← Back

CVE-2010-4368

nvd nist
Published: Dec 2, 2010Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.

Affected (34)

Products: Awstats: Awstats
1 product
Awstats
Configuration A
34 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Awstats
Up to 6.95
Version 1.0
Version 2.1.
Version 2.2.3
Version 2.2.4
Version 3.0
Version 3.1
Version 3.2
Version 4.0
Version 4.1
Version 5.0
Version 5.1
Version 5.2
Version 5.3
Version 5.4
Version 5.5
Version 5.6
Version 5.7
Version 5.8
Version 5.9
Version 6.0
Version 6.1
Version 6.2
Version 6.3
Version 6.4
Version 6.4_1
Version 6.4_1 sarge1
Version 6.5
Version 6.5_1.857
Version 6.5_1
Version 6.6
Version 6.7
Version 6.8
Version 6.9
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (6)

Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource

Timeline

No history available yet.