CVE-2018-10245
AWStats <= 7.5 - Full Path Disclosure
Record summary
CVE-2018-10245 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMAWStats <= 7.5 - Full Path DisclosureCVSS 5.3
AWStats 7.6 contains a full path disclosure caused by improper handling of framename and update parameters in awstats.pl, letting remote attackers determine server file paths, exploit requires sending crafted parameters.
Impact
Attackers can discover server file paths, aiding further exploitation or reconnaissance.
Remediation
Update to the latest version of AWStats or apply security patches addressing this issue.
Source: ProjectDiscovery