CVE-2005-0437Path Traversal in Awstats

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.6%
top 30.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debianawstats/awstats< 6.3-1+3
NVDawstats/awstats6.3, 6.4+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-v4pj-pfq5-2mmv: Directory traversal vulnerability in awstats2022-05-01
OSV
CVE-2005-0437: Directory traversal vulnerability in awstats2005-05-02
CVEList
CVE-2005-0437: Directory traversal vulnerability in awstats2005-02-15

📋Vendor Advisories

1
Debian
CVE-2005-0437: awstats - Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows re...2005