İçeriğe atla
Noroxi

awstats kayıtları

awstats üreticisine ait 26 yayımlanmış kayıt.

Tüm kayıtlar

26 kayıt
  • CVE-2005-0116
    52Planlayın

    AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir

    YüksekCVSS 7,5SilahlaştırılmışEPSS %75

    awstats · awstats18 Oca 2005

  • CVE-2017-1000501
    40Planlayın

    Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in

    KritikCVSS 9,8İstismar yokEPSS %4

    awstats · awstats3 Oca 2018

  • CVE-2020-29600
    40Planlayın

    In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc

    KritikCVSS 9,8İstismar yokEPSS %4

    awstats · awstats7 Ara 2020

  • CVE-2006-2237
    38İzleyin

    The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell

    OrtaCVSS 5,1SilahlaştırılmışEPSS %58

    awstats · awstats8 May 2006

  • CVE-2010-4367
    38İzleyin

    awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via

    YüksekCVSS 7,5Kavram kanıtıEPSS %28

    awstats · awstats2 Ara 2010

  • CVE-2005-0436
    32İzleyin

    Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the Pl

    YüksekCVSS 7,5Kavram kanıtıEPSS %7

    awstats · awstats2 May 2005

  • CVE-2010-4368
    31İzleyin

    awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary co

    YüksekCVSS 7,5İstismar yokEPSS %3

    awstats · awstats2 Ara 2010

  • CVE-2005-0363
    31İzleyin

    awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.

    YüksekCVSS 7,5İstismar yokEPSS %2

    awstats · awstats2 May 2005

  • CVE-2005-0437
    31İzleyin

    Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via ..

    YüksekCVSS 7,5İstismar yokEPSS %2

    awstats · awstats2 May 2005

  • CVE-2025-63261
    31İzleyin

    AWStats 8.0 is vulnerable to Command Injection via the open function

    YüksekCVSS 7,8İstismar yokEPSS %1

    awstats · awstats20 Mar 2026

  • CVE-2010-4369
    26İzleyin

    Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin direc

    OrtaCVSS 6,4İstismar yokEPSS %3

    awstats · awstats2 Ara 2010

  • CVE-2009-5020
    24İzleyin

    Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduc

    OrtaCVSS 5,8Kavram kanıtıEPSS %3

    awstats · awstats2 Ara 2010

  • CVE-2022-46391
    24İzleyin

    AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

    OrtaCVSS 6,1İstismar yokEPSS %1

    awstats · awstats3 Ara 2022

  • CVE-2006-3682
    23İzleyin

    awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode o

    OrtaCVSS 5,0Kavram kanıtıEPSS %10

    awstats · awstats21 Tem 2006

  • CVE-2005-0435
    22İzleyin

    awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to raw

    OrtaCVSS 5,0Kavram kanıtıEPSS %7

    awstats · awstats2 May 2005

  • CVE-2020-35176
    22İzleyin

    In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was inten

    OrtaCVSS 5,3İstismar yokEPSS %2

    awstats · awstats11 Ara 2020

  • CVE-2018-10245
    22İzleyin

    A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining th

    OrtaCVSS 5,3Kavram kanıtıEPSS %2

    awstats · awstats20 Nis 2018

  • CVE-2005-0438
    21İzleyin

    awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.

    OrtaCVSS 5,0Kavram kanıtıEPSS %4

    awstats · awstats2 May 2005

  • CVE-2005-1527
    21İzleyin

    Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbit

    OrtaCVSS 5,0İstismar yokEPSS %3

    awstats · awstats15 Ağu 2005

  • CVE-2005-2732
    21İzleyin

    AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the co

    OrtaCVSS 5,0İstismar yokEPSS %2

    awstats · awstats30 Ağu 2005

  • CVE-2008-3714
    19İzleyin

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the

    OrtaCVSS 4,3Kavram kanıtıEPSS %6

    awstats · awstats19 Ağu 2008

  • CVE-2005-0362
    19İzleyin

    awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadp

    OrtaCVSS 4,6İstismar yokEPSS %2

    awstats · awstats9 Şub 2005

  • CVE-2006-2644
    17İzleyin

    AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to aw

    OrtaCVSS 4,0İstismar yokEPSS %3

    awstats · awstats30 May 2006

  • CVE-2008-5080
    17İzleyin

    awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripti

    OrtaCVSS 4,3İstismar yokEPSS %1

    awstats · awstats3 Ara 2008

  • CVE-2006-1945
    11İzleyin

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or

    DüşükCVSS 2,6Kavram kanıtıEPSS %5

    awstats · awstats20 Nis 2006