CVE-2006-2644
EPSS 1.0%
Description
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
How to fix CVE-2006-2644
To remediate CVE-2006-2644, upgrade the affected package to a fixed version below.
- Debian/awstats—upgrade to 6.5-2 or later
Is CVE-2006-2644 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 6.5-2