PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attackers to fill the log files via a large number of requests, as demonstrated using pixel.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Statistik | Php_web | 1.4 (including) | 1.4 (including) |