Vulnerability CVE-2008-3922


Published: 2008-09-04   Modified: 2012-02-13

Description:
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.

See advisories in our WLB2 database:
Topic
Author
Date
High
Multiple Vulnerabilities in AWStats Totals
Elliot Kendall
06.09.2008
High
AWStats Totals =< v1.14 multisort Remote Command Execution
metasploit
27.05.2011

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Telartis bv -> Awstats totals 

 References:
http://securityreason.com/securityalert/4218
http://securityreason.com/securityalert/8259
http://userwww.service.emory.edu/~ekenda2/EMORY-2008-01.txt
http://www.exploit-db.com/exploits/17324
http://www.securityfocus.com/archive/1/495770/100/0/threaded
http://www.securityfocus.com/bid/30856
http://www.telartis.nl/xcms/awstats/
http://www.vupen.com/english/advisories/2008/2442
https://exchange.xforce.ibmcloud.com/vulnerabilities/44712
https://www.exploit-db.com/exploits/6368

Copyright 2022, cxsecurity.com

 

Back to Top