Back

CVE-2002-2330

Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.

Published: Dec 31, 2002 Modified: Jun 16, 2026
CWE-79

CVSS Metrics

Affected Products (1)

Vendor Product Version
uninet statsplus 1.25

GitHub Security Advisory GHSA-8wrm-x7j4-2w7c

Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.15%

Top 36% most likely to be exploited

Threat Score 20.3 / 100

Data Sources

NVD EPSS GitHub