Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-3681
HistoryJul 21, 2006 - 12:00 a.m.

CVE-2006-3681

2006-07-2100:00:00
ubuntu.com
ubuntu.com
10

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.006

Percentile

78.2%

Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in
AWStats 6.5 build 1.857 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) refererpagesfilter, (2)
refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or
(6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchawstats< 6.5-1ubuntu1.2UNKNOWN
ubuntu6.10noarchawstats< 6.5-2ubuntu1UNKNOWN
ubuntu7.04noarchawstats< 6.5-2ubuntu1UNKNOWN

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.006

Percentile

78.2%