1
0
mirror of https://git.FreeBSD.org/ports.git synced 2025-01-16 07:58:04 +00:00

Document vulnerabilities in awstats. Note that this entry will most

likely be updated soon when more information becomes available.
This commit is contained in:
Simon L. B. Nielsen 2005-02-16 23:25:23 +00:00
parent 36f8f623e4
commit 3aa53137ae
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=129051

View File

@ -32,6 +32,41 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
<vuln vid="fdad8a87-7f94-11d9-a9e7-0001020eed82">
<topic>awstats -- multiple vulnerabilities</topic>
<affects>
<package>
<name>awstats</name>
<range><lt>6.4</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>A GHC advisory reports:</p>
<blockquote cite="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110840530924124">
<p>Successful exploitation of an input validation
vulnerability in AWStats scripts allows attackers to
execute limited perl directives under the privileges of
the web server, get sensetive information. Some actions
of the attacker can lead to denial of service.</p>
</blockquote>
<p>Some reports indicate that these vulnerabilities can be
used to execute arbitrary commands with the privileges of
the web server awstats is running under.</p>
</body>
</description>
<references>
<bid>12543</bid>
<bid>12545</bid>
<mlist msgid="20050214081040.3370.qmail@www.securityfocus.com">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110840530924124</mlist>
<url>http://awstats.sourceforge.net/docs/awstats_changelog.txt</url>
</references>
<dates>
<discovery>2005-02-10</discovery>
<entry>2005-02-15</entry>
</dates>
</vuln>
<vuln vid="5a5422fd-7e1a-11d9-a9e7-0001020eed82">
<topic>powerdns -- DoS vulnerability</topic>
<affects>