WebTrends Analysis Suite Logfile HTML Injection Vulnerability
BID:7013
Info
WebTrends Analysis Suite Logfile HTML Injection Vulnerability
| Bugtraq ID: | 7013 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2003 12:00AM |
| Updated: | Mar 04 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Hugo "Vázquez" "Caramés". |
| Vulnerable: |
WebTrends WebTrends Analysis Suite 7.0 |
| Not Vulnerable: | |
Discussion
WebTrends Analysis Suite Logfile HTML Injection Vulnerability
WebTrends Analysis Suite does not sufficiently sanitize HTML when logging requests. If malicious data containing HTML and script code is logged and then viewed using the software, exploitation will occur. Through exploitation of this issue, it will be possible to falsify log information and execute arbitrary script code in the web client of the user viewing the logs.
Other WebTrends products may also be affected, though this has not been confirmed.
WebTrends Analysis Suite does not sufficiently sanitize HTML when logging requests. If malicious data containing HTML and script code is logged and then viewed using the software, exploitation will occur. Through exploitation of this issue, it will be possible to falsify log information and execute arbitrary script code in the web client of the user viewing the logs.
Other WebTrends products may also be affected, though this has not been confirmed.
Exploit / POC
WebTrends Analysis Suite Logfile HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
WebTrends Analysis Suite Logfile HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WebTrends Analysis Suite Logfile HTML Injection Vulnerability
References:
References:
- WebTrends Analysis Suite Product Page (NetIQ)
- Log corruption on multiple webservers, log analyzers,... ( Hugo "Vázquez" "Caramés"
)