SurfStats Log Analyzer Logfile HTML Injection Vulnerability
BID:7014
Info
SurfStats Log Analyzer Logfile HTML Injection Vulnerability
| Bugtraq ID: | 7014 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2003 12:00AM |
| Updated: | Mar 04 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Hugo "Vázquez" "Caramés". |
| Vulnerable: |
SurfStats SurfStats Log Analyzer 6.7 .0.3 |
| Not Vulnerable: | |
Discussion
SurfStats Log Analyzer Logfile HTML Injection Vulnerability
SurfStats Log Analyzer does not sufficiently sanitize HTML when logging requests. If malicious data containing HTML and script code is logged and then viewed using the software, exploitation will occur. Through exploitation of this issue, it will be possible to falsify log information and execute arbitrary script code in the web client of the user viewing the logs.
SurfStats Log Analyzer does not sufficiently sanitize HTML when logging requests. If malicious data containing HTML and script code is logged and then viewed using the software, exploitation will occur. Through exploitation of this issue, it will be possible to falsify log information and execute arbitrary script code in the web client of the user viewing the logs.
Exploit / POC
SurfStats Log Analyzer Logfile HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
References
SurfStats Log Analyzer Logfile HTML Injection Vulnerability
References:
References:
- SurfStats Homepage (SurfStats)
- Log corruption on multiple webservers, log analyzers,... ( Hugo "Vázquez" "Caramés"
)