cve/2008/CVE-2008-5080.md
2024-05-26 14:27:05 +02:00

754 B

CVE-2008-5080

Description

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.

POC

Reference

Github

No PoCs found on GitHub currently.