First published: Wed Dec 03 2008(Updated: )
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Awstats Awstats | <=6.8 | |
Awstats Awstats | =5.0 | |
Awstats Awstats | =5.1 | |
Awstats Awstats | =5.2 | |
Awstats Awstats | =5.3 | |
Awstats Awstats | =5.4 | |
Awstats Awstats | =5.5 | |
Awstats Awstats | =5.6 | |
Awstats Awstats | =5.7 | |
Awstats Awstats | =5.8 | |
Awstats Awstats | =5.9 | |
Awstats Awstats | =6.0 | |
Awstats Awstats | =6.1 | |
Awstats Awstats | =6.2 | |
Awstats Awstats | =6.3 | |
Awstats Awstats | =6.4 | |
Awstats Awstats | =6.5 | |
Awstats Awstats | =6.6 | |
Awstats Awstats | =6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.