7.5
CVSSv2

CVE-2005-0436

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote malicious users to execute portions of Perl code via the PluginMode parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

awstats awstats 6.3

awstats awstats 6.4

Exploits

#!/usr/bin/perl # # # Summarized the advisory wwwghcru GHC: /str0ke # # [0] Exploitable example (raw log plugin): # Attacker can read sensitive information # # server/cgi-bin/awstats-64/awstatspl?pluginmode=rawlog&loadplugin=rawlog # # [1] Perl code execution (This script) # ...