First published: Fri Jul 21 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AWStats | <=6.5_1.857 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3681 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-3681, upgrade to AWStats version 6.5 build 1.858 or later, where the vulnerability is addressed.
CVE-2006-3681 affects AWStats versions 6.5 build 1.857 and earlier.
CVE-2006-3681 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2006-3681 can be exploited remotely by injecting arbitrary web scripts through specific parameters.