PT-2006-6470 · Elog · Elog

Ulf Harnhammar

·

Published

2006-11-07

·

Updated

2017-07-20

·

CVE-2006-5791

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: ELOG versions 2.6.2 and earlier
Description: The issue allows remote attackers to inject arbitrary HTML or web script via specific parameters. This can be achieved by injecting malicious input in the filename for downloading, which is not properly quoted in an error message by the send file direct function. Additionally, the Type or Category values in a New entry are not properly handled in an error message by the submit elog function, allowing for the injection of arbitrary web script.
Recommendations: For ELOG versions 2.6.2 and earlier, consider disabling the send file direct and submit elog functions until a patch is available to prevent exploitation. Restrict access to error messages that may contain user-inputted data to minimize the risk of arbitrary HTML or web script injection.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5791
DSA-1242-1

Affected Products

Elog