Vulnerabilities
Vulnerable Software
Awstats:  Security Vulnerabilities
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.
CVSS Score
5.0
EPSS Score
0.074
Published
2005-05-02
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
CVSS Score
7.5
EPSS Score
0.07
Published
2005-05-02
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
CVSS Score
7.5
EPSS Score
0.018
Published
2005-05-02
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
CVSS Score
5.0
EPSS Score
0.038
Published
2005-05-02
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
CVSS Score
4.6
EPSS Score
0.018
Published
2005-02-09
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
CVSS Score
7.5
EPSS Score
0.749
Published
2005-01-18


Contact Us

Shodan ® - All rights reserved