Show filters
140 Total Results
Displaying 11-20 of 140
Sort by:
Attacker Value
Unknown
CVE-2022-46391
Disclosure Date: December 04, 2022 (last updated October 08, 2023)
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
0
Attacker Value
Unknown
CVE-2022-38223
Disclosure Date: August 15, 2022 (last updated December 30, 2023)
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2017-20099
Disclosure Date: June 27, 2022 (last updated October 07, 2023)
A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.
0
Attacker Value
Unknown
CVE-2020-23986
Disclosure Date: January 06, 2022 (last updated October 07, 2023)
Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError.
0
Attacker Value
Unknown
CVE-2015-10001
Disclosure Date: November 01, 2021 (last updated November 29, 2024)
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
0
Attacker Value
Unknown
CVE-2021-24679
Disclosure Date: October 04, 2021 (last updated November 28, 2024)
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2020-35176
Disclosure Date: December 12, 2020 (last updated February 22, 2025)
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
0
Attacker Value
Unknown
CVE-2020-29600
Disclosure Date: December 07, 2020 (last updated February 22, 2025)
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
0
Attacker Value
Unknown
CVE-2018-10245
Disclosure Date: April 20, 2018 (last updated November 26, 2024)
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
0
Attacker Value
Unknown
CVE-2018-6198
Disclosure Date: January 25, 2018 (last updated December 30, 2023)
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.
0