CVE-2005-3959
CVE-2005-3959
Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/26635unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://secunia.com/advisories/17783http://securitytracker.com/id?1015301https://exchange.xforce.ibmcloud.com/vulnerabilities/23387https://exchange.xforce.ibmcloud.com/vulnerabilities/23391http://www.freewebstat.com/changelog-english.htmlhttp://www.osvdb.org/21207http://www.securityfocus.com/archive/1/417902/100/0/threadedhttp://www.securityfocus.com/bid/15601http://www.ush.it/2005/11/25/free-web-stat/http://www.vupen.com/english/advisories/2005/2646