awstats kayıtları
awstats üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %7,7
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %88,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2005-0116Silahlaştırılmış | AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir awstats · awstats · CWE-20 | Yüksek7,5 | — | %74,9 | 18 Oca 2005 |
40Planlayın | CVE-2017-1000501İstismar yok | Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting inawstats · awstats · CWE-22 | Kritik9,8 | — | %4,4 | 3 Oca 2018 |
40Planlayın | CVE-2020-29600İstismar yok | In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etcawstats · awstats · CWE-22 | Kritik9,8 | — | %3,8 | 7 Ara 2020 |
38İzleyin | CVE-2006-2237Silahlaştırılmış | The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell awstats · awstats | Orta5,1 | — | %58,4 | 8 May 2006 |
38İzleyin | CVE-2010-4367Kavram kanıtı | awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via awstats · awstats · CWE-94 | Yüksek7,5 | — | %27,7 | 2 Ara 2010 |
32İzleyin | CVE-2005-0436Kavram kanıtı | Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the Plawstats · awstats | Yüksek7,5 | — | %7,0 | 2 May 2005 |
31İzleyin | CVE-2010-4368İstismar yok | awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary coawstats · awstats · CWE-94 | Yüksek7,5 | — | %2,5 | 2 Ara 2010 |
31İzleyin | CVE-2005-0363İstismar yok | awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.awstats · awstats | Yüksek7,5 | — | %2,0 | 2 May 2005 |
31İzleyin | CVE-2005-0437İstismar yok | Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via ..awstats · awstats | Yüksek7,5 | — | %1,8 | 2 May 2005 |
31İzleyin | CVE-2025-63261İstismar yok | AWStats 8.0 is vulnerable to Command Injection via the open functionawstats · awstats · CWE-78 | Yüksek7,8 | — | %1,0 | 20 Mar 2026 |
26İzleyin | CVE-2010-4369İstismar yok | Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin direcawstats · awstats · CWE-22 | Orta6,4 | — | %2,7 | 2 Ara 2010 |
24İzleyin | CVE-2009-5020Kavram kanıtı | Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conducawstats · awstats · CWE-20 | Orta5,8 | — | %3,5 | 2 Ara 2010 |
24İzleyin | CVE-2022-46391İstismar yok | AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.awstats · awstats · CWE-79 | Orta6,1 | — | %0,7 | 3 Ara 2022 |
23İzleyin | CVE-2006-3682Kavram kanıtı | awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode oawstats · awstats | Orta5,0 | — | %9,7 | 21 Tem 2006 |
22İzleyin | CVE-2005-0435Kavram kanıtı | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawawstats · awstats | Orta5,0 | — | %7,4 | 2 May 2005 |
22İzleyin | CVE-2020-35176İstismar yok | In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intenawstats · awstats · CWE-22 | Orta5,3 | — | %2,2 | 11 Ara 2020 |
22İzleyin | CVE-2018-10245Kavram kanıtı | A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining thawstats · awstats · CWE-200 | Orta5,3 | — | %1,9 | 20 Nis 2018 |
21İzleyin | CVE-2005-0438Kavram kanıtı | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.awstats · awstats | Orta5,0 | — | %3,8 | 2 May 2005 |
21İzleyin | CVE-2005-1527İstismar yok | Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitawstats · awstats · CWE-94 | Orta5,0 | — | %3,0 | 15 Ağu 2005 |
21İzleyin | CVE-2005-2732İstismar yok | AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the coawstats · awstats | Orta5,0 | — | %1,7 | 30 Ağu 2005 |
19İzleyin | CVE-2008-3714Kavram kanıtı | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via theawstats · awstats · CWE-79 | Orta4,3 | — | %5,6 | 19 Ağu 2008 |
19İzleyin | CVE-2005-0362İstismar yok | awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadpawstats · awstats | Orta4,6 | — | %1,8 | 9 Şub 2005 |
17İzleyin | CVE-2006-2644İstismar yok | AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awawstats · awstats | Orta4,0 | — | %2,7 | 30 May 2006 |
17İzleyin | CVE-2008-5080İstismar yok | awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scriptiawstats · awstats · CWE-79 | Orta4,3 | — | %1,1 | 3 Ara 2008 |
11İzleyin | CVE-2006-1945Kavram kanıtı | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or awstats · awstats | Düşük2,6 | — | %4,8 | 20 Nis 2006 |
- CVE-2005-011652Planlayın
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir
YüksekCVSS 7,5SilahlaştırılmışEPSS %75awstats · awstats18 Oca 2005
- CVE-2017-100050140Planlayın
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in
KritikCVSS 9,8İstismar yokEPSS %4awstats · awstats3 Oca 2018
- CVE-2020-2960040Planlayın
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc
KritikCVSS 9,8İstismar yokEPSS %4awstats · awstats7 Ara 2020
- CVE-2006-223738İzleyin
The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell
OrtaCVSS 5,1SilahlaştırılmışEPSS %58awstats · awstats8 May 2006
- CVE-2010-436738İzleyin
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %28awstats · awstats2 Ara 2010
- CVE-2005-043632İzleyin
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the Pl
YüksekCVSS 7,5Kavram kanıtıEPSS %7awstats · awstats2 May 2005
- CVE-2010-436831İzleyin
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary co
YüksekCVSS 7,5İstismar yokEPSS %3awstats · awstats2 Ara 2010
- CVE-2005-036331İzleyin
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
YüksekCVSS 7,5İstismar yokEPSS %2awstats · awstats2 May 2005
- CVE-2005-043731İzleyin
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via ..
YüksekCVSS 7,5İstismar yokEPSS %2awstats · awstats2 May 2005
- CVE-2025-6326131İzleyin
AWStats 8.0 is vulnerable to Command Injection via the open function
YüksekCVSS 7,8İstismar yokEPSS %1awstats · awstats20 Mar 2026
- CVE-2010-436926İzleyin
Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin direc
OrtaCVSS 6,4İstismar yokEPSS %3awstats · awstats2 Ara 2010
- CVE-2009-502024İzleyin
Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduc
OrtaCVSS 5,8Kavram kanıtıEPSS %3awstats · awstats2 Ara 2010
- CVE-2022-4639124İzleyin
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
OrtaCVSS 6,1İstismar yokEPSS %1awstats · awstats3 Ara 2022
- CVE-2006-368223İzleyin
awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode o
OrtaCVSS 5,0Kavram kanıtıEPSS %10awstats · awstats21 Tem 2006
- CVE-2005-043522İzleyin
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to raw
OrtaCVSS 5,0Kavram kanıtıEPSS %7awstats · awstats2 May 2005
- CVE-2020-3517622İzleyin
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was inten
OrtaCVSS 5,3İstismar yokEPSS %2awstats · awstats11 Ara 2020
- CVE-2018-1024522İzleyin
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining th
OrtaCVSS 5,3Kavram kanıtıEPSS %2awstats · awstats20 Nis 2018
- CVE-2005-043821İzleyin
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
OrtaCVSS 5,0Kavram kanıtıEPSS %4awstats · awstats2 May 2005
- CVE-2005-152721İzleyin
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbit
OrtaCVSS 5,0İstismar yokEPSS %3awstats · awstats15 Ağu 2005
- CVE-2005-273221İzleyin
AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the co
OrtaCVSS 5,0İstismar yokEPSS %2awstats · awstats30 Ağu 2005
- CVE-2008-371419İzleyin
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the
OrtaCVSS 4,3Kavram kanıtıEPSS %6awstats · awstats19 Ağu 2008
- CVE-2005-036219İzleyin
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadp
OrtaCVSS 4,6İstismar yokEPSS %2awstats · awstats9 Şub 2005
- CVE-2006-264417İzleyin
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to aw
OrtaCVSS 4,0İstismar yokEPSS %3awstats · awstats30 May 2006
- CVE-2008-508017İzleyin
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripti
OrtaCVSS 4,3İstismar yokEPSS %1awstats · awstats3 Ara 2008
- CVE-2006-194511İzleyin
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or
DüşükCVSS 2,6Kavram kanıtıEPSS %5awstats · awstats20 Nis 2006