Описание
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.
Ссылки
- Exploit
- US Government Resource
- Exploit
- US Government Resource
Уязвимые конфигурации
Одновременно
Одно из
EPSS
7.5 High
CVSS2
Дефекты
Связанные уязвимости
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir param ...
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.
EPSS
7.5 High
CVSS2