CVE-2020-29600
published 2020-12-07CVE-2020-29600: In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.91%
85.4th percentile
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| awstats | awstats | <= 7.7 | — |
| awstats | awstats | <= 7.8 | — |
| awstats | awstats | >= 0 < 7.8-1 | 7.8-1 |
| awstats | awstats | >= 0 < 7.8-2 | 7.8-2 |
| awstats | awstats | >= 0 < 7.8-1 | 7.8-1 |
| awstats | awstats | >= 0 < 7.8-2 | 7.8-2 |
| awstats | awstats | >= 0 < 7.8-1 | 7.8-1 |
| awstats | awstats | >= 0 < 7.8-2 | 7.8-2 |
| awstats | awstats | >= 0 < 7.8-1 | 7.8-1 |
| awstats | awstats | >= 0 < 7.8-2 | 7.8-2 |
| awstats | awstats | >= 0 < 7.6+dfsg-2ubuntu0.18.04.1 | 7.6+dfsg-2ubuntu0.18.04.1 |
| awstats | awstats | >= 0 < 7.6+dfsg-2ubuntu0.20.04.1 | 7.6+dfsg-2ubuntu0.20.04.1 |
| awstats | awstats | >= 0 < 7.4+dfsg-1ubuntu0.4+esm1 | 7.4+dfsg-1ubuntu0.4+esm1 |
| debian | awstats | < awstats 7.8-2 (bookworm) | awstats 7.8-2 (bookworm) |
| debian | awstats | < awstats 7.8-1 (bookworm) | awstats 7.8-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
AWStats vulnerabilities
vendor_ubuntu·2021-05-13·CVSS 9.8
CVE-2020-35176 [CRITICAL] AWStats vulnerabilities
Title: AWStats vulnerabilities
Summary: Several security issues were fixed in AWStats.
Sean Boran discovered that AWStats incorrectly filtered certain parameters.
A remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-29600)
It was discovered that AWStats incorrectly filtered certain parameters. A
remote attacker could possibly use this issue to access sensitive
information. (CVE-2020-35176)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-35176: awstats - In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pa...
vendor_debian·2020·CVSS 9.8
CVE-2020-35176 [CRITICAL] CVE-2020-35176: awstats - In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pa...
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
Scope: local
bookworm: resolved (fixed in 7.8-2)
bullseye: resolved (fixed in 7.8-2)
forky: resolved (fixed in 7.8-2)
sid: resolved (fixed in 7.8-2)
trixie: resolved (fixed in 7.8-2)
Debian
CVE-2020-29600: awstats - In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname,...
vendor_debian·2020·CVSS 9.8
CVE-2020-29600 [CRITICAL] CVE-2020-29600: awstats - In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname,...
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
Scope: local
bookworm: resolved (fixed in 7.8-1)
bullseye: resolved (fixed in 7.8-1)
forky: resolved (fixed in 7.8-1)
sid: resolved (fixed in 7.8-1)
trixie: resolved (fixed in 7.8-1)
GHSA
GHSA-6hh4-7wc7-6vq9: In AWStats through 7
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2020-35176 [CRITICAL] CWE-22 GHSA-6hh4-7wc7-6vq9: In AWStats through 7
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
GHSA
GHSA-43g3-5cf8-2gm2: In AWStats through 7
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2020-29600 [CRITICAL] CWE-22 GHSA-43g3-5cf8-2gm2: In AWStats through 7
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
OSV
awstats vulnerabilities
osv·2021-05-13·CVSS 9.8
CVE-2020-29600 [CRITICAL] awstats vulnerabilities
awstats vulnerabilities
Sean Boran discovered that AWStats incorrectly filtered certain parameters.
A remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-29600)
It was discovered that AWStats incorrectly filtered certain parameters. A
remote attacker could possibly use this issue to access sensitive
information. (CVE-2020-35176)
OSV
CVE-2020-35176: In AWStats through 7
osv·2020-12-12·CVSS 9.8
CVE-2020-35176 [CRITICAL] CVE-2020-35176: In AWStats through 7
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
OSV
CVE-2020-29600: In AWStats through 7
osv·2020-12-07·CVSS 9.8
CVE-2020-29600 [CRITICAL] CVE-2020-29600: In AWStats through 7
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891469https://github.com/eldy/awstats/issues/90https://lists.debian.org/debian-lts-announce/2020/12/msg00035.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47QZWKSRZYZFESYTLSW7A6KVKOOPL7IV/https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891469https://github.com/eldy/awstats/issues/90https://lists.debian.org/debian-lts-announce/2020/12/msg00035.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47QZWKSRZYZFESYTLSW7A6KVKOOPL7IV/
2020-12-07
Published