PoC Index

CVE-2014-9405

MEDIUM 5.4EPSS 1.5%

A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3.0.2, which allows malicious users to execute arbitrary code.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
1.50% chance of exploitation in the next 30 days, 73th percentile
Published
2020-01-06
Updated
2024-08-06

Proof-of-concept exploits (2)

References

Related