CVE-2005-0436: Code Injection
Published Feb 15, 2005
·Updated
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
Affected Software
2 affected components
Awstats AWStats=6.3
Awstats AWStats=6.4
Remediation
Patch Available
Event History
Feb 15, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0436?
CVE-2005-0436 is considered a medium severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2005-0436?
To fix CVE-2005-0436, upgrade AWStats to version 6.5 or later to eliminate the vulnerability.
3
What does CVE-2005-0436 affect?
CVE-2005-0436 affects AWStats versions 6.3 and 6.4, allowing remote code injection through the PluginMode parameter.
4
Can CVE-2005-0436 be exploited remotely?
Yes, CVE-2005-0436 can be exploited remotely by attackers injecting Perl code via the PluginMode parameter.
5
Is CVE-2005-0436 related to any specific software?
CVE-2005-0436 is specifically related to the AWStats software used for web statistics and analysis.