VulnerabilityModified
CVE-2008-3921
Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.
MEDIUM 4.3EPSS 1.26%
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- telartis bv/awstats totals
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/31630Vendor Advisory
- http://securityreason.com/securityalert/4218
- http://userwww.service.emory.edu/~ekenda2/EMORY-2008-01.txt
- http://www.securityfocus.com/archive/1/495770/100/0/threaded
- http://www.telartis.nl/xcms/awstats/Patch
- http://www.vupen.com/english/advisories/2008/2442
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44706
- http://secunia.com/advisories/31630Vendor Advisory
- http://securityreason.com/securityalert/4218
- http://userwww.service.emory.edu/~ekenda2/EMORY-2008-01.txt
- http://www.securityfocus.com/archive/1/495770/100/0/threaded
- http://www.telartis.nl/xcms/awstats/Patch
- http://www.vupen.com/english/advisories/2008/2442
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44706
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.