Record summary

CVE-2018-10245 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMAWStats <= 7.5 - Full Path DisclosureCVSS 5.3

AWStats 7.6 contains a full path disclosure caused by improper handling of framename and update parameters in awstats.pl, letting remote attackers determine server file paths, exploit requires sending crafted parameters.

Impact

Attackers can discover server file paths, aiding further exploitation or reconnaissance.

Remediation

Update to the latest version of AWStats or apply security patches addressing this issue.

WeaknessesCWE-200
Authors0x_Akoko
Template tagscvecve2018awstatsfpddisclosureexposure
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:laurent_destailleur:awstats:*:*:*:*:*:*:*:*
Shodan: http.html:"AWStats"
FOFA: app="AWStats"
Google: inurl:"awstats.pl"

Source: ProjectDiscovery

References

2