CVE-2010-4369
published 2010-12-02CVE-2010-4369: Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.
PriorityP432medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.67%
84.1th percentile
Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| awstats | awstats | <= 6.95 | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v355-j978-c759: Directory traversal vulnerability in AWStats before 7
ghsa_unreviewed·2022-05-17
CVE-2010-4369 [MEDIUM] CWE-22 GHSA-v355-j978-c759: Directory traversal vulnerability in AWStats before 7
Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.
OSV
CVE-2010-4369: Directory traversal vulnerability in AWStats before 7
osv·2010-12-02·CVSS 6.4
CVE-2010-4369 [MEDIUM] CVE-2010-4369: Directory traversal vulnerability in AWStats before 7
Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.
Ubuntu
AWStats vulnerability
vendor_ubuntu·2011-01-24
CVE-2010-4369 AWStats vulnerability
Title: AWStats vulnerability
It was discovered that AWStats did not correctly filter the LoadPlugin
configuration option. A local attacker on a shared system could use this
to inject arbitrary code into AWStats.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2010-4369: awstats - Directory traversal vulnerability in AWStats before 7.0 allows remote attackers ...
vendor_debian·2010·CVSS 6.4
CVE-2010-4369 [MEDIUM] CVE-2010-4369: awstats - Directory traversal vulnerability in AWStats before 7.0 allows remote attackers ...
Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.
Scope: local
bookworm: resolved (fixed in 6.9.5~dfsg-5)
bullseye: resolved (fixed in 6.9.5~dfsg-5)
forky: resolved (fixed in 6.9.5~dfsg-5)
sid: resolved (fixed in 6.9.5~dfsg-5)
trixie: resolved (fixed in 6.9.5~dfsg-5)
No detection rules found.
No public exploits indexed.
http://awstats.sourceforge.net/docs/awstats_changelog.txthttp://secunia.com/advisories/43004http://www.mandriva.com/security/advisories?name=MDVSA-2011:033http://www.securityfocus.com/bid/45210http://www.ubuntu.com/usn/USN-1047-1http://www.vupen.com/english/advisories/2011/0202http://awstats.sourceforge.net/docs/awstats_changelog.txthttp://secunia.com/advisories/43004http://www.mandriva.com/security/advisories?name=MDVSA-2011:033http://www.securityfocus.com/bid/45210http://www.ubuntu.com/usn/USN-1047-1http://www.vupen.com/english/advisories/2011/0202
2010-12-02
Published