awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.
Link | Tags |
---|---|
http://secunia.com/advisories/14299 | patch vendor advisory third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19333 | vdb entry |
http://www.securityfocus.com/archive/1/390368 | vendor advisory mailing list exploit |