Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown
CVE-2005-1527
Disclosure Date: August 15, 2005 (last updated February 22, 2025)
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
0
Attacker Value
Unknown
CVE-2005-0363
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
0
Attacker Value
Unknown
CVE-2005-0438
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
0
Attacker Value
Unknown
CVE-2005-0435
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.
0
Attacker Value
Unknown
CVE-2005-0437
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
0
Attacker Value
Unknown
CVE-2005-0436
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
0
Attacker Value
Unknown
CVE-2005-0362
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
0
Attacker Value
Unknown
CVE-2005-0116
Disclosure Date: January 18, 2005 (last updated February 22, 2025)
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
0