CVE-2005-0437: High severity Awstats AWStats vulnerability
Published Feb 15, 2005
·Updated
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
Affected Software
2 affected components
Awstats AWStats=6.3
Awstats AWStats=6.4
Remediation
Patch Available
Event History
Feb 15, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0437?
CVE-2005-0437 is considered a medium severity vulnerability due to its impact on system integrity.
2
How do I fix CVE-2005-0437?
To fix CVE-2005-0437, upgrade AWStats to version 6.5 or later, which addresses the directory traversal vulnerability.
3
What systems are affected by CVE-2005-0437?
CVE-2005-0437 affects AWStats versions 6.3 and 6.4.
4
What kind of attacks can exploit CVE-2005-0437?
CVE-2005-0437 can be exploited by remote attackers to include arbitrary Perl modules, potentially leading to unauthorized execution of code.
5
Is CVE-2005-0437 still a concern for current systems?
While CVE-2005-0437 applies to outdated versions of AWStats, systems still using versions 6.3 or 6.4 remain vulnerable and should be updated.