FreeBSD : Piwik -- remote command execution vulnerability (23c8423e-9bff-11e0-8ea2-0019d18c446a)

High Nessus Plugin ID 55395


The remote FreeBSD host is missing a security-related update.


The Piwik security advisory reports :

The Piwik 1.5 release addresses a critical security vulnerability, which affect all Piwik users that have let granted some access to the 'anonymous' user.

Piwik contains a remotely exploitable vulnerability that could allow a remote attacker to execute arbitrary code. Only installations that have granted untrusted view access to their stats (ie. grant 'view' access to a website to anonymous) are at risk.


Update the affected package.

See Also

Plugin Details

Severity: High

ID: 55395

File Name: freebsd_pkg_23c8423e9bff11e08ea20019d18c446a.nasl

Version: $Revision: 1.6 $

Type: local

Published: 2011/06/22

Modified: 2014/09/18

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:piwik, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2011/06/21

Vulnerability Publication Date: 2011/06/21