Summary
Ubuntu Update for Linux kernel vulnerabilities USN-686-1
Solution
Please Install the Updated Packages.
Insight
Morgan Todd discovered that AWStats did not correctly strip quotes from certain parameters, allowing for an XSS attack when running as a CGI.
If a user was tricked by a remote attacker into following a specially crafted URL, the user's authentication information could be exposed for the domain where AWStats was hosted.
Affected
awstats vulnerability on Ubuntu 6.06 LTS ,
Ubuntu 7.10 ,
Ubuntu 8.04 LTS ,
Ubuntu 8.10
Severity
Classification
-
CVE CVE-2008-3714 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities