Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20260308100650.06c98705@hboeck.de>
Date: Sun, 8 Mar 2026 10:06:50 +0100
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com
Subject: Re: AWStats awdownloadcsv.pl command injection and
 path traversal vulnerabilities

On Sun, 08 Mar 2026 08:26:23 +0000
"christopher.downs" <christopher.downs@...ersecurity.com> wrote:

> Repository:
> https://github.com/eldy/AWStats/tree/develop

From the repo:

"Deprecation notice (November 2025)
AWStats has been maintained for 25 years with enormous appreciation for
everyone who used and contributed to it. The AWStats project is now
deprecated and no longer actively developed. For modern,
privacy-respecting, supported log analytics we strongly recommend
migrating to Matomo Log Analytics."

So possibly we will not see a fixed version.

-- 
Hanno Böck - Independent security researcher
https://itsec.hboeck.de/
https://badkeys.info/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.