Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> AWStats rawlog plugin logfile parameter input validation vulnerability


Vulnerability Assessment Details

AWStats rawlog plugin logfile parameter input validation vulnerability

Vulnerability Assessment Summary
Acertains the presence of AWStats awstats.pl

Detailed Explanation for this Vulnerability Assessment

The remote host seems to be running AWStats, a free real-time logfile analyzer.

AWStats Rawlog Plugin is reported prone to an input validation vulnerability.
The issue is reported to exist because user supplied 'logfile' URI data passed
to the 'awstats.pl' script is not sanitized.

A possible hacker may exploit this condition to execute commands remotely or disclose
contents of web server readable files.

Solution : Upgrade to the latest version of this software
Network Security Threat Level: High

Networks Security ID: 10950

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 David Maciejak

Cables, Connectors


8 Ports Unmanaged Industrial Ethernet Switch Network Gigabit Ethernet Switch picture

8 Ports Unmanaged Industrial Ethernet Switch Network Gigabit Ethernet Switch

$76.50



Cisco SG110 8 Port Gigabit Ethernet Switch SG110D-08-UK picture

Cisco SG110 8 Port Gigabit Ethernet Switch SG110D-08-UK

$39.00



InHand Networks 5/8 Port Industrial Unmanaged Fast Ethernet/Giga DIN-Rail Switch picture

InHand Networks 5/8 Port Industrial Unmanaged Fast Ethernet/Giga DIN-Rail Switch

$76.50



Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24 picture

Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24

$117.00



HP 2530-48G 48 Port Gigabit Ethernet Network Switch J9775A picture

HP 2530-48G 48 Port Gigabit Ethernet Network Switch J9775A

$30.95



New Linksys SE3005 5-port Gigabit Ethernet Switch picture

New Linksys SE3005 5-port Gigabit Ethernet Switch

$18.99



New 10/100 Mbps 8 Ports Fast Ethernet LAN Desktop RJ45 Network Switch Hub picture

New 10/100 Mbps 8 Ports Fast Ethernet LAN Desktop RJ45 Network Switch Hub

$11.49



Linksys SE3008 8 Ports Rack Mountable Gigabit Ethernet Switch picture

Linksys SE3008 8 Ports Rack Mountable Gigabit Ethernet Switch

$21.99



HP ProCurve 2530-24G J9776A 24 Port Gigabit Ethernet Managed Network Switch picture

HP ProCurve 2530-24G J9776A 24 Port Gigabit Ethernet Managed Network Switch

$34.99



Juniper Networks EX3300-48P 48-Port PoE+ 4x SFP+ Network Switch w/ Power Cord picture

Juniper Networks EX3300-48P 48-Port PoE+ 4x SFP+ Network Switch w/ Power Cord

$43.95



Discussions

No Discussions have been posted on this vulnerability.