CVE-2010-4367
EPSS 7.3%
Description
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server.
How to fix CVE-2010-4367
To remediate CVE-2010-4367, upgrade the affected package to a fixed version below.
- Debian/awstats—upgrade to 6.9.5~dfsg-5 or later
Is CVE-2010-4367 being exploited?
Moderate — EPSS is 7.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 6.9.5~dfsg-5