Arbitrary Command Execution in AWStats 6.1 and Earlier Versions

Arbitrary Command Execution in AWStats 6.1 and Earlier Versions

CVE-2005-0116 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.

Learn more about our Web Application Penetration Testing UK.