Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
awstats vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-3714
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote malicious users to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
Awstats Awstats 6.8
1 EDB exploit
NA
CVE-2008-3921
Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 up to and including 1.14 allow remote malicious users to inject arbitrary web script or HTML via the (1) month and (2) year parameter.
Telartis Bv Awstats Totals 1.0
Telartis Bv Awstats Totals 1.1
Telartis Bv Awstats Totals 1.11
Telartis Bv Awstats Totals 1.13
Telartis Bv Awstats Totals 1.14
NA
CVE-2008-3922
awstatstotals.php in AWStats Totals 1.0 up to and including 1.14 allows remote malicious users to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.
Telartis Bv Awstats Totals 1.1
Telartis Bv Awstats Totals 1.11
Telartis Bv Awstats Totals 1.13
Telartis Bv Awstats Totals 1.14
Telartis Bv Awstats Totals 1.0
2 EDB exploits
1 Nmap script
9.8
CVSSv3
CVE-2020-29600
In AWStats up to and including 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
Awstats Awstats
Debian Debian Linux 9.0
Fedoraproject Fedora 32
5.3
CVSSv3
CVE-2020-35176
In AWStats up to and including 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-20...
Awstats Awstats
Debian Debian Linux 9.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
6.1
CVSSv3
CVE-2022-46391
AWStats 7.x up to and including 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Awstats Awstats
Debian Debian Linux 10.0
Fedoraproject Fedora 36
Fedoraproject Fedora 37
NA
CVE-2005-1527
Eval injection vulnerability in awstats.pl in AWStats 6.4 and previous versions, when a URLPlugin is enabled, allows remote malicious users to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
Awstats Awstats
Canonical Ubuntu Linux 5.04
Debian Debian Linux 3.1
Debian Debian Linux 3.0
9.8
CVSSv3
CVE-2017-1000501
Awstats version 7.6 and previous versions is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
Awstats Awstats
Debian Debian Linux 7.0
Debian Debian Linux 8.0
Debian Debian Linux 9.0
6.3
CVSSv3
CVE-2018-20912
cPanel prior to 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
Cpanel Cpanel
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
firmware
CVE-2006-4304
CVE-2024-32878
CVE-2024-31502
XSS
CVE-2024-3059
CVE-2024-33692
CVE-2024-3400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3