CVE-2010-4368Code Injection in Awstats

CWE-94Code Injection4 documents4 sources
Severity
7.5HIGHNVD
EPSS
1.4%
top 19.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 2
Latest updateMay 17

Description

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDawstats/awstats6.95+32

🔴Vulnerability Details

2
GHSA
GHSA-xp5j-75x6-qx28: awstats2022-05-17
CVEList
CVE-2010-4368: awstats2010-12-02

📋Vendor Advisories

1
Debian
CVE-2010-4368: awstats - awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in th...2010