PT-2006-6470 · Elog · Elog
Ulf Harnhammar
·
Published
2006-11-07
·
Updated
2017-07-20
·
CVE-2006-5791
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
ELOG versions 2.6.2 and earlier
Description:
The issue allows remote attackers to inject arbitrary HTML or web script via specific parameters. This can be achieved by injecting malicious input in the filename for downloading, which is not properly quoted in an error message by the
send file direct function. Additionally, the Type or Category values in a New entry are not properly handled in an error message by the submit elog function, allowing for the injection of arbitrary web script.Recommendations:
For ELOG versions 2.6.2 and earlier, consider disabling the
send file direct and submit elog functions until a patch is available to prevent exploitation. Restrict access to error messages that may contain user-inputted data to minimize the risk of arbitrary HTML or web script injection.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elog