CVE-2006-1945: XSS
Published Apr 20, 2006
·Updated
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.
Affected Software
7 affected components
Awstats AWStats=6.3
Awstats AWStats=6.5
Awstats AWStats=6.1
Awstats AWStats=6.2
Awstats AWStats=6.0
Awstats AWStats<=6.5_1.857
Awstats AWStats=6.4
Event History
Apr 20, 2006
CVE Published
10:02 PM
Apr 21, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1945?
The severity of CVE-2006-1945 is considered high due to its potential for allowing remote attackers to execute arbitrary web scripts.
2
How do I fix CVE-2006-1945?
To fix CVE-2006-1945, upgrade to AWStats version 6.6 or later where this vulnerability has been addressed.
3
Which versions of AWStats are affected by CVE-2006-1945?
AWStats versions 6.0 through 6.5 are affected by CVE-2006-1945.
4
What kind of attack does CVE-2006-1945 enable?
CVE-2006-1945 enables cross-site scripting (XSS) attacks through the injection of arbitrary HTML or web scripts.
5
Is CVE-2006-1945 related to any other vulnerabilities?
Yes, CVE-2006-1945 may be related to CVE-2005-2732 as they share a similar core issue.