First published: Wed Dec 03 2008(Updated: )
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
AWStats | <=6.8 | |
AWStats | =5.0 | |
AWStats | =5.1 | |
AWStats | =5.2 | |
AWStats | =5.3 | |
AWStats | =5.4 | |
AWStats | =5.5 | |
AWStats | =5.6 | |
AWStats | =5.7 | |
AWStats | =5.8 | |
AWStats | =5.9 | |
AWStats | =6.0 | |
AWStats | =6.1 | |
AWStats | =6.2 | |
AWStats | =6.3 | |
AWStats | =6.4 | |
AWStats | =6.5 | |
AWStats | =6.6 | |
AWStats | =6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5080 has a moderate severity rating due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2008-5080, you should upgrade to AWStats version 6.9 or later.
AWStats versions 6.8 and earlier, as well as versions 5.0 through 6.7, are affected by CVE-2008-5080.
CVE-2008-5080 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Yes, CVE-2008-5080 can significantly compromise your website's security by allowing remote attackers to execute scripts in users' browsers.