WebLog Expert HTTP Header Code Injection Vulnerability
BID:7015
Info
WebLog Expert HTTP Header Code Injection Vulnerability
| Bugtraq ID: | 7015 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2003 12:00AM |
| Updated: | Mar 04 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Hugo Vázquez Caramés & Toni Cortés Martínez. |
| Vulnerable: |
WebLog WebLog Expert Lite 2.0 Beta 1 WebLog WebLog Expert Lite 1.61 WebLog WebLog Expert 2.0 Beta 1 WebLog WebLog Expert 1.61 |
| Not Vulnerable: |
WebLog WebLog Expert Lite 2.0 Beta 2 WebLog WebLog Expert 2.0 Beta 2 |
Discussion
WebLog Expert HTTP Header Code Injection Vulnerability
A vulnerability has been discovered in WebLog Expert. Under certain circumstances an attacker may embed HTML code into the HTTP header section of a web log entry. Due to insufficient sanitization of HTTP header information, WebLog Expert reports that are derived from malicious web logs may incorporate the arbitrary attacker supplied HTML code.
This vulnerability was reported for WebLog Expert version 1.6.1 other versions may also be affected.
A vulnerability has been discovered in WebLog Expert. Under certain circumstances an attacker may embed HTML code into the HTTP header section of a web log entry. Due to insufficient sanitization of HTTP header information, WebLog Expert reports that are derived from malicious web logs may incorporate the arbitrary attacker supplied HTML code.
This vulnerability was reported for WebLog Expert version 1.6.1 other versions may also be affected.
Exploit / POC
WebLog Expert HTTP Header Code Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
WebLog Expert HTTP Header Code Injection Vulnerability
Solution:
Fixes available:
WebLog WebLog Expert Lite 2.0 Beta 1
WebLog WebLog Expert 2.0 Beta 1
Solution:
Fixes available:
WebLog WebLog Expert Lite 2.0 Beta 1
-
WebLog wlelitebeta.zip
http://www.weblogexpert.com/files/wlelitebeta.zip
WebLog WebLog Expert 2.0 Beta 1
-
WebLog wlexpertbeta.zip
http://www.weblogexpert.com/files/wlexpertbeta.zip
References
WebLog Expert HTTP Header Code Injection Vulnerability
References:
References:
- WebLog Expert Homepage (WebLog)
- Log corruption on multiple webservers, log analyzers,... ( Hugo "Vázquez" "Caramés"
)