AWStats Referrer Arbitrary Command Execution Vulnerability
BID:14525
Info
AWStats Referrer Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 14525 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1527 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2005 12:00AM |
| Updated: | Dec 20 2006 09:17PM |
| Credit: | Peter Vreugdenhil <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 AWStats AWStats 6.3 AWStats AWStats 6.2 AWStats AWStats 6.1 AWStats AWStats 6.0 AWStats AWStats 5.9 AWStats AWStats 5.8 AWStats AWStats 5.7 AWStats AWStats 5.6 AWStats AWStats 5.5 AWStats AWStats 5.4 AWStats AWStats 5.3 AWStats AWStats 5.2 AWStats AWStats 5.1 AWStats AWStats 5.0 |
| Not Vulnerable: |
AWStats AWStats 6.5.0 build 1.857 |
Discussion
AWStats Referrer Arbitrary Command Execution Vulnerability
AWStats is affected by an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this vulnerability will permit an attacker to execute arbitrary Perl code on the system hosting the affected application in the security context of the webserver process. This may aid in further attacks against the underlying system; other attacks are also possible.
Note that this vulnerability is possible only if the affected application has at least one URLPlugin enabled.
AWStats is affected by an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this vulnerability will permit an attacker to execute arbitrary Perl code on the system hosting the affected application in the security context of the webserver process. This may aid in further attacks against the underlying system; other attacks are also possible.
Note that this vulnerability is possible only if the affected application has at least one URLPlugin enabled.
Exploit / POC
AWStats Referrer Arbitrary Command Execution Vulnerability
No exploit is required.
A proof of concept is available:
http://www.securityfocus.com/data/vulnerabilities/exploits/awstats_poc.pl
No exploit is required.
A proof of concept is available:
http://www.securityfocus.com/data/vulnerabilities/exploits/awstats_poc.pl
Solution / Fix
AWStats Referrer Arbitrary Command Execution Vulnerability
Solution:
Please see the referenced vendor advisories for more information.
NOTE: The vendor has addressed this issue in AWStats version 6.4.
AWStats AWStats 5.0
AWStats AWStats 5.1
AWStats AWStats 5.2
AWStats AWStats 5.3
AWStats AWStats 5.4
AWStats AWStats 5.5
AWStats AWStats 5.6
AWStats AWStats 5.7
AWStats AWStats 5.8
AWStats AWStats 5.9
AWStats AWStats 6.0
AWStats AWStats 6.1
AWStats AWStats 6.2
AWStats AWStats 6.3
Solution:
Please see the referenced vendor advisories for more information.
NOTE: The vendor has addressed this issue in AWStats version 6.4.
AWStats AWStats 5.0
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.1
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.2
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.3
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.4
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.5
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.6
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.7
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.8
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 5.9
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 6.0
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 6.1
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 6.2
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
AWStats AWStats 6.3
-
AWStats awstats-6.4.tgz
http://awstats.sourceforge.net/files/awstats-6.4.tgz
References
AWStats Referrer Arbitrary Command Execution Vulnerability
References:
References:
- AWStats Change Log (AWStats)
- AWStats Homepage (AWStats)
- iDEFENSE Security Advisory 08.09.05: AWStats ShowInfoURL Remote Command Executio ("iDEFENSE Labs"
)