Jump to content

Advisories MDVSA-2009:266: awstats


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in awstats:

 

awstats.pl in AWStats 6.8 and earlier does not properly remove quote

characters, which allows remote attackers to conduct cross-site

scripting (XSS) attacks via the query_string parameter. NOTE:

this issue exists because of an incomplete fix for CVE-2008-3714

(CVE-2008-5080).

 

This update fixes this vulnerability.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...