Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter to admin/robots.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Robotstats | Robotstats | 1.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/129230/RobotStats-1.0-Cross-Site-Scripting.Exploit
- http://www.exploit-db.com/exploits/35342Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98950
- http://packetstormsecurity.com/files/129230/RobotStats-1.0-Cross-Site-Scripting.Exploit
- http://www.exploit-db.com/exploits/35342Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98950
FAQ
What is CVE-2014-9349?
CVE-2014-9349 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter ...
How severe is CVE-2014-9349?
CVE-2014-9349 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9349?
Check the references section above for vendor advisories and patch information. Affected products include: Robotstats Robotstats.