Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-3922
Description:awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.
Test IDs: 1.3.6.1.4.1.25623.1.0.801893  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-3922
BugTraq ID: 30856
http://www.securityfocus.com/bid/30856
Bugtraq: 20080826 Multiple Vulnerabilities in AWStats Totals (Google Search)
http://www.securityfocus.com/archive/1/495770/100/0/threaded
http://www.exploit-db.com/exploits/17324
https://www.exploit-db.com/exploits/6368
http://userwww.service.emory.edu/~ekenda2/EMORY-2008-01.txt
http://secunia.com/advisories/31630
http://securityreason.com/securityalert/4218
http://securityreason.com/securityalert/8259
http://www.vupen.com/english/advisories/2008/2442
XForce ISS Database: awstatstotals-multisort-command-execution(44712)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44712




© 1998-2025 E-Soft Inc. All rights reserved.