CVE-2005-0437

NameCVE-2005-0437
DescriptionDirectory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
awstats (PTS)bullseye7.8-2+deb11u1fixed
bullseye (security)7.8-2+deb11u2fixed
bookworm7.8-3+deb12u2fixed
trixie7.9-1+deb13u1fixed
forky, sid8.0-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
awstatssource(unstable)6.3-1

Search for package or bug name: Reporting problems