NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66123 | CVE-2005-0363 | awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
15623 | CVE-2010-4368 | awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname. | 2 | 7.5 | High | 2017-01-18 | 2010-12-03 | View | |
15622 | CVE-2010-4367 | awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server. | 2 | 7.5 | High | 2017-01-18 | 2011-02-23 | View | |
61329 | CVE-2006-2644 | AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
68421 | CVE-2005-2732 | AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 16197 of 17672, showing 5 records out of 88360 total, starting on record 80981, ending on 80985