Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
References
Link Resource
http://secunia.com/advisories/14299 Exploit Patch Vendor Advisory
http://www.securityfocus.com/archive/1/390368 Exploit Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2005-02-15T05:00:00

Updated: 2005-05-11T09:00:00

Reserved: 2005-02-15T00:00:00


Link: CVE-2005-0437

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2005-05-02T04:00:00.000

Modified: 2008-09-05T20:46:17.257


Link: CVE-2005-0437

JSON object: View

cve-icon Redhat Information

No data.