CVE-2005-0435
AWStats 6.3 and 6.4 - Unauthenticated Arbitrary File Read via loadplugin and pluginmode Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-0435.
AI-analyzed exploit summary This Perl script exploits CVE-2005-0435 in AWStats by sending HTTP requests with crafted parameters to execute arbitrary Perl code (e.g., `getpwent`) or leak sensitive information via debug modes. It demonstrates remote code execution and information disclosure vulnerabilities.
Description
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.
Exploits (1)
This Perl script exploits CVE-2005-0435 in AWStats by sending HTTP requests with crafted parameters to execute arbitrary Perl code (e.g., `getpwent`) or leak sensitive information via debug modes. It demonstrates remote code execution and information disclosure vulnerabilities.