Security Advisory

CVE-2008-3922

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-09-04 18:00:00
Last updated 2024-08-07 10:00:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.