CVE-2007-6307: XSS
Published Dec 11, 2007
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML via (1) the link parameter or (2) the User-Agent HTTP header.
Affected Software
1 affected component
JFree JFreeChart=1.0.8
Remediation
Patch Available
Patch Available
Event History
Dec 11, 2007
CVE Published
09:46 PM
Dec 12, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
Which deployments should be investigated?
Systems running wwwstats 3.21 are exposed through its clickstats.php endpoint. The affected component is identified as wwwstats, despite the software field listing JFree JFreeChart.
2
What input sources need to be controlled or reviewed?
An attacker can exploit the issue remotely without authentication by supplying script or HTML in either the link parameter or the User-Agent HTTP header. Successful exploitation requires interaction with the vulnerable endpoint and has a medium severity score of 4.3.
3
What is the recommended remediation?
A patch is available. Apply the vendor-provided patch to the affected wwwstats deployment.