The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.
| Software | From | Fixed in |
|---|---|---|
| awstats / awstats | 6.5 | 6.5.x |
| awstats / awstats | 6.4 | 6.4.x |