CVE-2006-3681Cross-site Scripting in Awstats

Severity
2.6LOWNVD
EPSS
0.6%
top 30.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 21
Latest updateMay 1

Description

Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages2 packages

Debianawstats/awstats< 6.5-2+3
NVDawstats/awstats6.5_1.857

🔴Vulnerability Details

3
GHSA
GHSA-j4xf-vwfm-mg7q: Multiple cross-site scripting (XSS) vulnerabilities in awstats2022-05-01
OSV
CVE-2006-3681: Multiple cross-site scripting (XSS) vulnerabilities in awstats2006-07-21
CVEList
CVE-2006-3681: Multiple cross-site scripting (XSS) vulnerabilities in awstats2006-07-18

📋Vendor Advisories

3
Red Hat
awstats: Cross-site scripting (XSS) vulnerability2008-06-23
Ubuntu
awstats vulnerabilities2006-10-10
Debian
CVE-2006-3681: awstats - Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5...2006

💬Community

1
Bugzilla
CVE-2008-3714 awstats: Cross-site scripting (XSS) vulnerability2008-08-20