Logan Pro HTTP Header Code Injection Vulnerability
BID:7010
Info
Logan Pro HTTP Header Code Injection Vulnerability
| Bugtraq ID: | 7010 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2003 12:00AM |
| Updated: | Mar 04 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Hugo Vázquez Caramés & Toni Cortés Martínez. |
| Vulnerable: |
Logan Pro Logan Pro 1.2 |
| Not Vulnerable: | |
Discussion
Logan Pro HTTP Header Code Injection Vulnerability
A vulnerability has been discovered in Logan Pro. Under certain circumstances an attacker may embed HTML code into the HTTP header section of a web log entry. Due to insufficient sanitization of HTTP header information, Logan Pro reports that are derived from malicious web logs may incorporate the arbitrary attacker-supplied HTML code.
This vulnerability was reported for Logan Pro version 1.2 previous versions may also be affected.
A vulnerability has been discovered in Logan Pro. Under certain circumstances an attacker may embed HTML code into the HTTP header section of a web log entry. Due to insufficient sanitization of HTTP header information, Logan Pro reports that are derived from malicious web logs may incorporate the arbitrary attacker-supplied HTML code.
This vulnerability was reported for Logan Pro version 1.2 previous versions may also be affected.
Exploit / POC
Logan Pro HTTP Header Code Injection Vulnerability
No exploit is required.
No exploit is required.
References
Logan Pro HTTP Header Code Injection Vulnerability
References:
References:
- Logan Pro Homepage (Logan Pro)
- Log corruption on multiple webservers, log analyzers,... ( Hugo "Vázquez" "Caramés"
)