Vulnerability record · CVE-2008-3922 · published 4 September 2008
CVE-2008-3922: AWStats Totals sort parameter PHP code injection
TTelartis Bv · Awstats Totals
AWStats Totals 1.0 through 1.14 passes the sort parameter into the multisort function, which dynamically builds an anonymous PHP function from that input. Because the parameter is not sanitized, injected PHP sequences are evaluated, allowing remote code execution on the web server. The flaw is a classic code injection (CWE-94) in a web-facing statistics script.
Description
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with complete impact and high EPSS, though exploitation requires some attack complexity and the product is old.
What it is
AWStats Totals 1.0 through 1.14 passes the sort parameter into the multisort function, which dynamically builds an anonymous PHP function from that input. Because the parameter is not sanitized, injected PHP sequences are evaluated, allowing remote code execution on the web server. The flaw is a classic code injection (CWE-94) in a web-facing statistics script.
Impact
An unauthenticated remote attacker can execute arbitrary PHP code with the privileges of the web server process, leading to full compromise of the host and any data it can reach. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached over the network through HTTP requests to awstatstotals.php, with the malicious payload carried in the sort parameter. No authentication or user interaction is required per the CVSS vector (AV:N/AC:M/Au:N), though the record does not describe any access control on the script.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but public exploit code exists in Exploit-DB (6368 and 17324) and EPSS is high at 0.532 (98.9th percentile), indicating meaningful real-world exploitation likelihood.
What to do
- Apply the vendor patch referenced at telartis.nl/xcms/awstats/ or upgrade AWStats Totals past 1.14.
- If the product is no longer maintained, remove or disable awstatstotals.php, or restrict it to trusted networks.
- Sanitize and whitelist the sort parameter so only expected column names reach multisort, and avoid dynamic function creation from request input.
- Run the web service under a least-privilege account and apply PHP open_basedir/disable_functions hardening to limit post-exploitation reach.
Detection
- Inspect web logs for requests to awstatstotals.php with PHP function or code syntax in the sort parameter.
- Alert on PHP errors or unusual eval/function-creation warnings tied to awstatstotals.php.
- Monitor for unexpected outbound connections or child processes spawned by the web server user after such requests.
- Search for known Exploit-DB payload patterns (6368, 17324) in HTTP request bodies and query strings.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-3922 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-3922), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.