This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Elog First view 2008-01-24
Product Elog Last view 2009-08-19
Version 1.0.0 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:elog:elog

Activity : Overall

Related : CVE

  Date Alert Description
10 2009-08-19 CVE-2008-7004

Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.

5 2008-01-24 CVE-2008-0445

The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries. NOTE: some of these details are obtained from third party information.

4.3 2008-01-24 CVE-2008-0444

Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.

CWE : Common Weakness Enumeration

%idName
50% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
50% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Open Source Vulnerability Database (OSVDB)

id Description
41684 ELOG Unspecified Overflow
41682 ELOG replace_inline_img Function Crafted Logbook Entry DoS
41681 ELOG subtext Parameter XSS

OpenVAS Exploits

id Description
2009-08-26 Name : ELOG Remote Buffer Overflow and Cross Site Scripting Vulnerabilities
File : nvt/secpod_elog_mult_vuln.nasl