Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2018-10245 A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full pa… Awstats after 7.6 Fix from $1,6002018-04-20 HIGH 7.5 CVE-2010-4367EPSS 28% awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted… Awstats after 6.95 Fix from $1,9502010-12-02 HIGH 7.5 CVE-2010-4368 awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands vi… Awstats after 6.95 Fix from $1,9502010-12-02 MEDIUM 6.4 CVE-2010-4369 Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory. Awstats after 6.95 Fix from $1,6002010-12-02 MEDIUM 5.8 CVE-2009-5020 Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishin… Awstats after 6.9 Fix from $1,6002010-12-02 MEDIUM 5.0 CVE-2006-3682EPSS 10% awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) mon… Awstats after 6.5_1.857 Fix from $1,6002006-07-21 MEDIUM 5.1 CVE-2006-2237EPSS 58% The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metachara… Awstats Patch available Fix from $1,6002006-05-08 MEDIUM 5.0 CVE-2005-2732 AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config para… Awstats after 6.4 Fix from $1,6002005-08-30 HIGH 7.5 CVE-2005-0363 awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter. Awstats Patch available Fix from $1,9502005-05-02 HIGH 7.5 CVE-2005-0436EPSS 7% Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode … Awstats Patch available Fix from $1,9502005-05-02 HIGH 7.5 CVE-2005-0437 Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) seq… Awstats Patch available Fix from $1,9502005-05-02 MEDIUM 5.0 CVE-2005-0435EPSS 7% awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog. Awstats Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0438 awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter. Awstats Patch available Fix from $1,6002005-05-02 HIGH 7.5 CVE-2005-0116EPSS 75% AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter… Awstats after 6.3 Fix from $1,9502005-01-18