[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAGEu6OA6DasUnpGT7zpZ+Da5g75J6bonu2BBHyzNLJ-wFFTooQ@mail.gmail.com>
Date: Mon, 12 Dec 2011 19:30:26 -0500
From: Lamar Spells <lamar.spells@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: New awstats.pl vulnerability?
For the past several days, I have been seeing thousands of requests
looking for awstats.pl like this one:
GET /awstats/awstats.pl ? configdir=|echo;echo YYYAAZ;uname;id;echo YYY;echo|
I am dropping these requests due to previous (and very old) issues
with awstats (see CVE-2006-3682).
But this leaves me wondering if there is a new vuln lurking here somewhere.
Anyone else seeing the same thing?
Regards,
Lamar Spells
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists