CVE-2006-2644
published 2006-05-30CVE-2006-2644: AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload…
PriorityP424medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
2.71%
84.3th percentile
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | — | — |
| awstats | awstats | >= 0 < 6.5-2 | 6.5-2 |
| awstats | awstats | >= 0 < 6.5-2 | 6.5-2 |
| awstats | awstats | >= 0 < 6.5-2 | 6.5-2 |
| awstats | awstats | >= 0 < 6.5-2 | 6.5-2 |
| debian | awstats | < awstats 6.5-2 (bookworm) | awstats 6.5-2 (bookworm) |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
awstats vulnerability
vendor_ubuntu·2006-06-08
CVE-2006-2644 awstats vulnerability
Title: awstats vulnerability
Summary: awstats vulnerability
Hendrik Weimer discovered a privilege escalation vulnerability in
awstats. By supplying the 'configdir' CGI parameter and setting it to
an attacker-controlled directory (such as an FTP account, /tmp, or
similar), an attacker could execute arbitrary shell commands with the
privileges of the web server (user 'www-data').
This update disables the 'configdir' parameter by default. If all
local user accounts can be trusted, it can be reenabled by running
awstats with the AWSTATS_ENABLE_CONFIG_DIR environment variable set to
a nonempty value.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-2644: awstats - AWStats 6.5, and possibly other versions, allows remote authenticated users to e...
vendor_debian·2006·CVSS 4.0
CVE-2006-2644 [MEDIUM] CVE-2006-2644: awstats - AWStats 6.5, and possibly other versions, allows remote authenticated users to e...
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
Scope: local
bookworm: resolved (fixed in 6.5-2)
bullseye: resolved (fixed in 6.5-2)
forky: resolved (fixed in 6.5-2)
sid: resolved (fixed in 6.5-2)
trixie: resolved (fixed in 6.5-2)
GHSA
GHSA-cpq2-7cfm-gfc2: AWStats 6
ghsa_unreviewed·2022-05-01
CVE-2006-2644 [MEDIUM] GHSA-cpq2-7cfm-gfc2: AWStats 6
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
OSV
CVE-2006-2644: AWStats 6
osv·2006-05-30·CVSS 4.0
CVE-2006-2644 [MEDIUM] CVE-2006-2644: AWStats 6
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365910http://secunia.com/advisories/20164http://secunia.com/advisories/20283http://secunia.com/advisories/20502http://secunia.com/advisories/20710http://www.debian.org/security/2006/dsa-1075http://www.novell.com/linux/security/advisories/2006_33_awstats.htmlhttp://www.osreviews.net/reviews/comm/awstatshttp://www.securityfocus.com/bid/18327http://www.vupen.com/english/advisories/2006/1998https://usn.ubuntu.com/290-1/http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365910http://secunia.com/advisories/20164http://secunia.com/advisories/20283http://secunia.com/advisories/20502http://secunia.com/advisories/20710http://www.debian.org/security/2006/dsa-1075http://www.novell.com/linux/security/advisories/2006_33_awstats.htmlhttp://www.osreviews.net/reviews/comm/awstatshttp://www.securityfocus.com/bid/18327http://www.vupen.com/english/advisories/2006/1998https://usn.ubuntu.com/290-1/
2006-05-30
Published