Lucene search

K
cveMitreCVE-2006-3681
HistoryJul 21, 2006 - 2:03 p.m.

CVE-2006-3681

2006-07-2114:03:00
mitre
web.nvd.nist.gov
40
cve-2006-3681
xss
awstats
vulnerability
remote attackers
web script
html

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.006

Percentile

78.2%

Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.

Affected configurations

Nvd
Node
awstatsawstatsRange6.5_1.857
VendorProductVersionCPE
awstatsawstatscpe:/a:awstats:awstats::::

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.006

Percentile

78.2%