Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-35176

Опубликовано: 12 дек. 2020
Источник: debian
EPSS Низкий

Описание

In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
awstatsfixed7.8-2package
awstatsfixed7.6+dfsg-2+deb10u1busterpackage

Примечания

  • https://github.com/eldy/awstats/issues/195

  • https://github.com/eldy/AWStats/commit/96756d7f40e002cc1e6ba72c633fb66b92e54f49

EPSS

Процентиль: 76%
0.00937
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.

CVSS3: 5.3
nvd
около 5 лет назад

In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.

CVSS3: 5.3
github
больше 3 лет назад

In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.

EPSS

Процентиль: 76%
0.00937
Низкий