![]() |
Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | ||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.63106 |
Kategorie: | FreeBSD Local Security Checks |
Titel: | FreeBSD Ports: awstats |
Zusammenfassung: | The remote host is missing an update to the system; as announced in the referenced advisory. |
Beschreibung: | Summary: The remote host is missing an update to the system as announced in the referenced advisory. Vulnerability Insight: The following packages are affected: awstats awstats-devel CVE-2008-3714 Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945. CVE-2008-5080 awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714. Solution: Update your system with the appropriate patches or software upgrades. CVSS Score: 4.3 CVSS Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-3714 BugTraq ID: 30730 http://www.securityfocus.com/bid/30730 Debian Security Information: DSA-1679 (Google Search) http://www.debian.org/security/2008/dsa-1679 https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00107.html https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00355.html http://www.mandriva.com/security/advisories?name=MDVSA-2008:203 http://www.securitytracker.com/id?1020704 http://secunia.com/advisories/31519 http://secunia.com/advisories/31759 http://secunia.com/advisories/32939 http://secunia.com/advisories/33002 http://www.ubuntu.com/usn/usn-686-1 http://www.vupen.com/english/advisories/2008/2399 XForce ISS Database: awstats-awstats-xss(44504) https://exchange.xforce.ibmcloud.com/vulnerabilities/44504 Common Vulnerability Exposure (CVE) ID: CVE-2008-5080 33002 USN-686-1 awstats-querystring-xss(47116) https://exchange.xforce.ibmcloud.com/vulnerabilities/47116 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495432#21 https://bugzilla.redhat.com/show_bug.cgi?id=474396 |
Copyright | Copyright (C) 2009 E-Soft Inc. |
Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |