CVE

Id
6712  
CVE No.
CVE-2002-2330  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.  
Phase
Assigned (20071026)  
Votes
None (candidate not yet proposed)  
Comments