Lucene search

K
osvGoogleOSV:DSA-1679-1
HistoryDec 03, 2008 - 12:00 a.m.

awstats - cross-site scripting

2008-12-0300:00:00
Google
osv.dev
228

0.518 Medium

EPSS

Percentile

97.6%

Morgan Todd discovered a cross-site scripting vulnerability in awstats,
a log file analyzer, involving the “config” request parameter (and
possibly others; CVE-2008-3714).

For the stable distribution (etch), this problem has been fixed in version
6.5+dfsg-1+etch1.

The unstable (sid) and testing (lenny) distribution will be fixed soon.

We recommend that you upgrade your awstats package.

CPENameOperatorVersion
awstatseq6.5+dfsg-1