CVE-2014-8380 | Splunk 6.1.1 Header Referer cross site scripting (ID 126813 / EDB-40997)
A vulnerability has been found in Splunk 6.1.1 and classified as problematic. This vulnerability affects unknown code of the component Header Handler. The manipulation of the argument Referer with the input javascript:prompt("XXS by justpentest"); leads to cross site scripting.
This vulnerability was named CVE-2014-8380. The attack can be initiated remotely. Furthermore, there is an exploit available.