Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-1945Cross-site Scripting in Awstats

CWE-79Cross-site Scripting17 documents7 sources
Severity
4.3MEDIUMNVD
NVD2.6OSV5.0OSV2.6
EPSS
3.8%
top 11.85%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 20
Latest updateMay 2

Description

Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages3 packages

debiandebian/awstats< awstats 6.7.dfsg-5.1 (bookworm)+1
Debianawstats/awstats< 6.5-2+7
NVDawstats/awstats6.5_1.857+7

🔴Vulnerability Details

6
GHSA
GHSA-5pfp-c3pj-vr5r: Cross-site scripting (XSS) vulnerability in awstats2022-05-02
GHSA
GHSA-h828-p7pc-74fc: Cross-site scripting (XSS) vulnerability in awstats2022-05-01
GHSA
GHSA-j4xf-vwfm-mg7q: Multiple cross-site scripting (XSS) vulnerabilities in awstats2022-05-01
OSV
CVE-2008-3714: Cross-site scripting (XSS) vulnerability in awstats2008-08-19
OSV
CVE-2006-3681: Multiple cross-site scripting (XSS) vulnerabilities in awstats2006-07-21

💥Exploits & PoCs

1
Exploit-DB
AWStats 4.0/5.x/6.x - AWStats.pl Multiple Cross-Site Scripting Vulnerabilities2006-04-19

📋Vendor Advisories

4
Red Hat
awstats: Cross-site scripting (XSS) vulnerability2008-06-23
Debian
CVE-2008-3714: awstats - Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows rem...2008
Debian
CVE-2006-1945: awstats - Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlie...2006
Debian
CVE-2006-3681: awstats - Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5...2006

💬Community

3
Bugzilla
CVE-2008-3714 awstats: Cross-site scripting (XSS) vulnerability2008-08-20
Bugzilla
CVE-2006-1945: awstats cross site scripting vulnerability2006-05-06
Bugzilla
CVE-2006-1945: awstats cross site scripting vulnerability2006-05-06
CVE-2006-1945 — Cross-site Scripting in Debian Awstats | cvebase