RULE(RULE ID:322687)

Rule General Information
Release Date: 2019-07-08
Rule Name: AWStats awstats.pl configdir Parameter Command Execution Vulnerability (CVE-2005-0116)
Severity:
CVE ID:
Rule Protection Details
Description: AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:12298
http://awstats.sourceforge.net/docs/awstats_changelog.txt
http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf
http://www.idefense.com/application/poi/display?id=185&type=vulnerabilities&flashstatus=false
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://awstats.sourceforge.net/#DOWNLOAD