CVE-2010-4368: Code Injection
Published Dec 2, 2010
·Updated
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.
Affected Software
35 affected components
Awstats AWStats<=6.95
Awstats AWStats=1.0
Awstats AWStats=2.1.
Awstats AWStats=2.2.3
Awstats AWStats=2.2.4
Awstats AWStats=3.0
Awstats AWStats=3.1
Awstats AWStats=3.2
Awstats AWStats=4.0
Awstats AWStats=4.1
Awstats AWStats=5.0
Awstats AWStats=5.1
Awstats AWStats=5.2
Awstats AWStats=5.3
Awstats AWStats=5.4
Awstats AWStats=5.5
Awstats AWStats=5.6
Awstats AWStats=5.7
Awstats AWStats=5.8
Awstats AWStats=5.9
Awstats AWStats=6.0
Awstats AWStats=6.1
Awstats AWStats=6.2
Awstats AWStats=6.3
Awstats AWStats=6.4
Awstats AWStats=6.4_1
Awstats AWStats=6.4_1-sarge1
Awstats AWStats=6.5
Awstats AWStats=6.5_1
Awstats AWStats=6.5_1.857
Awstats AWStats=6.6
Awstats AWStats=6.7
Awstats AWStats=6.8
Awstats AWStats=6.9
Microsoft Windows
Event History
Dec 2, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
04:22 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-4368?
CVE-2010-4368 is considered a critical vulnerability as it allows remote attackers to execute arbitrary commands on affected systems.
2
How do I fix CVE-2010-4368?
To fix CVE-2010-4368, upgrade to AWStats version 7.0 or later, which addresses this vulnerability.
3
Which versions of AWStats are affected by CVE-2010-4368?
CVE-2010-4368 affects all AWStats versions prior to 7.0, including versions 1.0 to 6.9.
4
What type of attack is possible with CVE-2010-4368?
CVE-2010-4368 allows remote attackers to execute arbitrary commands via crafted configuration files located at a UNC share pathname.
5
Is CVE-2010-4368 specific to any operating system?
CVE-2010-4368 affects AWStats running on Windows systems.