LWN.net Logo

AWStats: remote code execution

Package(s):awstats CVE #(s):CAN-2005-0116 CAN-2005-0362 CAN-2005-0363
Created:January 25, 2005 Updated:February 15, 2005
Description: When 'awstats.pl' is run as a CGI script, it fails to validate specific inputs which are used in a Perl open() function call. A remote attacker could supply AWStats malicious input, potentially allowing the execution of arbitrary code with the rights of the web server.
Alerts:
Debian DSA-682-1 2005-02-15
Gentoo 200501-36:03 2005-01-25
Gentoo 200501-36 2005-01-25

(Log in to post comments)

AWStats: remote code execution

Posted Feb 4, 2005 9:28 UTC (Fri) by nettings (subscriber, #429) [Link]

this one is being exploited actively (how do i know? wellll...)
a few days ago i found a moviez exchange in my /tmp and a selection of rootkits as well.
fortunately, the box was not rooted, but apache user rights for strangers is annoying enough.
it appears that the attackers google for vulnerable hosts.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds