Show filters
140 Total Results
Displaying 11-20 of 140
Sort by:
Attacker Value
Unknown

CVE-2022-46391

Disclosure Date: December 04, 2022 (last updated October 08, 2023)
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Attacker Value
Unknown

CVE-2022-38223

Disclosure Date: August 15, 2022 (last updated December 30, 2023)
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Attacker Value
Unknown

CVE-2017-20099

Disclosure Date: June 27, 2022 (last updated October 07, 2023)
A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.
Attacker Value
Unknown

CVE-2020-23986

Disclosure Date: January 06, 2022 (last updated October 07, 2023)
Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError.
Attacker Value
Unknown

CVE-2015-10001

Disclosure Date: November 01, 2021 (last updated November 29, 2024)
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
Attacker Value
Unknown

CVE-2021-24679

Disclosure Date: October 04, 2021 (last updated November 28, 2024)
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2020-35176

Disclosure Date: December 12, 2020 (last updated February 22, 2025)
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
Attacker Value
Unknown

CVE-2020-29600

Disclosure Date: December 07, 2020 (last updated February 22, 2025)
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
Attacker Value
Unknown

CVE-2018-10245

Disclosure Date: April 20, 2018 (last updated November 26, 2024)
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
0
Attacker Value
Unknown

CVE-2018-6198

Disclosure Date: January 25, 2018 (last updated December 30, 2023)
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.
0