AWStats 'awstats.pl' Multiple Path Disclosure Vulnerability
BID:34159
Info
AWStats 'awstats.pl' Multiple Path Disclosure Vulnerability
| Bugtraq ID: | 34159 |
| Class: | Design Error |
| CVE: |
CVE-2006-3682 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2006 12:00AM |
| Updated: | Mar 18 2009 05:56PM |
| Credit: | r0t is credited with the discovery of this vulnerability. |
| Vulnerable: |
WebGUI WebGUI Runtime Environment 0.8.5 Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 AWStats AWStats 6.4 AWStats AWStats 6.3 AWStats AWStats 6.2 AWStats AWStats 6.1 AWStats AWStats 6.0 AWStats AWStats 5.9 AWStats AWStats 5.8 AWStats AWStats 5.7 AWStats AWStats 5.6 AWStats AWStats 5.5 AWStats AWStats 5.4 AWStats AWStats 5.3 AWStats AWStats 5.2 AWStats AWStats 5.1 AWStats AWStats 5.0 AWStats AWStats 4.0 AWStats AWStats 6.5.0 build 1.857 |
| Not Vulnerable: |
WebGUI WebGUI Runtime Environment 0.9 |
Discussion
AWStats 'awstats.pl' Multiple Path Disclosure Vulnerability
AWStats is prone to a path-disclosure vulnerability.
Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks against a vulnerable computer.
The following are vulnerable:
AWStats 6.5 (build 1.857) and prior
WebGUI Runtime Environment 0.8.x and prior
AWStats is prone to a path-disclosure vulnerability.
Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks against a vulnerable computer.
The following are vulnerable:
AWStats 6.5 (build 1.857) and prior
WebGUI Runtime Environment 0.8.x and prior
Exploit / POC
AWStats 'awstats.pl' Multiple Path Disclosure Vulnerability
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/awstats/awstats.pl?config=HACKdestailleur.fr
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/awstats/awstats.pl?config=HACKdestailleur.fr
Solution / Fix
AWStats 'awstats.pl' Multiple Path Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
AWStats AWStats 6.3
AWStats AWStats 6.4
Solution:
Updates are available. Please see the references for more information.
AWStats AWStats 6.3
-
Ubuntu awstats_6.3-1ubuntu0.4_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3-1ubu ntu0.4_all.deb
AWStats AWStats 6.4
-
Ubuntu awstats_6.4-1ubuntu1.3_all.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4-1ubu ntu1.3_all.deb
References
AWStats 'awstats.pl' Multiple Path Disclosure Vulnerability
References:
References:
- AWStats Homepage (AWStats)
- Security issue - Awstats.pl reveals server info on error (#8964) (WebGUI)