See how astats compares to other vendors in security performance
aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.
SQL injection vulnerability in includes/countdlorlink.inc.php in the astatsPRO (comastatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
SQL injection vulnerability in refer.php in the astatsPRO (comastatspro) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.