First published: Tue Feb 15 2005(Updated: )
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AWStats | =6.3 | |
AWStats | =6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0436 is considered a medium severity vulnerability due to its potential for remote code execution.
To fix CVE-2005-0436, upgrade AWStats to version 6.5 or later to eliminate the vulnerability.
CVE-2005-0436 affects AWStats versions 6.3 and 6.4, allowing remote code injection through the PluginMode parameter.
Yes, CVE-2005-0436 can be exploited remotely by attackers injecting Perl code via the PluginMode parameter.
CVE-2005-0436 is specifically related to the AWStats software used for web statistics and analysis.