paul Posted October 12, 2009 Report Share Posted October 12, 2009 A vulnerability has been found and corrected in awstats: awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714 (CVE-2008-5080). This update fixes this vulnerability. Link to comment Share on other sites More sharing options...
Recommended Posts