AWStats 7.6 contains a full path disclosure caused by improper handling of framename and update parameters in awstats.pl, letting remote attackers determine server file paths, exploit requires sending crafted parameters.
id: CVE-2018-10245
info:
name: AWStats <= 7.5 - Full Path Disclosure
author: 0x_Akoko
severit
...