CVE-2014-9743: XSS
Cross-site scripting (XSS) vulnerability in the httpdHtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9743?
CVE-2014-9743 is classified as a medium severity vulnerability due to the possibility of cross-site scripting (XSS) exploitation.
How do I fix CVE-2014-9743?
To remediate CVE-2014-9743, update VLC Media Player to version 2.2.0 or later where the vulnerability has been patched.
What type of vulnerability is CVE-2014-9743?
CVE-2014-9743 is a cross-site scripting (XSS) vulnerability found in the web interface of VLC Media Player.
Which versions of VLC Media Player are affected by CVE-2014-9743?
CVE-2014-9743 affects VLC Media Player versions prior to 2.2.0, specifically up to version 2.1.6.
Can CVE-2014-9743 be exploited remotely?
Yes, CVE-2014-9743 allows remote attackers to execute arbitrary web scripts or HTML through the affected web interface.