CVE Vulnerabilities

CVE-2006-1945

Published: Apr 20, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.

Affected Software

NameVendorStart VersionEnd Version
AwstatsAwstats*6.5_1.857 (including)
AwstatsAwstats6.0 (including)6.0 (including)
AwstatsAwstats6.1 (including)6.1 (including)
AwstatsAwstats6.2 (including)6.2 (including)
AwstatsAwstats6.3 (including)6.3 (including)
AwstatsAwstats6.4 (including)6.4 (including)
AwstatsAwstats6.5 (including)6.5 (including)
AwstatsUbuntudapper*
AwstatsUbuntudevel*

References