First published: Tue Feb 15 2005(Updated: )
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AWStats | =6.3 | |
AWStats | =6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0435 is considered a moderate severity vulnerability that allows unauthorized access to web server logs.
To fix CVE-2005-0435, upgrade AWStats to a version later than 6.4 that addresses this vulnerability.
CVE-2005-0435 affects AWStats versions 6.3 and 6.4.
CVE-2005-0435 can be exploited by an attacker manipulating the loadplugin and pluginmode parameters to read server web logs.
CVE-2005-0435 can be easily exploited by a remote attacker with knowledge of the affected parameters.