X-Stat Cross-Site Scripting Vulnerability
BID:4281
Info
X-Stat Cross-Site Scripting Vulnerability
| Bugtraq ID: | 4281 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2002 12:00AM |
| Updated: | Mar 13 2002 12:00AM |
| Credit: | This issue was reported by frog frog <[email protected]>. |
| Vulnerable: |
Xqus X-Stat 2.3 Xqus X-Stat 2.2 |
| Not Vulnerable: | |
Discussion
X-Stat Cross-Site Scripting Vulnerability
X-Stat is a freely available web traffic analyzer, written in PHP. It will run on Unix and Linux variants, as well as Microsoft operating systems.
X-Stat fails to properly filter arbitrary script code from URL parameters. This makes it prone to cross-site scripting attacks. A remote attacker may create a link which contains malicious script code. When this link is clicked by a web user, the script code will execute in the browser of the web user, in the context of the site running the vulnerable software.
Successful exploitation may enable an attacker to steal cookie-based authentication credentials from a legitimate user of the software.
X-Stat is a freely available web traffic analyzer, written in PHP. It will run on Unix and Linux variants, as well as Microsoft operating systems.
X-Stat fails to properly filter arbitrary script code from URL parameters. This makes it prone to cross-site scripting attacks. A remote attacker may create a link which contains malicious script code. When this link is clicked by a web user, the script code will execute in the browser of the web user, in the context of the site running the vulnerable software.
Successful exploitation may enable an attacker to steal cookie-based authentication credentials from a legitimate user of the software.
References
X-Stat Cross-Site Scripting Vulnerability
References:
References:
- X-Holes (frog frog)
- X-Stat Product Page (Xqus)