In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-awstats | Mar 26, 2024 | Dec 11, 2020 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Dec 11, 2020 | |
| Debian | debian-upgrade-awstats | Dec 29, 2020 | Dec 12, 2020 | |
| Freebsd | freebsd-upgrade-package-awstats | Jan 24, 2023 | Jan 23, 2023 | |
| Ubuntu | ubuntu-pro-upgrade-awstatsubuntu-upgrade-awstats | May 14, 2021 | Dec 12, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub