AWStats.Configdir.Command.Execution

description-logoDescription

This indicates an attack attempt against a Remote Code Execution vulnerability in AWStats.
This is due tp how the filters for user inputs fail to properly sanitize the Configdir parameter value that is passed to "awstats.pl". An attacker may include shell commands by supplying an injection string through the URL.

affected-products-logoAffected Products

AWStats version 5.0 to 6.2

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems

recomended-action-logoRecommended Actions

Upgrade to AWStat 6.3 or later.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)