ID | CVE-2006-2644 | ||||||
Sažetak | AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive. | ||||||
Reference |
|
||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:L/Au:S/C:N/I:P/A:N | ||||||
Zadnje važnije ažuriranje | 03-10-2018 - 21:41 | ||||||
Objavljeno | 30-05-2006 - 10:02 |