Description
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-2643 | AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive. |
Ubuntu USN |
USN-290-1 | awstats vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T17:58:51.684Z
Reserved: 2006-05-30T00:00:00.000Z
Link: CVE-2006-2644
No data.
Status : Deferred
Published: 2006-05-30T10:02:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-2644
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN