Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28582
HistoryDec 13, 2020 - 4:24 a.m.

Remote Code Execution

2020-12-1304:24:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
awstats
vulnerability
remote code execution
cgi-bin
configuration file

EPSS

0.002

Percentile

61.2%

awstats is vulnerable to remote code execution. The vulnerability exists as cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format.