CVE-2005-0116 describes a critical remote command execution vulnerability in AWStats versions 6.1 and earlier. Attackers can exploit this flaw by injecting shell metacharacters into the configdir parameter of the awstats.pl script. This vulnerability carries a high CVSS score of 7.5, indicating that it is easily exploitable over the network without authentication, leading to potential compromise of confidentiality, integrity, and availability. The high EPSS score and FAUCET Risk Score of 100/100 highlight the significant threat this vulnerability poses. While not listed in CISA's KEV catalog, multiple public exploit modules exist, including several Metasploit modules and entries on ExploitDB, confirming its widespread exploitability. The vulnerability also garners substantial community discussion, with over 10 mentions, indicating active interest and awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.3CPE matchmatch criteria | cpe:2.3:a:awstats:awstats:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.