Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Awstats 配置文件 远程任意命令执行漏洞
Vulnerability Description
AWStats 6.5及可能的其他版本可以使远程认证用户使用对awstats.pl的 configdir参数上传名称包含shell元字符的配置文件,然后再使用LogFile 指令访问该文件,从而执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A