CVE-2014-0339: XSS
Published Mar 16, 2014
·Updated
Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before 1.680 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Affected Software
8 affected components
webmin webmin<=1.670
webmin webmin=1.600
webmin webmin=1.610
webmin webmin=1.620
webmin webmin=1.630
webmin webmin=1.640
webmin webmin=1.650
webmin webmin=1.660
Event History
Mar 16, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·02:06 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0339?
CVE-2014-0339 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-0339?
To fix CVE-2014-0339, upgrade Webmin to version 1.680 or later.
3
What software versions are affected by CVE-2014-0339?
CVE-2014-0339 affects Webmin versions earlier than 1.680, specifically versions 1.600 to 1.670.
4
What type of attack does CVE-2014-0339 allow?
CVE-2014-0339 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
5
Where can CVE-2014-0339 be exploited?
CVE-2014-0339 can be exploited in the Webmin interface, specifically in the view.cgi functionality.