Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wrm-x7j4-2w7c

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.

Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.

EPSS

Процентиль: 57%
0.00359
Низкий

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 22 лет назад

Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.

EPSS

Процентиль: 57%
0.00359
Низкий

Дефекты

CWE-79