PT-2005-1438 · Awstats · Awstats
Celso Gonzalez
·
Publicado
2005-02-16
·
Atualizado
2008-09-05
·
CVE-2005-0363
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AWStats versions 4.0 through 6.2
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the
config parameter. This can be exploited by sending malicious input to the affected software.Recommendations
For AWStats versions 4.0 through 6.2, consider restricting access to the
config parameter to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the config parameter with untrusted input.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Awstats