REDHAT-BUG-459605: XSS
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3714 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the querystring, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
References:
http://bugs.gentoo.org/showbug.cgi?id=235225
Upstream patch:
http://awstats.cvs.sourceforge.net/awstats/awstats/wwwroot/cgi-bin/awstats.pl?r1=1.910&r2=1.912
Upstream bug report:
http://sourceforge.net/tracker/index.php?func=detail&aid=2001151&groupid=13764&atid=113764
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-459605?
The severity of REDHAT-BUG-459605 is considered high due to its potential for remote code execution via cross-site scripting.
How do I fix REDHAT-BUG-459605?
To fix REDHAT-BUG-459605, upgrade to the latest version of AWStats that addresses the CVE-2008-3714 vulnerability.
What are the potential impacts of REDHAT-BUG-459605?
The potential impacts of REDHAT-BUG-459605 include unauthorized access to user information and the ability to perform actions on behalf of users.
Which versions of AWStats are affected by REDHAT-BUG-459605?
AWStats version 6.8 is affected by REDHAT-BUG-459605, making it vulnerable to cross-site scripting attacks.
Is REDHAT-BUG-459605 publicly known?
Yes, REDHAT-BUG-459605 is publicly known and has been assigned a CVE identifier, CVE-2008-3714.