4.3
CVSSv2

CVE-2008-3714

Published: 19/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote malicious users to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.

Vulnerable Product Search on Vulmon Subscribe to Product

awstats awstats 6.8

Vendor Advisories

Debian Bug report logs - #495432 XSS in awstats < 69beta (upstream bug 2001151) Package: awstats; Maintainer for awstats is Debian QA Group <packages@qadebianorg>; Source for awstats is src:awstats (PTS, buildd, popcon) Reported by: Andreas Henriksson <andreas@fatalse> Date: Sun, 17 Aug 2008 11:30:01 UTC Seve ...
Morgan Todd discovered that AWStats did not correctly strip quotes from certain parameters, allowing for an XSS attack when running as a CGI If a user was tricked by a remote attacker into following a specially crafted URL, the user’s authentication information could be exposed for the domain where AWStats was hosted ...
Morgan Todd discovered a cross-site scripting vulnerability in awstats, a log file analyzer, involving the "config" request parameter (and possibly others; CVE-2008-3714) For the stable distribution (etch), this problem has been fixed in version 65+dfsg-1+etch1 The unstable (sid) and testing (lenny) distribution will be fixed soon We recommend ...

Exploits

source: wwwsecurityfocuscom/bid/30730/info AWStats is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the atta ...