Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmvc-j5gw-8prm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.

EPSS

Процентиль: 60%
0.00396
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 17 лет назад

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.

nvd
около 17 лет назад

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.

debian
около 17 лет назад

awstats.pl in AWStats 6.8 and earlier does not properly remove quote c ...

EPSS

Процентиль: 60%
0.00396
Низкий

Дефекты

CWE-79