First published: Wed Aug 20 2008(Updated: )
Common Vulnerabilities and Exposures assigned an identifier <a href="https://access.redhat.com/security/cve/CVE-2008-3714">CVE-2008-3714</a> to the following vulnerability: Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than <a href="https://access.redhat.com/security/cve/CVE-2006-3681">CVE-2006-3681</a> and <a href="https://access.redhat.com/security/cve/CVE-2006-1945">CVE-2006-1945</a>. References: <a href="http://bugs.gentoo.org/show_bug.cgi?id=235225">http://bugs.gentoo.org/show_bug.cgi?id=235225</a> Upstream patch: <a href="http://awstats.cvs.sourceforge.net/awstats/awstats/wwwroot/cgi-bin/awstats.pl?r1=1.910&r2=1.912">http://awstats.cvs.sourceforge.net/awstats/awstats/wwwroot/cgi-bin/awstats.pl?r1=1.910&r2=1.912</a> Upstream bug report: <a href="http://sourceforge.net/tracker/index.php?func=detail&aid=2001151&group_id=13764&atid=113764">http://sourceforge.net/tracker/index.php?func=detail&aid=2001151&group_id=13764&atid=113764</a>
Affected Software | Affected Version | How to fix |
---|---|---|
AWStats |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.