CVE-2006-3681
EPSS 0.61%發布日:2006/7/21修改日:2026/4/28
也稱為:DEBIAN-CVE-2006-3681
描述
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.
受影響套件(1)
- Debian/awstatsfrom 0, < 6.5-2