System compromise in Piwik

Posted: November 28, 2012 in Vulnerabilities
Tags: ,


System compromise in Piwik

Vulnerability: System compromise in Piwik

Severity Rating: Critical
Patch: Yes
Number of vulnerabilities: 1

Vector of operation: Remote
Impact: System Compromise

Exploited by active exploitation of the vulnerability
Affected products: Piwik 1.x

Affected versions: Piwik 1.9.2 November 26, 2012 from 15:43 UTC to 23:59 UTC.


The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability is due to the fact that the developer is distributing the program installation package with built-in backdoor. This can be, for example, to execute arbitrary PHP code.

Manufacturer URL:

Solution: Download and reinstall the latest version from the manufacturer.


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s