|
|
Subscribe / Log in / New account

awstats: arbitrary code injection

Package(s):awstats CVE #(s):CVE-2010-4369
Created:January 24, 2011 Updated:February 21, 2011
Description: From the Ubuntu advisory:

It was discovered that AWStats did not correctly filter the LoadPlugin configuration option. A local attacker on a shared system could use this to inject arbitrary code into AWStats.

Alerts:
Mandriva MDVSA-2011:033 awstats 2011-02-21
Ubuntu USN-1047-1 awstats 2011-01-24

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds