS
medium
31133OSSIM Framework session/login.php dest Parameter XSS
medium
31120BEA Plumtree portal/server.pt name Parameter XSS
medium
31117ProjectPier index.php Multiple Parameter XSS
medium
30217F5 BIG-IP Web Management Multiple XSS
medium
29926Sun Java System Identity Manager Multiple XSS
medium
29895IceWarp Mail Server admin/index.html message Parameter XSS
medium
29834Atlassian JIRA 500page.jsp XSS
medium
29306Websense Reporting Tools WsCgiLogin.exe username Parameter XSS
medium
29225NetScaler Web Management ws/generic_api_call.pl standalone Parameter XSS
medium
29219Mort Bay Jetty Dump Servlet (webapps/test/jsp/dump.jsp) XSS
medium
28334ht://dig htsearch sort Parameter XSS
medium
27818ManageEngine OpManager Login.do Multiple Parameter XSS
medium
26927GForge account/verify.php confirm_hash Parameter XSS
medium
26196Google Mini Search Appliance search Script ie Parameter XSS
medium
26070Apache Tomcat Sample App cal2.jsp 'time' Parameter XSS (CVE-2006-7196)
medium
26069IceWarp Merak Mail Server < 9.0.0 BODY Element XSS
medium
25995Apache Tomcat SendMailServlet sendmail.jsp 'mailfrom' Parameter XSS
medium
25823Joomla! com_content Component 'order' Parameter XSS
medium
25553FuseTalk Multiple Script XSS
medium