PT-2004-2421 · 04Webserver · 04Webserver
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-1513
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
04WebServer version 1.42
Description
The issue is related to inadequate filtering of data written to log files, potentially allowing remote attackers to inject carriage return characters into the log file and spoof log entries.
Recommendations
For version 1.42, consider implementing proper input validation and filtering to prevent the injection of malicious characters into log files. As a temporary workaround, restrict access to the log files to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
04Webserver