CVE-2006-3681
published 2006-07-21CVE-2006-3681: Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script…
PriorityP411low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.05%
79.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| awstats | awstats | <= 6.5_1.857 | — |
| awstats | awstats | — | — |
| awstats | awstats | >= 0 < 6.5-2 | 6.5-2 |
| awstats | awstats | >= 0 < 6.7.dfsg-5.1 | 6.7.dfsg-5.1 |
| awstats | awstats | >= 0 < 6.5-2 | 6.5-2 |
| awstats | awstats | >= 0 < 6.7.dfsg-5.1 | 6.7.dfsg-5.1 |
| awstats | awstats | >= 0 < 6.5-2 | 6.5-2 |
| awstats | awstats | >= 0 < 6.7.dfsg-5.1 | 6.7.dfsg-5.1 |
| awstats | awstats | >= 0 < 6.5-2 | 6.5-2 |
| awstats | awstats | >= 0 < 6.7.dfsg-5.1 | 6.7.dfsg-5.1 |
| debian | awstats | < awstats 6.7.dfsg-5.1 (bookworm) | awstats 6.7.dfsg-5.1 (bookworm) |
| debian | awstats | < awstats 6.5-2 (bookworm) | awstats 6.5-2 (bookworm) |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
awstats: Cross-site scripting (XSS) vulnerability
vendor_redhat·2008-06-23·CVSS 2.6
CVE-2008-3714 [LOW] CWE-79 awstats: Cross-site scripting (XSS) vulnerability
awstats: Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
Debian
CVE-2008-3714: awstats - Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows rem...
vendor_debian·2008·CVSS 2.6
CVE-2008-3714 [LOW] CVE-2008-3714: awstats - Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows rem...
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
Scope: local
bookworm: resolved (fixed in 6.7.dfsg-5.1)
bullseye: resolved (fixed in 6.7.dfsg-5.1)
forky: resolved (fixed in 6.7.dfsg-5.1)
sid: resolved (fixed in 6.7.dfsg-5.1)
trixie: resolved (fixed in 6.7.dfsg-5.1)
Ubuntu
awstats vulnerabilities
vendor_ubuntu·2006-10-10·CVSS 2.6
CVE-2006-3681 [LOW] awstats vulnerabilities
Title: awstats vulnerabilities
Summary: awstats vulnerabilities
awstats did not fully sanitize input, which was passed directly to the user's
browser, allowing for an XSS attack. If a user was tricked into following a
specially crafted awstats URL, the user's authentication information could be
exposed for the domain where awstats was hosted. (CVE-2006-3681)
awstats could display its installation path under certain conditions.
However, this might only become a concern if awstats is installed into
an user's home directory. (CVE-2006-3682)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-3681: awstats - Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5...
vendor_debian·2006·CVSS 2.6
CVE-2006-3681 [LOW] CVE-2006-3681: awstats - Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5...
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.
Scope: local
bookworm: resolved (fixed in 6.5-2)
bullseye: resolved (fixed in 6.5-2)
forky: resolved (fixed in 6.5-2)
sid: resolved (fixed in 6.5-2)
trixie: resolved (fixed in 6.5-2)
GHSA
GHSA-5pfp-c3pj-vr5r: Cross-site scripting (XSS) vulnerability in awstats
ghsa_unreviewed·2022-05-02·CVSS 2.6
CVE-2008-3714 [LOW] CWE-79 GHSA-5pfp-c3pj-vr5r: Cross-site scripting (XSS) vulnerability in awstats
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
GHSA
GHSA-j4xf-vwfm-mg7q: Multiple cross-site scripting (XSS) vulnerabilities in awstats
ghsa_unreviewed·2022-05-01·CVSS 2.6
CVE-2006-3681 [LOW] GHSA-j4xf-vwfm-mg7q: Multiple cross-site scripting (XSS) vulnerabilities in awstats
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.
OSV
CVE-2008-3714: Cross-site scripting (XSS) vulnerability in awstats
osv·2008-08-19·CVSS 2.6
CVE-2008-3714 [LOW] CVE-2008-3714: Cross-site scripting (XSS) vulnerability in awstats
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
OSV
CVE-2006-3681: Multiple cross-site scripting (XSS) vulnerabilities in awstats
osv·2006-07-21·CVSS 2.6
CVE-2006-3681 [LOW] CVE-2006-3681: Multiple cross-site scripting (XSS) vulnerabilities in awstats
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.
No detection rules found.
No public exploits indexed.
http://pridels0.blogspot.com/2006/04/awstats-65x-multiple-vuln.htmlhttp://secunia.com/advisories/19725http://secunia.com/advisories/22306http://www.ubuntu.com/usn/usn-360-1http://www.vupen.com/english/advisories/2006/1421https://exchange.xforce.ibmcloud.com/vulnerabilities/25879http://pridels0.blogspot.com/2006/04/awstats-65x-multiple-vuln.htmlhttp://secunia.com/advisories/19725http://secunia.com/advisories/22306http://www.ubuntu.com/usn/usn-360-1http://www.vupen.com/english/advisories/2006/1421https://exchange.xforce.ibmcloud.com/vulnerabilities/25879
2006-07-21
Published