|No such thing as a small change|
Awstats Perl securityby hakkr (Chaplain)
|on Nov 09, 2005 at 17:07 UTC||Need Help??|
I use awstats which is a very good webstats app written in Perl. I just had this url thrown at a web server.
luckily said directory is password protected and i have the latest patched version.
Probably old news but just a warning to take some action if you have an old version of this installed. recent installs should be ok.
There was a CERT warning in february I think. Would hate to see tainted perl compromise any servers and didt find it in supersearch so there you go.cheerio
Edit g0n - added code tags
Edit g0n - moved from SoPW to Newsupdate CERT link