OSVDB ID: 22647

Title: ELOG URL Processing Unspecified Traversal

Info

Disclosure

Jan 19, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

ELOG contains a flaw that allows a remote attacker to access files outside of the web path. The issue is due to the ELOG server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via an unspecified variable.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality
Exploit: Exploit Unknown
Disclosure: OSVDB Verified
OSVDB: Web Related

Solution

Upgrade to version 2.6.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Stefan Ritt

ELOG

2.6.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218