CVE-2014-7261: Ultrapop I-Httpd

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string that is improperly rendered during construction of a directory index page, a different vulnerability than CVE-2014-7263.

Affected products

  • Ultrapop I-Httpd: affected versions not specified

Published 2014-12-12. Last modified 2026-06-17.