CVE-2008-5080
published 2008-12-03CVE-2008-5080: awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks…
PriorityP413medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.09%
61.6th percentile
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| awstats | awstats | <= 6.8 | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | >= 0 < 6.7.dfsg-5.1 | 6.7.dfsg-5.1 |
| awstats | awstats | >= 0 < 6.7.dfsg-5.1 | 6.7.dfsg-5.1 |
| awstats | awstats | >= 0 < 6.7.dfsg-5.1 | 6.7.dfsg-5.1 |
| awstats | awstats | >= 0 < 6.7.dfsg-5.1 | 6.7.dfsg-5.1 |
| debian | awstats | < awstats 6.7.dfsg-5.1 (bookworm) | awstats 6.7.dfsg-5.1 (bookworm) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
AWStats vulnerability
vendor_ubuntu·2008-12-04
CVE-2008-3714 AWStats vulnerability
Title: AWStats vulnerability
Summary: AWStats vulnerability
Morgan Todd discovered that AWStats did not correctly strip quotes from
certain parameters, allowing for an XSS attack when running as a CGI.
If a user was tricked by a remote attacker into following a specially
crafted URL, the user's authentication information could be exposed for
the domain where AWStats was hosted.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2008-5080: awstats - awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters,...
vendor_debian·2008·CVSS 4.3
CVE-2008-5080 [MEDIUM] CVE-2008-5080: awstats - awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters,...
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
Scope: local
bookworm: resolved (fixed in 6.7.dfsg-5.1)
bullseye: resolved (fixed in 6.7.dfsg-5.1)
forky: resolved (fixed in 6.7.dfsg-5.1)
sid: resolved (fixed in 6.7.dfsg-5.1)
trixie: resolved (fixed in 6.7.dfsg-5.1)
Red Hat
awstats: incomplete fix for CVE-2008-3714 XSS issue
vendor_redhat·CVSS 4.3
CVE-2008-5080 [MEDIUM] awstats: incomplete fix for CVE-2008-3714 XSS issue
awstats: incomplete fix for CVE-2008-3714 XSS issue
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
GHSA
GHSA-hmvc-j5gw-8prm: awstats
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2008-5080 [MEDIUM] CWE-79 GHSA-hmvc-j5gw-8prm: awstats
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
OSV
CVE-2008-5080: awstats
osv·2008-12-03·CVSS 4.3
CVE-2008-5080 [MEDIUM] CVE-2008-5080: awstats
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495432#21http://secunia.com/advisories/33002http://www.ubuntu.com/usn/usn-686-1https://bugzilla.redhat.com/show_bug.cgi?id=474396https://exchange.xforce.ibmcloud.com/vulnerabilities/47116http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495432#21http://secunia.com/advisories/33002http://www.ubuntu.com/usn/usn-686-1https://bugzilla.redhat.com/show_bug.cgi?id=474396https://exchange.xforce.ibmcloud.com/vulnerabilities/47116
2008-12-03
Published