awstats: arbitrary code injection
Package(s): | awstats | CVE #(s): | CVE-2010-4369 | ||||||||
Created: | January 24, 2011 | Updated: | February 21, 2011 | ||||||||
Description: | From the Ubuntu advisory:
It was discovered that AWStats did not correctly filter the LoadPlugin configuration option. A local attacker on a shared system could use this to inject arbitrary code into AWStats. | ||||||||||
Alerts: |
|