CVE-2010-4368
Publication date 2 December 2010
Last updated 24 July 2024
Ubuntu priority
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.