5
CVSSv2

CVE-2005-0435

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

awstats.pl in AWStats 6.3 and 6.4 allows remote malicious users to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.

Vulnerable Product Search on Vulmon Subscribe to Product

awstats awstats 6.3

awstats awstats 6.4

Exploits

#!/usr/bin/perl # # # Summarized the advisory wwwghcru GHC: /str0ke # # [0] Exploitable example (raw log plugin): # Attacker can read sensitive information # # server/cgi-bin/awstats-64/awstatspl?pluginmode=rawlog&loadplugin=rawlog # # [1] Perl code execution (This script) # ...