CVE-2006-2644
Publication date 30 May 2006
Last updated 24 July 2024
Ubuntu priority
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.