Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML via (1) the link parameter or (2) the User-Agent HTTP header.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.113
EPSS Ranking 93.2%