CVE-2014-9349
medium
CVSS v3
—
CVSS v2
4.3
VIR risk
4.3
Description
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter to admin/robots.php.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Exploits
Exploit-DB
- EDB-35342 · dos · aix
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| robotstats | robotstats | 1.0 | |
References
- http://packetstormsecurity.com/files/129230/RobotStats-1.0-Cross-Site-Scripting.html
- http://www.exploit-db.com/exploits/35342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98950
- http://packetstormsecurity.com/files/129230/RobotStats-1.0-Cross-Site-Scripting.html
- http://www.exploit-db.com/exploits/35342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98950
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.