Vulnerability Name:

CVE-2008-3714 (CCN-44504)

Assigned:2008-08-05
Published:2008-08-05
Updated:2017-08-08
Summary:Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: AWStats Web page
AWStats

Source: CCN
Type: AWStats Changelog
Revision: 1.257, 6.9

Source: CONFIRM
Type: UNKNOWN
http://awstats.sourceforge.net/docs/awstats_changelog.txt

Source: CONFIRM
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495432

Source: MITRE
Type: CNA
CVE-2008-3714

Source: CCN
Type: SA31519
AWStats URL Cross-Site Scripting Vulnerability

Source: SECUNIA
Type: Vendor Advisory
31519

Source: SECUNIA
Type: UNKNOWN
31759

Source: SECUNIA
Type: UNKNOWN
32939

Source: SECUNIA
Type: UNKNOWN
33002

Source: CCN
Type: SECTRACK ID: 1020704
AWStats Input Validation Hole in Displaying Action Attribute Permits Cross-Site Scripting Attacks

Source: CCN
Type: SourceForge.net: Detail: 2001151
XSS Issue

Source: CONFIRM
Type: UNKNOWN
http://sourceforge.net/tracker/index.php?func=detail&aid=2001151&group_id=13764&atid=113764

Source: DEBIAN
Type: UNKNOWN
DSA-1679

Source: DEBIAN
Type: DSA-1679
awstats -- cross-site scripting

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2008:203

Source: BID
Type: UNKNOWN
30730

Source: CCN
Type: BID-30730
AWStats 'awstats.pl' Cross-Site Scripting Vulnerability

Source: SECTRACK
Type: UNKNOWN
1020704

Source: CCN
Type: USN-686-1
AWStats vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-686-1

Source: VUPEN
Type: UNKNOWN
ADV-2008-2399

Source: XF
Type: UNKNOWN
awstats-awstats-xss(44504)

Source: XF
Type: UNKNOWN
awstats-awstats-xss(44504)

Source: FEDORA
Type: UNKNOWN
FEDORA-2008-7663

Source: FEDORA
Type: UNKNOWN
FEDORA-2008-7684

Vulnerable Configuration:Configuration 1:
  • cpe:/a:awstats:awstats:6.8:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:awstats:awstats:6.8:*:*:*:*:*:*:*
  • AND
  • cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
  • OR cpe:/o:mandriva:enterprise_server:5:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:enterprise_server:5:*:*:*:x86_64:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:17861
    P
    USN-686-1 -- awstats vulnerability
    2014-06-30
    oval:org.mitre.oval:def:8151
    P
    DSA-1679 awstats -- cross-site scripting
    2014-06-23
    oval:org.mitre.oval:def:20224
    P
    DSA-1679-1 awstats - cross-site scripting
    2014-06-23
    oval:org.debian:def:1679
    V
    cross-site scripting
    2008-12-03
    BACK
    awstats awstats 6.8
    awstats awstats 6.8
    canonical ubuntu 6.06
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    debian debian linux 4.0
    canonical ubuntu 7.10
    canonical ubuntu 8.04
    mandriva enterprise server 5
    mandriva enterprise server 5