Vulnerability Name: | CVE-2008-3714 (CCN-44504) | ||||||||||||||||||||
Assigned: | 2008-08-05 | ||||||||||||||||||||
Published: | 2008-08-05 | ||||||||||||||||||||
Updated: | 2017-08-08 | ||||||||||||||||||||
Summary: | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: CCN Type: AWStats Web page AWStats Source: CCN Type: AWStats Changelog Revision: 1.257, 6.9 Source: CONFIRM Type: UNKNOWN http://awstats.sourceforge.net/docs/awstats_changelog.txt Source: CONFIRM Type: UNKNOWN http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495432 Source: MITRE Type: CNA CVE-2008-3714 Source: CCN Type: SA31519 AWStats URL Cross-Site Scripting Vulnerability Source: SECUNIA Type: Vendor Advisory 31519 Source: SECUNIA Type: UNKNOWN 31759 Source: SECUNIA Type: UNKNOWN 32939 Source: SECUNIA Type: UNKNOWN 33002 Source: CCN Type: SECTRACK ID: 1020704 AWStats Input Validation Hole in Displaying Action Attribute Permits Cross-Site Scripting Attacks Source: CCN Type: SourceForge.net: Detail: 2001151 XSS Issue Source: CONFIRM Type: UNKNOWN http://sourceforge.net/tracker/index.php?func=detail&aid=2001151&group_id=13764&atid=113764 Source: DEBIAN Type: UNKNOWN DSA-1679 Source: DEBIAN Type: DSA-1679 awstats -- cross-site scripting Source: MANDRIVA Type: UNKNOWN MDVSA-2008:203 Source: BID Type: UNKNOWN 30730 Source: CCN Type: BID-30730 AWStats 'awstats.pl' Cross-Site Scripting Vulnerability Source: SECTRACK Type: UNKNOWN 1020704 Source: CCN Type: USN-686-1 AWStats vulnerability Source: UBUNTU Type: UNKNOWN USN-686-1 Source: VUPEN Type: UNKNOWN ADV-2008-2399 Source: XF Type: UNKNOWN awstats-awstats-xss(44504) Source: XF Type: UNKNOWN awstats-awstats-xss(44504) Source: FEDORA Type: UNKNOWN FEDORA-2008-7663 Source: FEDORA Type: UNKNOWN FEDORA-2008-7684 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |