CVE-2017-1000501: Path Traversal
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-1000501?
CVE-2017-1000501 is a vulnerability in Awstats version 7.6 and earlier that allows for unauthenticated remote code execution through a path traversal flaw in the handling of the 'config' and 'migrate' parameters.
How severe is CVE-2017-1000501?
CVE-2017-1000501 has a severity score of 9.8, which is considered critical.
Which software is affected by CVE-2017-1000501?
Awstats version 7.6 and earlier, as well as Debian Linux versions 7.0, 8.0, and 9.0, are affected by CVE-2017-1000501.
How can I fix CVE-2017-1000501?
To fix CVE-2017-1000501, upgrade to Awstats version 7.9-1 or later and apply the necessary updates for Debian Linux.
Where can I find more information about CVE-2017-1000501?
You can find more information about CVE-2017-1000501 on the Awstats website and the GitHub repository for Awstats.