Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Nov 2004
    Location
    Earth
    Posts
    151

    Exclamation AWStats Remote Command Execution Vulnerability (configdir)

    Analysis:
    Successful exploitation allows remote attackers to execute arbitrary commands under the privileges of the web server. This can lead to further compromise as it provides remote attackers with local
    access.
    AwStats Vuln

    Is this a global config or will it need to be changed for each domain?

  2. #2
    Member
    Join Date
    Aug 2003
    Location
    United Kingdom
    Posts
    186

    Default

    cPanel has AWstats 6.2 installed, which is the current stable version. The author has only released 6.3 as a development release.

    It should be possible to centrally upgrade awstats.


    http://secunia.com/advisories/13893/

    Solution:
    Update to version 6.3.
    http://awstats.sourceforge.net/#DOWNLOAD

  3. #3
    Member
    Join Date
    Aug 2003
    Location
    United Kingdom
    Posts
    186

    Default

    You could follow this link, and adjust for 6.3:

    http://forums.cpanel.net/showthread....pgrade+awstats

  4. #4
    Member
    Join Date
    Nov 2004
    Location
    Earth
    Posts
    151

    Default

    Thanks for the link man!

Similar Threads & Tags
Similar threads

  1. how does awstats execution get scheduled?
    By eclay in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 07-14-2010, 07:55 AM
  2. cron execution command
    By kartheek999 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-14-2007, 04:53 AM
  3. Clam AntiVirus DoS Vulnerability & Remote code execution
    By dropby23 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 11-07-2005, 09:29 AM
  4. AWStats 6.x Multiple Remote Command Execution (Shell) Exploit
    By SupaDucta in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 03-03-2005, 05:58 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube