CVE Vulnerabilities

CVE-2006-1945

Published: Apr 20, 2006 | Modified: Nov 03, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.

Affected Software

Name Vendor Start Version End Version
Awstats Awstats * 6.5_1.857 (including)
Awstats Awstats 6.0 (including) 6.0 (including)
Awstats Awstats 6.1 (including) 6.1 (including)
Awstats Awstats 6.2 (including) 6.2 (including)
Awstats Awstats 6.3 (including) 6.3 (including)
Awstats Awstats 6.4 (including) 6.4 (including)
Awstats Awstats 6.5 (including) 6.5 (including)

References