Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ELOG Cross-Site Scripting Vulnerability and Denial of Service Vulnerability

ELOG is prone to a cross-site scripting vulnerability and a denial-of-service vulnerability because the application fails to properly handle user-supplied input.

An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Versions prior to ELOG 2.7.1 are vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus