Show filters
87 Total Results
Displaying 61-70 of 87
Sort by:
Attacker Value
Unknown
CVE-2006-3681
Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945.
0
Attacker Value
Unknown
CVE-2006-3682
Disclosure Date: July 21, 2006 (last updated October 04, 2023)
awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters.
0
Attacker Value
Unknown
CVE-2006-3292
Disclosure Date: June 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in the searchdata parameter (search field).
0
Attacker Value
Unknown
CVE-2006-2920
Disclosure Date: June 09, 2006 (last updated October 04, 2023)
Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.
0
Attacker Value
Unknown
CVE-2006-2644
Disclosure Date: May 30, 2006 (last updated October 04, 2023)
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
0
Attacker Value
Unknown
CVE-2006-2237
Disclosure Date: May 08, 2006 (last updated October 04, 2023)
The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.
0
Attacker Value
Unknown
CVE-2006-1945
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.
0
Attacker Value
Unknown
CVE-2005-3955
Disclosure Date: December 01, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
0
Attacker Value
Unknown
CVE-2005-2732
Disclosure Date: August 30, 2005 (last updated February 22, 2025)
AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message.
0
Attacker Value
Unknown
CVE-2005-1527
Disclosure Date: August 15, 2005 (last updated February 22, 2025)
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
0