CVE Vulnerabilities

CVE-2006-2237

Published: May 08, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.

Affected Software

Name Vendor Start Version End Version
Awstats Awstats 6.4 (including) 6.4 (including)
Awstats Awstats 6.5 (including) 6.5 (including)
Awstats Ubuntu dapper *
Awstats Ubuntu devel *
Awstats Ubuntu edgy *
Awstats Ubuntu feisty *

References