AStarWithin Posted February 12, 2005 Posted February 12, 2005 Hi, I noticed that TCH was using Awstats version 6.2, I just wanted to make aware the following statement on their website: Warning, a security hole was recently found in AWStats versions from 5.0 to 6.2 when AWStats is used as a CGI: A remote user can execute arbitrary commands on your server using permissions of your web server user (in most cases user "nobody").If you use AWStats with another version or is not available as a CGI, you are safe. If not, it is highly recommanded to upgrade to 6.4 version that fix this security hole and another less important one. edit: oops, didn't notice it was already posted..... sorry! Quote
TCH-Bruce Posted February 12, 2005 Posted February 12, 2005 Yes, it was posted and patches have been appied. http://www.totalchoicehosting.com/forums/i...showtopic=16651 Thank you for your concern. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.