Record summary

CVE-2012-4547 has a selected CVSS score of 4.3; EIP currently links 1 Nuclei template.

Description

Unspecified vulnerability in awredir.pl in AWStats before 7.1 has unknown impact and attack vectors.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMAWStats 6.95/7.0 - 'awredir.pl' Cross-Site ScriptingCVSS 4.3

AWStats is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.

Impact

Allows remote attackers to inject arbitrary web script or HTML via the 'url' parameter.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-79
AuthorsdhiyaneshDk
Template tagscve2012cvexssawstatsedblaurent_destailleurvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:a:laurent_destailleur:awstats:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:laurent_destailleur:awstats"

Source: ProjectDiscovery

References

6