Описание
AWStats 8.0 is vulnerable to Command Injection via the open function
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| awstats | fixed | 8.0-5 | package | |
| awstats | fixed | 7.9-1+deb13u1 | trixie | package |
| awstats | fixed | 7.8-3+deb12u2 | bookworm | package |
Примечания
https://pentest-tools.com/PTT-2025-021-Code-Execution-in-AWStats.pdf
https://github.com/eldy/AWStats/issues/287
Crosses no reasonable security boundary, requires an attacker to modify awstats.conf
Связанные уязвимости
CVSS3: 7.8
ubuntu
6 месяцев назад
AWStats 8.0 is vulnerable to Command Injection via the open function
CVSS3: 7.8
nvd
6 месяцев назад
AWStats 8.0 is vulnerable to Command Injection via the open function
CVSS3: 7.8
github
6 месяцев назад
AWStats 8.0 is vulnerable to Command Injection via the open function