PT-2005-1438 · Awstats · Awstats
Celso Gonzalez
·
Published
2005-02-16
·
Updated
2008-09-05
·
CVE-2005-0363
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AWStats versions 4.0 through 6.2
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the
config parameter. This can be exploited by sending malicious input to the affected software.Recommendations
For AWStats versions 4.0 through 6.2, consider restricting access to the
config parameter to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the config parameter with untrusted input.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Awstats