CAN-2005-1527
Monday, August 22nd, 2005There is a major vulnerability in the awstats log analyzer, versions 6.4 and lower. Basically, awstats passes a string from the log file straight to Perl’s eval() (which is truly an awful idea, from both security and performance standpoint). Naturally this leads to pwnage if you can get Apache to log a particularly misformed request.
And […]