ELOG Web Logbook Multiple Remote Vulnerabilities
BID:12556
Info
ELOG Web Logbook Multiple Remote Vulnerabilities
| Bugtraq ID: | 12556 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2005 12:00AM |
| Updated: | Feb 14 2005 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Elog Web Logbook Elog Web Logbook 2.5 Elog Web Logbook Elog Web Logbook 2.4 Elog Web Logbook Elog Web Logbook 2.2.4 Elog Web Logbook Elog Web Logbook 2.2.3 Elog Web Logbook Elog Web Logbook 2.2.2 Elog Web Logbook Elog Web Logbook 2.2.1 Elog Web Logbook Elog Web Logbook 2.2 .0 Elog Web Logbook Elog Web Logbook 2.1.3 Elog Web Logbook Elog Web Logbook 2.1.2 Elog Web Logbook Elog Web Logbook 2.1.1 Elog Web Logbook Elog Web Logbook 2.1 .0 Elog Web Logbook Elog Web Logbook 2.0.5 Elog Web Logbook Elog Web Logbook 2.0.4 Elog Web Logbook Elog Web Logbook 2.0.3 Elog Web Logbook Elog Web Logbook 2.0.2 Elog Web Logbook Elog Web Logbook 2.0.1 Elog Web Logbook Elog Web Logbook 2.0 .0 |
| Not Vulnerable: |
Elog Web Logbook Elog Web Logbook 2.5.7 |
Discussion
ELOG Web Logbook Multiple Remote Vulnerabilities
ELOG is reported prone to multiple remote vulnerabilities. These issues may allow an attacker to disclose sensitive information and potentially execute arbitrary code on a vulnerable computer.
The following specific issues were identified:
The application is reported prone to an unspecified buffer overflow vulnerability. The vendor has reported that this vulnerability is exploitable and allows attackers to gain unauthorized access to a vulnerable computer.
Another vulnerability affecting the application can allow remote attackers to obtain sensitive information such as authentication credentials stored in an unspecified configuration file.
ELOG 2.5.0 and prior versions are affected by these vulnerabilities.
ELOG is reported prone to multiple remote vulnerabilities. These issues may allow an attacker to disclose sensitive information and potentially execute arbitrary code on a vulnerable computer.
The following specific issues were identified:
The application is reported prone to an unspecified buffer overflow vulnerability. The vendor has reported that this vulnerability is exploitable and allows attackers to gain unauthorized access to a vulnerable computer.
Another vulnerability affecting the application can allow remote attackers to obtain sensitive information such as authentication credentials stored in an unspecified configuration file.
ELOG 2.5.0 and prior versions are affected by these vulnerabilities.
Exploit / POC
ELOG Web Logbook Multiple Remote Vulnerabilities
Currently we are not aware of any exploits for the buffer overflow issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The information disclosure issue does not require exploit code.
Currently we are not aware of any exploits for the buffer overflow issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The information disclosure issue does not require exploit code.
Solution / Fix
ELOG Web Logbook Multiple Remote Vulnerabilities
Solution:
The vendor has released ELOG 2.5.7 to address these issues.
Elog Web Logbook Elog Web Logbook 2.0 .0
Elog Web Logbook Elog Web Logbook 2.0.1
Elog Web Logbook Elog Web Logbook 2.0.2
Elog Web Logbook Elog Web Logbook 2.0.3
Elog Web Logbook Elog Web Logbook 2.0.4
Elog Web Logbook Elog Web Logbook 2.0.5
Elog Web Logbook Elog Web Logbook 2.1 .0
Elog Web Logbook Elog Web Logbook 2.1.1
Elog Web Logbook Elog Web Logbook 2.1.2
Elog Web Logbook Elog Web Logbook 2.1.3
Elog Web Logbook Elog Web Logbook 2.2 .0
Elog Web Logbook Elog Web Logbook 2.2.1
Elog Web Logbook Elog Web Logbook 2.2.2
Elog Web Logbook Elog Web Logbook 2.2.3
Elog Web Logbook Elog Web Logbook 2.2.4
Elog Web Logbook Elog Web Logbook 2.4
Elog Web Logbook Elog Web Logbook 2.5
Solution:
The vendor has released ELOG 2.5.7 to address these issues.
Elog Web Logbook Elog Web Logbook 2.0 .0
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.0.1
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.0.2
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.0.3
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.0.4
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.0.5
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.1 .0
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.1.1
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.1.2
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.1.3
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.2 .0
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.2.1
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.2.2
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.2.3
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.2.4
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.4
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
Elog Web Logbook Elog Web Logbook 2.5
-
Elog Web Logbook elog-2.5.7-1.tar.gz
http://prdownloads.sourceforge.net/elog/elog-2.5.7-1.tar.gz?download
References
ELOG Web Logbook Multiple Remote Vulnerabilities
References:
References:
- Change Log (Elog Web Logbook)
- Elog Web Logbook Homepage (Elog Web Logbook)