<SCRIPT>alert('document.domain='+document.domain)</SCRIPT>.shtml causes cross site scripting.This vulnerability appears as CVE-2014-2856. The attack may be initiated remotely. In addition, an exploit is available.
It is suggested to upgrade the affected component.