Ubuntu Security Notice USN-686-1 – Morgan Todd discovered that AWStats did not correctly strip quotes from certain parameters, allowing for an XSS attack when running as a CGI. If a user was tricked by a remote attacker into following a specially crafted URL, the user’s authentication information could be exposed for the domain where AWStats was hosted.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/72607/USN-686-1.txt
Source: https://packetstormsecurity.com/files/72607/Ubuntu-Security-Notice-686-1.html

