PT-2018-9780 · Awstats+2 · Awstats+2

Juanri Villén

+2

·

Publicado

2018-01-12

·

Atualizado

2018-05-18

·

CVE-2018-10245

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: AWStats versions prior to 7.7
Description: A Full Path Disclosure issue allows remote attackers to determine the location of the config file, thereby obtaining the full path of the server. This can be achieved by exploiting the awstats.pl "framename" and "update" parameters.
Recommendations: For AWStats versions prior to 7.7, update to version 7.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the awstats.pl script to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1032
CVE-2018-10245

Produtos afetados

Alt Linux
Awstats
Debian