Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200606-06
https://security.gentoo.org/
Severity: High
Title: AWStats: Remote execution of arbitrary code
Date: June 07, 2006
Bugs: #130487
ID: 200606-06
Synopsis
=======
AWStats contains a bug in the sanitization of the input parameterswhich can lead to the remote execution of arbitrary code.
Background
=========
AWStats is an advanced log file analyzer and statistics generator.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-www/awstats < 6.5-r1 >= 6.5-r1
==========
Hendrik Weimer has found that if updating the statistics via the web
frontend is enabled, it is possible to inject arbitrary code via a pipe
character...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.