Перейти к содержимому
Noroxi

Записи awstats

26 опубликованных записей вендора awstats.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
2 · 7,7 %
Pre-auth RCE
8
С записью об исправлении
88,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

26 записей
  • CVE-2005-0116
    52В плане

    AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 75 %

    awstats · awstats18 янв. 2005 г.

  • CVE-2017-1000501
    40В плане

    Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    awstats · awstats3 янв. 2018 г.

  • CVE-2020-29600
    40В плане

    In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    awstats · awstats7 дек. 2020 г.

  • CVE-2006-2237
    38Наблюдать

    The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell

    СредняяCVSS 5,1Готовый эксплойтEPSS 58 %

    awstats · awstats8 мая 2006 г.

  • CVE-2010-4367
    38Наблюдать

    awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via

    ВысокаяCVSS 7,5Proof of conceptEPSS 28 %

    awstats · awstats2 дек. 2010 г.

  • CVE-2005-0436
    32Наблюдать

    Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the Pl

    ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

    awstats · awstats2 мая 2005 г.

  • CVE-2010-4368
    31Наблюдать

    awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary co

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    awstats · awstats2 дек. 2010 г.

  • CVE-2005-0363
    31Наблюдать

    awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    awstats · awstats2 мая 2005 г.

  • CVE-2005-0437
    31Наблюдать

    Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via ..

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    awstats · awstats2 мая 2005 г.

  • CVE-2025-63261
    31Наблюдать

    AWStats 8.0 is vulnerable to Command Injection via the open function

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    awstats · awstats20 мар. 2026 г.

  • CVE-2010-4369
    26Наблюдать

    Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin direc

    СредняяCVSS 6,4Эксплойта нетEPSS 3 %

    awstats · awstats2 дек. 2010 г.

  • CVE-2009-5020
    24Наблюдать

    Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduc

    СредняяCVSS 5,8Proof of conceptEPSS 3 %

    awstats · awstats2 дек. 2010 г.

  • CVE-2022-46391
    24Наблюдать

    AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    awstats · awstats3 дек. 2022 г.

  • CVE-2006-3682
    23Наблюдать

    awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode o

    СредняяCVSS 5,0Proof of conceptEPSS 10 %

    awstats · awstats21 июл. 2006 г.

  • CVE-2005-0435
    22Наблюдать

    awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to raw

    СредняяCVSS 5,0Proof of conceptEPSS 7 %

    awstats · awstats2 мая 2005 г.

  • CVE-2020-35176
    22Наблюдать

    In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was inten

    СредняяCVSS 5,3Эксплойта нетEPSS 2 %

    awstats · awstats11 дек. 2020 г.

  • CVE-2018-10245
    22Наблюдать

    A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining th

    СредняяCVSS 5,3Proof of conceptEPSS 2 %

    awstats · awstats20 апр. 2018 г.

  • CVE-2005-0438
    21Наблюдать

    awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.

    СредняяCVSS 5,0Proof of conceptEPSS 4 %

    awstats · awstats2 мая 2005 г.

  • CVE-2005-1527
    21Наблюдать

    Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbit

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    awstats · awstats15 авг. 2005 г.

  • CVE-2005-2732
    21Наблюдать

    AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the co

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    awstats · awstats30 авг. 2005 г.

  • CVE-2008-3714
    19Наблюдать

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the

    СредняяCVSS 4,3Proof of conceptEPSS 6 %

    awstats · awstats19 авг. 2008 г.

  • CVE-2005-0362
    19Наблюдать

    awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadp

    СредняяCVSS 4,6Эксплойта нетEPSS 2 %

    awstats · awstats9 февр. 2005 г.

  • CVE-2006-2644
    17Наблюдать

    AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to aw

    СредняяCVSS 4,0Эксплойта нетEPSS 3 %

    awstats · awstats30 мая 2006 г.

  • CVE-2008-5080
    17Наблюдать

    awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripti

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    awstats · awstats3 дек. 2008 г.

  • CVE-2006-1945
    11Наблюдать

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or

    НизкаяCVSS 2,6Proof of conceptEPSS 5 %

    awstats · awstats20 апр. 2006 г.