CVE-2005-0116: Input Validation
Published Jan 18, 2005
·Updated
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
Affected Software
1 affected component
Awstats AWStats<=6.3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 18, 2005
CVE Published
05:00 AM
Jan 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0116?
CVE-2005-0116 is rated as critical due to the potential for remote command execution.
2
How do I fix CVE-2005-0116?
To fix CVE-2005-0116, upgrade AWStats to version 6.3 or later.
3
What versions of AWStats are affected by CVE-2005-0116?
AWStats versions prior to 6.3, including 6.1, are affected by CVE-2005-0116.
4
Can CVE-2005-0116 be exploited remotely?
Yes, CVE-2005-0116 can be exploited remotely through the configdir parameter.
5
What type of vulnerability is CVE-2005-0116?
CVE-2005-0116 is a command injection vulnerability that allows arbitrary command execution.