WebLog Expert Logfile HTML Injection Vulnerability
BID:7016
Info
WebLog Expert Logfile HTML Injection Vulnerability
| Bugtraq ID: | 7016 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2003 12:00AM |
| Updated: | Mar 04 2003 12:00AM |
| Credit: | Discovery credited to Hugo "Vázquez" "Caramés" <[email protected]>. |
| Vulnerable: |
WebLog WebLog Expert Lite 2.0 Beta 1 WebLog WebLog Expert Lite 1.61 WebLog WebLog Expert 2.0 Beta 1 WebLog WebLog Expert 1.61 |
| Not Vulnerable: | |
Discussion
WebLog Expert Logfile HTML Injection Vulnerability
WebLog Expert does not sufficiently sanitize HTML when logging requests. If malicious data containing HTML and script code is logged and then viewed using the software, exploitation will occur. Through exploitation of this issue, it will be possible to falsify log information and execute arbitrary script code in the web client of the user viewing the logs.
WebLog Expert does not sufficiently sanitize HTML when logging requests. If malicious data containing HTML and script code is logged and then viewed using the software, exploitation will occur. Through exploitation of this issue, it will be possible to falsify log information and execute arbitrary script code in the web client of the user viewing the logs.
Solution / Fix
WebLog Expert Logfile HTML Injection Vulnerability
Solution:
Fixes available:
WebLog WebLog Expert Lite 2.0 Beta 1
WebLog WebLog Expert 2.0 Beta 1
Solution:
Fixes available:
WebLog WebLog Expert Lite 2.0 Beta 1
-
WebLog wlelitebeta.zip
http://www.weblogexpert.com/files/wlelitebeta.zip
WebLog WebLog Expert 2.0 Beta 1
-
WebLog wlexpertbeta.zip
http://www.weblogexpert.com/files/wlexpertbeta.zip