AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
2006-05-30T10:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | awstats | awstats | 6.4_1 | Yes |
Application | awstats | awstats | 6.5 | Yes |
Application | awstats | awstats | 6.5_1 | Yes |