S4E just found a high-severity finding from top 38 parameters xss vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2009-5020 Scanner

CVE-2009-5020 scanner - Open Redirect vulnerability in AWStats

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2009-5020
5.8
CVSS

Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

AWStats is a free, open-source website traffic analysis tool that generates advanced web, ftp, or mail server statistics. It is widely used by web developers and site owners to keep track of the number of visitors on their site, the pages they visit, and the time they spend on different sections of their website. The software is easy to use and provides insightful data visualizations and reports that help in optimizing the website content and enhancing the user experience.

CVE-2009-5020 is a security vulnerability that was detected in AWStats before version 6.95. The vulnerability is caused by an open redirect in the awredir.pl script, which allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks using unspecified vectors. This means that an attacker could trick a user into visiting a malicious website by sending them a link that appears to be legitimate but actually redirects them to a phishing site. 

When this vulnerability is exploited, it can lead to serious consequences for both the website owner and site's visitors. An attacker can use the vulnerability to steal sensitive information from the visitors, manipulate their behavior, or even compromise the entire website. This can damage the reputation of the website and lead to financial losses. Additionally, if visitors have logged in to the website, their credentials can be stolen, which can lead to major data breaches.

In conclusion, vulnerabilities in digital assets can have severe consequences for both website owners and users. With the pro features of s4e.io, anyone can quickly and easily learn about vulnerabilities in their digital assets and take the necessary precautions to protect against them. It is important to stay vigilant and keep software up-to-date to avoid potential exploits and data breaches. By taking proactive measures, website owners can safeguard their websites and users' sensitive information.

 

REFERENCES

Solution Advice

Protecting against this vulnerability is crucial for website owners. Some of the measures that can be taken to mitigate this vulnerability include:

  • Updating AWStats to the latest version that has the vulnerability fixed.
  • Preventing users from accessing the awredir.pl script.
  • Implementing a URL validation scheme to ensure that any redirects made are valid.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2009-5020 scanner - Open Redirect vulnerability in AWStats | S4E