Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

AWStats < 6.6 migrate Variable Command Execution



The remote host is vulnerable to an arbitrary 'command insertion' flaw.


The remote host is running AWStats, a CGI log analyzer. There are various content-parsing flaws in the remote version of this software that would allow an attacker to execute code on the remote host. An attacker exploiting this flaw would only need to be able to generate HTTP requests to the awstats.pl CGI script. A successful attack would allow the attacker to run system commands with the privileges of the CGI script.


Upgrade to version 6.6 or higher.