Vulnerabilities
Vulnerable Software
Awstats:  >> Awstats  Security Vulnerabilities
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
CVSS Score
7.5
EPSS Score
0.047
Published
2005-05-02
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
CVSS Score
7.5
EPSS Score
0.006
Published
2005-05-02
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
CVSS Score
5.0
EPSS Score
0.047
Published
2005-05-02
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
CVSS Score
4.6
EPSS Score
0.002
Published
2005-02-09
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
CVSS Score
7.5
EPSS Score
0.917
Published
2005-01-18


Contact Us

Shodan ® - All rights reserved