Back
CVE-2002-2330
Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CWE-79
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| uninet | statsplus | 1.25 |
GitHub Security Advisory GHSA-8wrm-x7j4-2w7c
Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to...
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
1.15%
Top 36% most likely to be exploited
Threat Score
20.3 / 100
Data Sources
NVD
EPSS
GitHub