CVE-2020-29600: Path Traversal
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29600?
CVE-2020-29600 is a vulnerability in AWStats that allows an absolute pathname to be accepted instead of the intended format.
What is the severity of CVE-2020-29600?
The severity of CVE-2020-29600 is critical with a CVSS severity score of 9.8.
How does CVE-2020-29600 affect AWStats?
CVE-2020-29600 allows an absolute pathname to be accepted in the 'config' parameter of cgi-bin/awstats.pl file, which can lead to unauthorized access of files.
Which software versions are affected by CVE-2020-29600?
AWStats versions up to and including 7.7 are affected by CVE-2020-29600.
Is there a fix available for CVE-2020-29600?
At the moment, there is no known fix available for CVE-2020-29600. It is recommended to update to a patched version of AWStats when it becomes available.