PT-2005-1499 · Awstats · Awstats

Published

2005-02-15

·

Updated

2008-09-05

·

CVE-2005-0437

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AWStats versions 6.3 through 6.4
Description A directory traversal issue exists, allowing remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
Recommendations For AWStats versions 6.3 through 6.4, consider restricting access to the loadplugin parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0437

Affected Products

Awstats