Users of the Webstats package AWStats will definitely want to upgrade to the latest version (6.4), (or at least to version 6.3) in order to plug the AWStats ‘configdir’ Remote Command Execution exploit, which was detailed by the iDefense site. In short, the vulnerability allows the hackers to to execute arbitrary commands under the privileges of the Web server's username.