← All CVEs

CVE-2008-3922

high · 9.3

awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.

9.3
CVSS
53.2%
EPSS (exploit prob.)
99th
EPSS percentile
2008-09-04
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
telartis_bvawstats_totals1.0
telartis_bvawstats_totals1.1
telartis_bvawstats_totals1.11
telartis_bvawstats_totals1.13
telartis_bvawstats_totals1.14

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-3922