First published: Mon Aug 17 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VideoLAN VLC media player | <=2.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9743 is classified as a medium severity vulnerability due to the possibility of cross-site scripting (XSS) exploitation.
To remediate CVE-2014-9743, update VLC Media Player to version 2.2.0 or later where the vulnerability has been patched.
CVE-2014-9743 is a cross-site scripting (XSS) vulnerability found in the web interface of VLC Media Player.
CVE-2014-9743 affects VLC Media Player versions prior to 2.2.0, specifically up to version 2.1.6.
Yes, CVE-2014-9743 allows remote attackers to execute arbitrary web scripts or HTML through the affected web interface.