NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4867 | CVE-2008-5080 | awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-04 | View | |
62350 | CVE-2006-3682 | awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
66193 | CVE-2005-0435 | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66196 | CVE-2005-0438 | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66122 | CVE-2005-0362 | awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters. | 2 | 4.6 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 16196 of 17672, showing 5 records out of 88360 total, starting on record 80976, ending on 80980