CVE
- Id
- 6712
- CVE No.
- CVE-2002-2330
- Status
- Candidate
- Description
- Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.
- Phase
- Assigned (20071026)
- Votes
- None (candidate not yet proposed)
- Comments