CVE-2008-3922 Information
Feb 14, 2021
cve
Description
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter which is used by the multisort function when dynamically creating an anonymous PHP function.
Reference
http://secunia.com/advisories/31630 http://securityreason.com/securityalert/4218 http://securityreason.com/securityalert/8259 http://userwww.service.emory.edu/~ekenda2/EMORY-2008-01.txt http://www.exploit-db.com/exploits/17324 http://www.securityfocus.com/archive/1/495770/100/0/threaded http://www.securityfocus.com/bid/30856 http://www.telartis.nl/xcms/awstats/ http://www.vupen.com/english/advisories/2008/2442 https://exchange.xforce.ibmcloud.com/vulnerabilities/44712 https://www.exploit-db.com/exploits/6368
Share on: