CVE-2008-3714: XSS
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3714 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the querystring, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
References:
http://bugs.gentoo.org/showbug.cgi?id=235225
Upstream patch:
http://awstats.cvs.sourceforge.net/awstats/awstats/wwwroot/cgi-bin/awstats.pl?r1=1.910&r2=1.912
Upstream bug report:
http://sourceforge.net/tracker/index.php?func=detail&aid=2001151&groupid=13764&atid=113764
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3714?
CVE-2008-3714 is considered a high severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2008-3714?
To fix CVE-2008-3714, upgrade AWStats to version 6.9 or later, where the XSS vulnerability has been addressed.
What specific vulnerability does CVE-2008-3714 describe?
CVE-2008-3714 describes a cross-site scripting vulnerability in awstats.pl that allows remote attackers to inject arbitrary scripts via the query_string.
Which version of AWStats is affected by CVE-2008-3714?
AWStats version 6.8 is affected by CVE-2008-3714.
Who can exploit CVE-2008-3714?
Remote attackers can exploit CVE-2008-3714 to execute arbitrary web script or HTML on affected systems.