Summary
Detail | |||
---|---|---|---|
Vendor | Elog | First view | 2008-01-24 |
Product | Elog | Last view | 2009-08-19 |
Version | 1.0.0 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:elog:elog |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
10 | 2009-08-19 | CVE-2008-7004 | Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c. |
5 | 2008-01-24 | CVE-2008-0445 | The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries. NOTE: some of these details are obtained from third party information. |
4.3 | 2008-01-24 | CVE-2008-0444 | Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
50% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
41684 | ELOG Unspecified Overflow |
41682 | ELOG replace_inline_img Function Crafted Logbook Entry DoS |
41681 | ELOG subtext Parameter XSS |
OpenVAS Exploits
id | Description |
---|---|
2009-08-26 | Name : ELOG Remote Buffer Overflow and Cross Site Scripting Vulnerabilities File : nvt/secpod_elog_mult_vuln.nasl |