CVE-2010-4367: Code Injection
Published Dec 2, 2010
·Updated
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server.
Affected Software
34 affected components
Awstats AWStats<=6.95
Awstats AWStats=1.0
Awstats AWStats=2.1.
Awstats AWStats=2.2.3
Awstats AWStats=2.2.4
Awstats AWStats=3.0
Awstats AWStats=3.1
Awstats AWStats=3.2
Awstats AWStats=4.0
Awstats AWStats=4.1
Awstats AWStats=5.0
Awstats AWStats=5.1
Awstats AWStats=5.2
Awstats AWStats=5.3
Awstats AWStats=5.4
Awstats AWStats=5.5
Awstats AWStats=5.6
Awstats AWStats=5.7
Awstats AWStats=5.8
Awstats AWStats=5.9
Awstats AWStats=6.0
Awstats AWStats=6.1
Awstats AWStats=6.2
Awstats AWStats=6.3
Awstats AWStats=6.4
Awstats AWStats=6.4_1
Awstats AWStats=6.4_1-sarge1
Awstats AWStats=6.5
Awstats AWStats=6.5_1
Awstats AWStats=6.5_1.857
Awstats AWStats=6.6
Awstats AWStats=6.7
Awstats AWStats=6.8
Awstats AWStats=6.9
Event History
Dec 2, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4367?
CVE-2010-4367 is rated as critical due to its potential for remote command execution.
2
How do I fix CVE-2010-4367?
To fix CVE-2010-4367, upgrade AWStats to version 7.0 or later, which addresses this vulnerability.
3
Which versions of AWStats are affected by CVE-2010-4367?
AWStats versions prior to 7.0, including all versions from 1.0 to 6.9, are affected by CVE-2010-4367.
4
What are the implications of CVE-2010-4367 for my web server?
CVE-2010-4367 allows attackers to execute arbitrary commands on your server, potentially compromising the entire system.
5
Is there a workaround for CVE-2010-4367 if I can't upgrade?
If you cannot upgrade, restrict access to the awstats.cgi script and implement firewall rules to limit incoming traffic.