awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters.
Link | Tags |
---|---|
http://pridels0.blogspot.com/2006/04/awstats-65x-multiple-vuln.html | |
http://www.ubuntu.com/usn/usn-360-1 | vendor advisory |
http://www.vupen.com/english/advisories/2006/1421 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25880 | vdb entry |
http://secunia.com/advisories/22306 | third party advisory |
http://secunia.com/advisories/19725 | exploit third party advisory vendor advisory |