eldy / AWStats

AWStats Log Analyzer project (official sources)
https://www.awstats.org
361 stars 119 forks source link

CVE-2017-1000501 Explanation #223

Open Touexe opened 1 year ago

Touexe commented 1 year ago

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.

Can anyone explain these flaw on config and migrate? Is there any particular exploit showing how are these very critical issues, rce but how so?