awstats.sourceforge.netConfirmation
http://awstats.sourceforge.net/docs/awstats_changelog.txt CVE-2012-4547
Nuclei
AWStats 6.95/7.0 - 'awredir.pl' Cross-Site Scripting
Record summary
CVE-2012-4547 has a selected CVSS score of 4.3; EIP currently links 1 Nuclei template.
Description
Unspecified vulnerability in awredir.pl in AWStats before 7.1 has unknown impact and attack vectors.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMAWStats 6.95/7.0 - 'awredir.pl' Cross-Site ScriptingCVSS 4.3
AWStats is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
Impact
Allows remote attackers to inject arbitrary web script or HTML via the 'url' parameter.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
WeaknessesCWE-79
AuthorsdhiyaneshDk
Template tagscve2012cvexssawstatsedblaurent_destailleurvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:a:laurent_destailleur:awstats:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:laurent_destailleur:awstats"
https://www.exploit-db.com/exploits/36164 https://nvd.nist.gov/vuln/detail/CVE-2012-4547 http://awstats.sourceforge.net/docs/awstats_changelog.txt http://openwall.com/lists/oss-security/2012/10/29/7 http://openwall.com/lists/oss-security/2012/10/26/1
Source: ProjectDiscovery
References
6[oss-security] 20121025 Re: CVE request: awstats before 7.1 awredir.pl vulnerabilitymailing list
http://openwall.com/lists/oss-security/2012/10/26/1 [oss-security] 20121029 Re: CVE request: awstats before 7.1 awredir.pl vulnerabilitymailing list
http://openwall.com/lists/oss-security/2012/10/29/7 56280vdb entry
http://www.securityfocus.com/bid/56280 awstats-awredir-unspecified(79638)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/79638 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-4547