A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-2319 A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T20:32:47.833Z

Reserved: 2018-04-20T00:00:00Z

Link: CVE-2018-10245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-20T17:29:00.243

Modified: 2024-11-21T03:41:06.093

Link: CVE-2018-10245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.