CVE-2020-35176
published 2020-12-12CVE-2020-35176: In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.83%
76.5th percentile
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| awstats | awstats | <= 7.8 | — |
| awstats | awstats | >= 0 < 7.8-2 | 7.8-2 |
| awstats | awstats | >= 0 < 7.8-2 | 7.8-2 |
| awstats | awstats | >= 0 < 7.8-2 | 7.8-2 |
| awstats | awstats | >= 0 < 7.8-2 | 7.8-2 |
| awstats | awstats | >= 0 < 7.6+dfsg-2ubuntu0.18.04.1 | 7.6+dfsg-2ubuntu0.18.04.1 |
| awstats | awstats | >= 0 < 7.6+dfsg-2ubuntu0.20.04.1 | 7.6+dfsg-2ubuntu0.20.04.1 |
| awstats | awstats | >= 0 < 7.4+dfsg-1ubuntu0.4+esm1 | 7.4+dfsg-1ubuntu0.4+esm1 |
| debian | awstats | < awstats 7.8-2 (bookworm) | awstats 7.8-2 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
AWStats vulnerabilities
vendor_ubuntu·2021-05-13·CVSS 9.8
CVE-2020-35176 [CRITICAL] AWStats vulnerabilities
Title: AWStats vulnerabilities
Summary: Several security issues were fixed in AWStats.
Sean Boran discovered that AWStats incorrectly filtered certain parameters.
A remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-29600)
It was discovered that AWStats incorrectly filtered certain parameters. A
remote attacker could possibly use this issue to access sensitive
information. (CVE-2020-35176)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-35176: awstats - In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pa...
vendor_debian·2020·CVSS 9.8
CVE-2020-35176 [CRITICAL] CVE-2020-35176: awstats - In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pa...
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
Scope: local
bookworm: resolved (fixed in 7.8-2)
bullseye: resolved (fixed in 7.8-2)
forky: resolved (fixed in 7.8-2)
sid: resolved (fixed in 7.8-2)
trixie: resolved (fixed in 7.8-2)
GHSA
GHSA-6hh4-7wc7-6vq9: In AWStats through 7
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2020-35176 [CRITICAL] CWE-22 GHSA-6hh4-7wc7-6vq9: In AWStats through 7
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
OSV
awstats vulnerabilities
osv·2021-05-13·CVSS 9.8
CVE-2020-29600 [CRITICAL] awstats vulnerabilities
awstats vulnerabilities
Sean Boran discovered that AWStats incorrectly filtered certain parameters.
A remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-29600)
It was discovered that AWStats incorrectly filtered certain parameters. A
remote attacker could possibly use this issue to access sensitive
information. (CVE-2020-35176)
OSV
CVE-2020-35176: In AWStats through 7
osv·2020-12-12·CVSS 9.8
CVE-2020-35176 [CRITICAL] CVE-2020-35176: In AWStats through 7
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/eldy/awstats/issues/195https://lists.debian.org/debian-lts-announce/2020/12/msg00035.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47QZWKSRZYZFESYTLSW7A6KVKOOPL7IV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHYCKLW5VPM6KP2WZW6DCCVHVBG7YCW/https://github.com/eldy/awstats/issues/195https://lists.debian.org/debian-lts-announce/2020/12/msg00035.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47QZWKSRZYZFESYTLSW7A6KVKOOPL7IV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHYCKLW5VPM6KP2WZW6DCCVHVBG7YCW/
2020-12-12
Published