Vulnerabilities > Awstats > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-03 CVE-2017-1000501 Path Traversal vulnerability in multiple products
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
network
low complexity
awstats debian CWE-22
7.5
2010-12-02 CVE-2010-4368 Code Injection vulnerability in Awstats
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.
network
low complexity
awstats microsoft CWE-94
7.5
2010-12-02 CVE-2010-4367 Code Injection vulnerability in Awstats
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server.
network
low complexity
awstats CWE-94
7.5
2005-05-02 CVE-2005-0437 Directory Traversal vulnerability in Awstats 6.3/6.4
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via ..
network
low complexity
awstats
7.5
2005-05-02 CVE-2005-0436 Remote Security vulnerability in Awstats 6.3/6.4
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
network
low complexity
awstats
7.5
2005-05-02 CVE-2005-0363 Unspecified vulnerability in Awstats 4.0/6.2
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
network
low complexity
awstats
7.5
2005-01-18 CVE-2005-0116 Improper Input Validation vulnerability in Awstats
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
network
low complexity
awstats CWE-20
7.5