Description
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 alpine v3.20 | | =6.95-r0 || =7.0-r0 || =7.1-r0 || =7.1.1-r0 || =7.2-r0 || =7.2-r1 || =7.3-r0 || =7.4-r0 || =7.5-r0 || =7.5-r1 || =7.6-r0 || =7.6-r1 || >=0 <7.6-r2 | 7.6-r2 |
 alpine v3.22 | | =6.95-r0 || =7.0-r0 || =7.1-r0 || =7.1.1-r0 || =7.2-r0 || =7.2-r1 || =7.3-r0 || =7.4-r0 || =7.5-r0 || =7.5-r1 || =7.6-r0 || =7.6-r1 || >=0 <7.6-r2 | 7.6-r2 |
 debian 14 | | | 7.6+dfsg-2 |
 debian 13 | | | 7.6+dfsg-2 |
 alpine v3.13 | | =6.95-r0 || =7.0-r0 || =7.1-r0 || =7.1.1-r0 || =7.2-r0 || =7.2-r1 || =7.3-r0 || =7.4-r0 || =7.5-r0 || =7.5-r1 || =7.6-r0 || =7.6-r1 || >=0 <7.6-r2 | 7.6-r2 |
 alpine v3.17 | | =6.95-r0 || =7.0-r0 || =7.1-r0 || =7.1.1-r0 || =7.2-r0 || =7.2-r1 || =7.3-r0 || =7.4-r0 || =7.5-r0 || =7.5-r1 || =7.6-r0 || =7.6-r1 || >=0 <7.6-r2 | 7.6-r2 |
 alpine v3.18 | | =6.95-r0 || =7.0-r0 || =7.1-r0 || =7.1.1-r0 || =7.2-r0 || =7.2-r1 || =7.3-r0 || =7.4-r0 || =7.5-r0 || =7.5-r1 || =7.6-r0 || =7.6-r1 || >=0 <7.6-r2 | 7.6-r2 |
 alpine v3.21 | | =6.95-r0 || =7.0-r0 || =7.1-r0 || =7.1.1-r0 || =7.2-r0 || =7.2-r1 || =7.3-r0 || =7.4-r0 || =7.5-r0 || =7.5-r1 || =7.6-r0 || =7.6-r1 || >=0 <7.6-r2 | 7.6-r2 |
 alpine v3.14 | | =6.95-r0 || =7.0-r0 || =7.1-r0 || =7.1.1-r0 || =7.2-r0 || =7.2-r1 || =7.3-r0 || =7.4-r0 || =7.5-r0 || =7.5-r1 || =7.6-r0 || =7.6-r1 || >=0 <7.6-r2 | 7.6-r2 |
 alpine v3.15 | | =6.95-r0 || =7.0-r0 || =7.1-r0 || =7.1.1-r0 || =7.2-r0 || =7.2-r1 || =7.3-r0 || =7.4-r0 || =7.5-r0 || =7.5-r1 || =7.6-r0 || =7.6-r1 || >=0 <7.6-r2 | 7.6-r2 |