Loading
Generated remediation guidance and an executive summary. No account required.
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.
Use CWE-94, Telartis Bv vendor hub and Awstats Totals product page to widen CVE-2008-3922 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2008-3921 for nearby disclosures in the same product family.