CVE-2010-4367
EPSS 7.3%Published: 12/2/2010Modified: 4/28/2026
Description
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server.
Affected packages (1)
- Debian/awstatsfrom 0, < 6.9.5~dfsg-5