CVE-2020-35176: Path Traversal
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35176?
CVE-2020-35176 is a vulnerability in AWStats through 7.8 that allows a partial absolute pathname to be accepted, potentially exposing sensitive information.
What is the severity of CVE-2020-35176?
The severity of CVE-2020-35176 is medium with a CVSS score of 5.3.
How does CVE-2020-35176 affect AWStats?
CVE-2020-35176 affects AWStats through version 7.8 by allowing a partial absolute pathname to be accepted, which was not intended.
How does CVE-2020-35176 impact Debian Debian Linux 9.0?
CVE-2020-35176 impacts Debian Debian Linux 9.0 as it is one of the affected software versions.
Is there a fix for CVE-2020-35176?
Yes, the fix for CVE-2020-35176 has been released. It is recommended to update to the latest version of AWStats.