{"id":"CVE-2014-9743","details":"Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info.","modified":"2026-04-10T03:44:57.435284Z","published":"2015-08-17T15:59:00Z","references":[{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2014/Mar/324"},{"type":"EVIDENCE","url":"http://www.quantumleap.it/vlc-reflected-xss-vulnerability/"},{"type":"WEB","url":"http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=fe5063ec5ad1873039ea719eb1f137c8f3bda84b"},{"type":"WEB","url":"http://www.securityfocus.com/bid/66307"}],"schema_version":"1.7.5"}