Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.
2006-04-20T22:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 2.6 (LOW)
AV:N/AC:H/Au:N/C:N/I:P/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | awstats | awstats | ≤ 6.5_1.857 | Yes |
Application | awstats | awstats | 6.0 | Yes |
Application | awstats | awstats | 6.1 | Yes |
Application | awstats | awstats | 6.2 | Yes |
Application | awstats | awstats | 6.3 | Yes |
Application | awstats | awstats | 6.4 | Yes |
Application | awstats | awstats | 6.5 | Yes |