[Snort-sigs] Rule Submit: AWstats Migrate Remote File Include

Blake Hartstein bhartstein at ...274...
Fri May 5 15:49:02 EDT 2006

This vulnerability only exists when AllowToUpdateStatsFromBrowser is 
enabled, which is off by default.
The migrate parameter is passed to an open command without proper 
sanitization, which would allow a remote attacker to issue commands 
using a PIPE character '|'.

(msg:"BLEEDING-EDGE WEB CGI AWstats Migrate Command Attempt"; 
flow:established,to_server; uricontent:"/awstats.pl?"; nocase; 
pcre:"/migrate\s*=\s*\|/Ui"; reference:bugtraq,17844; 
classtype:web-application-attack; sid:59595959; rev:1; )


