CVE-2017-1000501Path Traversal in Awstats

CWE-22Path Traversal17 documents6 sources
Severity
9.8CRITICALNVD
NVD5.3
EPSS
6.5%
top 8.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 3
Latest updateMay 24

Description

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

debiandebian/awstats< awstats 7.8-2 (bookworm)+2
Debianawstats/awstats< 7.8-1+11
NVDawstats/awstats7.6.0+2

Also affects: Debian Linux 7.0, 8.0, 9.0, Fedora 32, 33

Patches

🔴Vulnerability Details

6
GHSA
GHSA-6hh4-7wc7-6vq9: In AWStats through 72022-05-24
GHSA
GHSA-43g3-5cf8-2gm2: In AWStats through 72022-05-24
GHSA
GHSA-ph65-4f3r-7fv8: Awstats version 72022-05-13
OSV
CVE-2020-35176: In AWStats through 72020-12-12
OSV
CVE-2020-29600: In AWStats through 72020-12-07

📋Vendor Advisories

5
Ubuntu
AWStats vulnerabilities2021-05-13
Debian
CVE-2020-35176: awstats - In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pa...2020
Debian
CVE-2020-29600: awstats - In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname,...2020
Ubuntu
AWStats vulnerability2018-01-08
Debian
CVE-2017-1000501: awstats - Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the ha...2017

💬Community

3
Bugzilla
CVE-2017-1000501 awstats: awstat: Two path traversal issues in awstat.pl [epel-all]2017-12-27
Bugzilla
CVE-2017-1000501 awstat: Two path traversal issues in awstat.pl2017-12-27
Bugzilla
CVE-2017-1000501 awstats: awstat: Two path traversal issues in awstat.pl [fedora-all]2017-12-27
CVE-2017-1000501 — Path Traversal in Debian Awstats | cvebase