CVE-2008-3922 Information

Description

awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter which is used by the multisort function when dynamically creating an anonymous PHP function.

Reference

http://secunia.com/advisories/31630 http://securityreason.com/securityalert/4218 http://securityreason.com/securityalert/8259 http://userwww.service.emory.edu/~ekenda2/EMORY-2008-01.txt http://www.exploit-db.com/exploits/17324 http://www.securityfocus.com/archive/1/495770/100/0/threaded http://www.securityfocus.com/bid/30856 http://www.telartis.nl/xcms/awstats/ http://www.vupen.com/english/advisories/2008/2442 https://exchange.xforce.ibmcloud.com/vulnerabilities/44712 https://www.exploit-db.com/exploits/6368

Share on: