CVE-2005-1527: Code Injection
Published Aug 15, 2005
·Updated
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
Affected Software
21 affected components
Awstats AWStats=5.7
Awstats AWStats=6.3
Awstats AWStats=5.9
Awstats AWStats=6.1
Awstats AWStats=6.2
Awstats AWStats=5.0
Awstats AWStats=5.2
Awstats AWStats=5.6
Awstats AWStats=5.1
Awstats AWStats=6.0
Awstats AWStats=5.4
Awstats AWStats=5.3
Awstats AWStats=5.8
Awstats AWStats=5.5
Ubuntu Ubuntu Linux=5.04
Ubuntu Ubuntu Linux=5.04
Ubuntu Ubuntu Linux=5.04
Awstats AWStats<=6.4
Canonical Ubuntu Linux=5.04
Debian Debian Linux=3.0
Debian Debian Linux=3.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 15, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1527?
CVE-2005-1527 is considered a medium severity vulnerability.
2
How do I fix CVE-2005-1527?
To fix CVE-2005-1527, update AWStats to version 6.5 or later.
3
What software is affected by CVE-2005-1527?
CVE-2005-1527 affects AWStats versions 6.4 and earlier.
4
How does CVE-2005-1527 impact my system?
CVE-2005-1527 allows remote attackers to execute arbitrary Perl code, compromising your system's security.
5
Is there a workaround for CVE-2005-1527?
A temporary workaround for CVE-2005-1527 is to disable the URLPlugin in AWStats until an update can be applied.