5
CVSSv2

CVE-2005-1527

Published: 15/08/2005 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Eval injection vulnerability in awstats.pl in AWStats 6.4 and previous versions, when a URLPlugin is enabled, allows remote malicious users to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.

Vulnerable Product Search on Vulmon Subscribe to Product

awstats awstats

canonical ubuntu linux 5.04

debian debian linux 3.1

debian debian linux 3.0

Vendor Advisories

Peter Vreugdenhil discovered a command injection vulnerability in AWStats As part of the statistics reporting function, AWStats displays information about the most common referrer values that caused users to visit the website Referer URLs could be crafted in a way that they contained arbitrary Perl code which would have been executed with the pri ...