See how astats compares to other vendors in security performance
SQL injection vulnerability in includes/countdlorlink.inc.php in the astatsPRO (comastatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
SQL injection vulnerability in refer.php in the astatsPRO (comastatspro) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.
aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.