CVE-2006-7125: XSS
Published Mar 6, 2007
·Updated
Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not properly handled when the administrator views site statistics.
Affected Software
2 affected components
Joomla BSQ Sitestats=1.8.0
Joomla BSQ Sitestats=2.1.1
Remediation
Patch Available
Event History
Mar 6, 2007
CVE Published
01:19 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7125?
CVE-2006-7125 is classified as a medium-severity vulnerability due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2006-7125?
To fix CVE-2006-7125, updating Joomla BSQ Sitestats to the latest version where this vulnerability is patched is recommended.
3
What versions of Joomla BSQ Sitestats are affected by CVE-2006-7125?
CVE-2006-7125 affects Joomla BSQ Sitestats versions 1.8.0 and 2.2.1.
4
What type of vulnerability is CVE-2006-7125?
CVE-2006-7125 is a cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2006-7125?
Remote attackers can exploit CVE-2006-7125 by injecting arbitrary web scripts or HTML through the HTTP Referer header.