cbcvebase.

Debian Awstats vulnerabilities

24 known vulnerabilities affecting debian/awstats.

Total CVEs
24
CISA KEV
0
Public exploits
11
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH4MEDIUM8LOW9

Vulnerabilities

Page 2 of 2
CVE-2022-46391P4MEDIUMCVSS 6.1fixed in awstats 7.8-3 (bookworm)2022
CVE-2022-46391 [MEDIUM] CVE-2022-46391: awstats - AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a resp... AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks. Scope: local bookworm: resolved (fixed in 7.8-3) bullseye: resolved (fixed in 7.8-2+deb11u1) forky: resolved (fixed in 7.8-3) sid: resolved (fixed in 7.8-3) trixie: resolved (fixed in 7.8-3)
debian
CVE-2006-2644P4MEDIUMCVSS 4.0fixed in awstats 6.5-2 (bookworm)2006
CVE-2006-2644 [MEDIUM] CVE-2006-2644: awstats - AWStats 6.5, and possibly other versions, allows remote authenticated users to e... AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive. Scope: local bookworm: resolved (fixed in 6.5-2) bullseye: resolved (fixed in 6.5-2) forky: res
debian
CVE-2008-5080P4LOWCVSS 4.3fixed in awstats 6.7.dfsg-5.1 (bookworm)2008
CVE-2008-5080 [MEDIUM] CVE-2008-5080: awstats - awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters,... awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714. Scope: local bookworm: resolved (fixed in 6.7.dfsg-5.1) bullseye: resolved (fixed in 6.7.dfsg-5.1) forky: r
debian
CVE-2006-3681P4LOWCVSS 2.6fixed in awstats 6.5-2 (bookworm)2006
CVE-2006-3681 [LOW] CVE-2006-3681: awstats - Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5... Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945. Scope: local bookwo
debian