Advisories Blog | G5 Cyber Security

Ubuntu Security Notice 686-1

Ubuntu Security Notice USN-686-1 – Morgan Todd discovered that AWStats did not correctly strip quotes from certain parameters, allowing for an XSS attack when running as a CGI. If a user was tricked by a remote attacker into following a specially crafted URL, the user’s authentication information could be exposed for the domain where AWStats was hosted.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/72607/USN-686-1.txt

Source: https://packetstormsecurity.com/files/72607/Ubuntu-Security-Notice-686-1.html

Exit mobile version