CVE-2014-8365
Last modified
CVE-2014-8365 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Xornic Contact Us allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) email parameter to contact.php or (3) PATH_INFO to setup.php, related to the "PHP_SELF" variable.. EPSS estimates a 1.42% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Xornic Contact Us allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) email parameter to contact.php or (3) PATH_INFO to setup.php, related to the "PHP_SELF" variable.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xornic | Contact Us | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-8365?
How severe is CVE-2014-8365?
How do I fix CVE-2014-8365?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-8359Untrusted search path vulnerability in Huawei Mobile Partner…
- CVE-2014-8360Directory traversal vulnerability in inc/autoload.function.p…
- CVE-2014-8361The miniigd SOAP service in Realtek SDK allows remote attack…9.8
- CVE-2014-8362Vivint Sky Control Panel 1.1.1.9926 allows remote attackers …
- CVE-2014-8363SQL injection vulnerability in ss_handler.php in the WordPre…
- CVE-2014-8364Cross-site scripting (XSS) vulnerability in ss_handler.php i…
- CVE-2014-8366SQL injection vulnerability in openSIS 4.5 through 5.3 allow…
- CVE-2014-8367SQL injection vulnerability in Aruba Networks ClearPass Poli…
- CVE-2014-8368The web interface in Aruba Networks AirWave before 7.7.14 an…
- CVE-2014-8369The kvm_iommu_map_pages function in virt/kvm/iommu.c in the …7.8
- CVE-2014-8370VMware Workstation 10.x before 10.0.5, VMware Player 6.x bef…
- CVE-2014-8371VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, …
Are you affected by CVE-2014-8365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
