Записи awstats
26 опубликованных записей вендора awstats.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 7,7 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 88,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2005-0116Готовый эксплойт | AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir awstats · awstats · CWE-20 | Высокая7,5 | — | 74,9 % | 18 янв. 2005 г. |
40В плане | CVE-2017-1000501Эксплойта нет | Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting inawstats · awstats · CWE-22 | Критическая9,8 | — | 4,4 % | 3 янв. 2018 г. |
40В плане | CVE-2020-29600Эксплойта нет | In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etcawstats · awstats · CWE-22 | Критическая9,8 | — | 3,8 % | 7 дек. 2020 г. |
38Наблюдать | CVE-2006-2237Готовый эксплойт | The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell awstats · awstats | Средняя5,1 | — | 58,4 % | 8 мая 2006 г. |
38Наблюдать | CVE-2010-4367Proof of concept | awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via awstats · awstats · CWE-94 | Высокая7,5 | — | 27,7 % | 2 дек. 2010 г. |
32Наблюдать | CVE-2005-0436Proof of concept | Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the Plawstats · awstats | Высокая7,5 | — | 7,0 % | 2 мая 2005 г. |
31Наблюдать | CVE-2010-4368Эксплойта нет | awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary coawstats · awstats · CWE-94 | Высокая7,5 | — | 2,5 % | 2 дек. 2010 г. |
31Наблюдать | CVE-2005-0363Эксплойта нет | awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.awstats · awstats | Высокая7,5 | — | 2,0 % | 2 мая 2005 г. |
31Наблюдать | CVE-2005-0437Эксплойта нет | Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via ..awstats · awstats | Высокая7,5 | — | 1,8 % | 2 мая 2005 г. |
31Наблюдать | CVE-2025-63261Эксплойта нет | AWStats 8.0 is vulnerable to Command Injection via the open functionawstats · awstats · CWE-78 | Высокая7,8 | — | 1,0 % | 20 мар. 2026 г. |
26Наблюдать | CVE-2010-4369Эксплойта нет | Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin direcawstats · awstats · CWE-22 | Средняя6,4 | — | 2,7 % | 2 дек. 2010 г. |
24Наблюдать | CVE-2009-5020Proof of concept | Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conducawstats · awstats · CWE-20 | Средняя5,8 | — | 3,5 % | 2 дек. 2010 г. |
24Наблюдать | CVE-2022-46391Эксплойта нет | AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.awstats · awstats · CWE-79 | Средняя6,1 | — | 0,7 % | 3 дек. 2022 г. |
23Наблюдать | CVE-2006-3682Proof of concept | awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode oawstats · awstats | Средняя5,0 | — | 9,7 % | 21 июл. 2006 г. |
22Наблюдать | CVE-2005-0435Proof of concept | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawawstats · awstats | Средняя5,0 | — | 7,4 % | 2 мая 2005 г. |
22Наблюдать | CVE-2020-35176Эксплойта нет | In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intenawstats · awstats · CWE-22 | Средняя5,3 | — | 2,2 % | 11 дек. 2020 г. |
22Наблюдать | CVE-2018-10245Proof of concept | A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining thawstats · awstats · CWE-200 | Средняя5,3 | — | 1,9 % | 20 апр. 2018 г. |
21Наблюдать | CVE-2005-0438Proof of concept | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.awstats · awstats | Средняя5,0 | — | 3,8 % | 2 мая 2005 г. |
21Наблюдать | CVE-2005-1527Эксплойта нет | Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitawstats · awstats · CWE-94 | Средняя5,0 | — | 3,0 % | 15 авг. 2005 г. |
21Наблюдать | CVE-2005-2732Эксплойта нет | AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the coawstats · awstats | Средняя5,0 | — | 1,7 % | 30 авг. 2005 г. |
19Наблюдать | CVE-2008-3714Proof of concept | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via theawstats · awstats · CWE-79 | Средняя4,3 | — | 5,6 % | 19 авг. 2008 г. |
19Наблюдать | CVE-2005-0362Эксплойта нет | awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadpawstats · awstats | Средняя4,6 | — | 1,8 % | 9 февр. 2005 г. |
17Наблюдать | CVE-2006-2644Эксплойта нет | AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awawstats · awstats | Средняя4,0 | — | 2,7 % | 30 мая 2006 г. |
17Наблюдать | CVE-2008-5080Эксплойта нет | awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scriptiawstats · awstats · CWE-79 | Средняя4,3 | — | 1,1 % | 3 дек. 2008 г. |
11Наблюдать | CVE-2006-1945Proof of concept | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or awstats · awstats | Низкая2,6 | — | 4,8 % | 20 апр. 2006 г. |
- CVE-2005-011652В плане
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir
ВысокаяCVSS 7,5Готовый эксплойтEPSS 75 %awstats · awstats18 янв. 2005 г.
- CVE-2017-100050140В плане
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %awstats · awstats3 янв. 2018 г.
- CVE-2020-2960040В плане
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %awstats · awstats7 дек. 2020 г.
- CVE-2006-223738Наблюдать
The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell
СредняяCVSS 5,1Готовый эксплойтEPSS 58 %awstats · awstats8 мая 2006 г.
- CVE-2010-436738Наблюдать
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 28 %awstats · awstats2 дек. 2010 г.
- CVE-2005-043632Наблюдать
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the Pl
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %awstats · awstats2 мая 2005 г.
- CVE-2010-436831Наблюдать
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary co
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %awstats · awstats2 дек. 2010 г.
- CVE-2005-036331Наблюдать
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %awstats · awstats2 мая 2005 г.
- CVE-2005-043731Наблюдать
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via ..
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %awstats · awstats2 мая 2005 г.
- CVE-2025-6326131Наблюдать
AWStats 8.0 is vulnerable to Command Injection via the open function
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %awstats · awstats20 мар. 2026 г.
- CVE-2010-436926Наблюдать
Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin direc
СредняяCVSS 6,4Эксплойта нетEPSS 3 %awstats · awstats2 дек. 2010 г.
- CVE-2009-502024Наблюдать
Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduc
СредняяCVSS 5,8Proof of conceptEPSS 3 %awstats · awstats2 дек. 2010 г.
- CVE-2022-4639124Наблюдать
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %awstats · awstats3 дек. 2022 г.
- CVE-2006-368223Наблюдать
awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode o
СредняяCVSS 5,0Proof of conceptEPSS 10 %awstats · awstats21 июл. 2006 г.
- CVE-2005-043522Наблюдать
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to raw
СредняяCVSS 5,0Proof of conceptEPSS 7 %awstats · awstats2 мая 2005 г.
- CVE-2020-3517622Наблюдать
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was inten
СредняяCVSS 5,3Эксплойта нетEPSS 2 %awstats · awstats11 дек. 2020 г.
- CVE-2018-1024522Наблюдать
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining th
СредняяCVSS 5,3Proof of conceptEPSS 2 %awstats · awstats20 апр. 2018 г.
- CVE-2005-043821Наблюдать
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
СредняяCVSS 5,0Proof of conceptEPSS 4 %awstats · awstats2 мая 2005 г.
- CVE-2005-152721Наблюдать
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbit
СредняяCVSS 5,0Эксплойта нетEPSS 3 %awstats · awstats15 авг. 2005 г.
- CVE-2005-273221Наблюдать
AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the co
СредняяCVSS 5,0Эксплойта нетEPSS 2 %awstats · awstats30 авг. 2005 г.
- CVE-2008-371419Наблюдать
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the
СредняяCVSS 4,3Proof of conceptEPSS 6 %awstats · awstats19 авг. 2008 г.
- CVE-2005-036219Наблюдать
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadp
СредняяCVSS 4,6Эксплойта нетEPSS 2 %awstats · awstats9 февр. 2005 г.
- CVE-2006-264417Наблюдать
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to aw
СредняяCVSS 4,0Эксплойта нетEPSS 3 %awstats · awstats30 мая 2006 г.
- CVE-2008-508017Наблюдать
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripti
СредняяCVSS 4,3Эксплойта нетEPSS 1 %awstats · awstats3 дек. 2008 г.
- CVE-2006-194511Наблюдать
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or
НизкаяCVSS 2,6Proof of conceptEPSS 5 %awstats · awstats20 апр. 2006 г.