Quote: |
This vuln only affects awstats run in CGI mode and which have AllowToUpdateStatsFromBrowser enabled. If you load awstats and there is a button allowing you to update your stats right then and there, you may be vulnerable. Setting this (in awstats.conf) to '0' instead of '1' is the quickest fix. 2nd quickest fix is a small modification to the awstats.pl code, then you can activate browser updating again. 3rd solution is full upgrade (recommended). No need to switch stats programs, this is a pretty minor fix...
http://awstats.sourceforge.net/
|