vendor:
AWStats Totals
by:
Ricardo Almeida
9.3
CVSS
HIGH
Remote Execution Exploit
78
CWE
Product Name: AWStats Totals
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2008
Remote Execution Exploit for AWStats Totals vulnerability (Interactive Shell) Version 2
This exploit allows an attacker to execute arbitrary commands on a vulnerable system. It works by sending a maliciously crafted HTTP request to the vulnerable system, which then executes the command. The exploit works with both magic quotes on or off.
Mitigation:
Disable the vulnerable script or apply the patch provided by the vendor.