vendor:
AWStats
by:
Matteo Cantoni and hdm
N/A
CVSS
N/A
Arbitrary Command Execution
78
CWE
Product Name: AWStats
Affected Version From: 6.1
Affected Version To: 6.2
Patch Exists: NO
Related CWE: CVE-2005-0116
CPE: awstats
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=16189, https://www.infosecmatter.com/nessus-plugin-library/?id=16427, https://www.infosecmatter.com/nessus-plugin-library/?id=18840, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/unix/webapp/awstats_configdir_exec
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2005
AWStats configdir Remote Command Execution
This module exploits an arbitrary command execution vulnerability in the AWStats CGI script. iDEFENSE has confirmed that AWStats versions 6.1 and 6.2 are vulnerable.
Mitigation:
No known mitigation or remediation for this vulnerability