Unrated severityNVD Advisory· Published May 30, 2006· Updated Apr 16, 2026
CVE-2006-2644
CVE-2006-2644
Description
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/20283nvdPatchVendor Advisory
- www.debian.org/security/2006/dsa-1075nvdPatch
- www.osreviews.net/reviews/comm/awstatsnvdPatch
- secunia.com/advisories/20164nvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- secunia.com/advisories/20502nvd
- secunia.com/advisories/20710nvd
- www.novell.com/linux/security/advisories/2006_33_awstats.htmlnvd
- www.securityfocus.com/bid/18327nvd
- www.vupen.com/english/advisories/2006/1998nvd
- usn.ubuntu.com/290-1/nvd
News mentions
0No linked articles in our index yet.