|
|
| |
|
| |
awstats: arbitrary code injection
| Package(s): | awstats |
CVE #(s): | CVE-2010-4369
|
| Created: | January 24, 2011 |
Updated: | February 21, 2011 |
| Description: |
From the Ubuntu advisory:
It was discovered that AWStats did not correctly filter the LoadPlugin
configuration option. A local attacker on a shared system could use this
to inject arbitrary code into AWStats.
|
| Alerts: |
|
( Log in to post comments)
|
|
|