Описание
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
Ссылки
- Broken LinkPatchVendor Advisory
- Broken Link
- Broken LinkPatchThird Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Broken Link
- Broken Link
- Broken LinkPatch
- Broken LinkVendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Broken Link
- Broken LinkPatchVendor Advisory
- Broken Link
- Broken LinkPatchThird Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Broken Link
- Broken Link
- Broken LinkPatch
- Broken LinkVendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Одно из
EPSS
5 Medium
CVSS2
Дефекты
Связанные уязвимости
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, ...
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
EPSS
5 Medium
CVSS2