A new CleanXSS() function was added [1] to awstats' awredir.pl cgi script and is part of the 7.1 release [2]. The additional function aims to clean strings of HTML tags so as to avoid XSS flaws. It doesn't indicate whether or not it was possible to actually inject arbitrary HTML into these strings or whether this was just a hardening mechanism, however this would be applicable to all currently supported versions of awstats. [1] http://awstats.cvs.sourceforge.net/viewvc/awstats/awstats/wwwroot/cgi-bin/awredir.pl?r1=1.13&r2=1.14 [2] http://awstats.sourceforge.net/docs/awstats_changelog.txt
Created awstats tracking bugs for this issue Affects: fedora-all [bug 871189] Affects: epel-all [bug 871190]
awstats-7.0-11.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
awstats-7.0-9.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
awstats-7.0-3.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
The awstats-7.0-3.el6 package changes the location of files and directory structure compared to the previous release (awstats-7.0-2.el6). As a result, updating breaks all configurations.
(In reply to Zenon Panoussis from comment #5) > The awstats-7.0-3.el6 package changes the location of files and directory > structure compared to the previous release (awstats-7.0-2.el6). As a result, > updating breaks all configurations. There was no change between awstats-7.0-2.el6 and awstats-7.0-3.el6 related to the locations. But if you have any issue, please file a new bug please.