CVE-2014-8338: XSS
Published Jan 31, 2020
·Updated
Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/specialtextscroller.php in the VideoWhisper Webcam plugins for Drupal 7.x allows remote attackers to inject arbitrary web script or HTML via a URL to a crafted SVG file in the feed parameter.
Affected Software
1 affected component
VideoWhisper Webcam Drupal=7.x-1.7
Event History
Jan 31, 2020
CVE Published
via MITRE·09:49 PM
Data Sourced
via MITRE·09:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8338?
The severity of CVE-2014-8338 is rated as medium with a CVSS score of 6.1.
2
How can I exploit the XSS vulnerability in CVE-2014-8338?
Remote attackers can exploit this XSS vulnerability by injecting arbitrary web script or HTML via a URL to a crafted SVG file in the feed parameter of the affected plugin.
3
What is the affected software in CVE-2014-8338?
The affected software in CVE-2014-8338 is Videowhisper Webcam version 7.x-1.7 for Drupal.
4
Is there a reference link for CVE-2014-8338?
Yes, you can find more information about CVE-2014-8338 at security websites like Packet Storm Security and SecurityFocus.