Nihuo Web Log Analyzer HTML Injection Vulnerability
BID:10988
Info
Nihuo Web Log Analyzer HTML Injection Vulnerability
| Bugtraq ID: | 10988 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 20 2004 12:00AM |
| Updated: | Aug 20 2004 12:00AM |
| Credit: | Audun Larsen <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Nihuo Software Inc. Web Log Analyzer 1.6 |
| Not Vulnerable: | |
Discussion
Nihuo Web Log Analyzer HTML Injection Vulnerability
An HTML injection vulnerability is reported in Nihuo Web Log Analyzer. The problem occurs due to a lack of proper sanitization of user-supplied input data.
Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Version 1.6 was reported vulnerable to this issue. Other versions may also be affected.
An HTML injection vulnerability is reported in Nihuo Web Log Analyzer. The problem occurs due to a lack of proper sanitization of user-supplied input data.
Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Version 1.6 was reported vulnerable to this issue. Other versions may also be affected.
Exploit / POC
Nihuo Web Log Analyzer HTML Injection Vulnerability
An exploit is not required. Example HTTP request data was provided:
GET / HTTP/1.1
Host: www.example.com
Connection: close
Accept: text/plain
Accept-Language: en-us,en
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
User-Agent: Some-Fake-UA <img src='http://attacker.example.com/app.gif'>
An exploit is not required. Example HTTP request data was provided:
GET / HTTP/1.1
Host: www.example.com
Connection: close
Accept: text/plain
Accept-Language: en-us,en
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
User-Agent: Some-Fake-UA <img src='http://attacker.example.com/app.gif'>
Solution / Fix
Nihuo Web Log Analyzer HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nihuo Web Log Analyzer HTML Injection Vulnerability
References:
References:
- Nihuo Web Log Analyzer Home Page (Nihuo Software, Inc.)
- Cross-Site Scripting (XSS) in Nihuo Web Log Analyzer (Audun Larsen
)