First published: Tue Mar 06 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not properly handled when the administrator views site statistics.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla BSQ Sitestats | =1.8.0 | |
Joomla BSQ Sitestats | =2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7125 is classified as a medium-severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2006-7125, updating Joomla BSQ Sitestats to the latest version where this vulnerability is patched is recommended.
CVE-2006-7125 affects Joomla BSQ Sitestats versions 1.8.0 and 2.2.1.
CVE-2006-7125 is a cross-site scripting (XSS) vulnerability.
Remote attackers can exploit CVE-2006-7125 by injecting arbitrary web scripts or HTML through the HTTP Referer header.