Vulnerabilities (CVE)

Filtered by vendor Awstats Subscribe
Filtered by product Awstats
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0437 1 Awstats 1 Awstats 2023-12-10 7.5 HIGH N/A
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
CVE-2005-2732 1 Awstats 1 Awstats 2023-12-10 5.0 MEDIUM N/A
AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message.
CVE-2006-2237 1 Awstats 1 Awstats 2023-12-10 5.1 MEDIUM N/A
The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.
CVE-2006-3682 1 Awstats 1 Awstats 2023-12-10 5.0 MEDIUM N/A
awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters.
CVE-2006-1945 1 Awstats 1 Awstats 2023-12-10 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.