Analog Logfile Script Code Injection Vulnerability

BID:4389

Info

Analog Logfile Script Code Injection Vulnerability

Bugtraq ID: 4389
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Mar 28 2002 12:00AM
Updated: Mar 28 2002 12:00AM
Credit: Discovery of this issue is credited to Yuji Takahashi.
Vulnerable: Analog Analog 5.2
- FreeBSD FreeBSD 4.5
- FreeBSD FreeBSD 4.4
- FreeBSD FreeBSD 4.3
- FreeBSD FreeBSD 4.2
- FreeBSD FreeBSD 4.1.1
- FreeBSD FreeBSD 4.1
Analog Analog 5.1 a
Analog Analog 5.0 3
Analog Analog 5.0 2
Analog Analog 5.0 1
Analog Analog 5.0
Analog Analog 4.16
Analog Analog 4.15
Analog Analog 4.14
Analog Analog 4.11
Analog Analog 4.9 1beta1
Analog Analog 4.9 0beta4
Analog Analog 4.9 0beta3
Analog Analog 4.9 0beta2
Analog Analog 4.1
Analog Analog 4.0 4
Analog Analog 4.0 3
Analog Analog 4.0 2
Analog Analog 4.0 1
- Debian Linux 2.2
Analog Analog 3.9 0beta2
Analog Analog 3.9 0beta1
Not Vulnerable: Analog Analog 5.22
- Debian Linux 2.2

Discussion

Analog Logfile Script Code Injection Vulnerability

Analog is logfile analysis software which is capable of printing formatted logfiles in HTML. It will run on most Unix and Linux variants, as well as a number of other operating systems including Microsoft Windows.

Analog does not filter script code when analyzing logfiles. As a result, it is possible for an attacker to cause arbitrary script code to be included in web pages generated by Analog.

Exploit / POC

Analog Logfile Script Code Injection Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Analog Logfile Script Code Injection Vulnerability

Solution:
The vendor has fixed this issue in version 5.22. Additional upgrades are also available.


Analog Analog 3.9 0beta1

Analog Analog 3.9 0beta2

Analog Analog 4.0 1

Analog Analog 4.0 3

Analog Analog 4.0 4

Analog Analog 4.0 2

Analog Analog 4.1

Analog Analog 4.11

Analog Analog 4.14

Analog Analog 4.15

Analog Analog 4.16

Analog Analog 4.9 0beta3

Analog Analog 4.9 1beta1

Analog Analog 4.9 0beta2

Analog Analog 4.9 0beta4

Analog Analog 5.0

Analog Analog 5.0 1

Analog Analog 5.0 3

Analog Analog 5.0 2

Analog Analog 5.1 a

Analog Analog 5.2

References

Analog Logfile Script Code Injection Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report