Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2008-7206

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS).
0
Attacker Value
Unknown

CVE-2008-7004

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.
0
Attacker Value
Unknown

CVE-2008-0444

Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.
0
Attacker Value
Unknown

CVE-2008-0445

Disclosure Date: January 25, 2008 (last updated October 04, 2023)
The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-6318

Disclosure Date: December 28, 2006 (last updated October 04, 2023)
The show_elog_list function in elogd.c in elog 2.6.2 and earlier allows remote authenticated users to cause a denial of service (daemon crash) by attempting to access a logbook whose name begins with "global," which results in a NULL pointer dereference. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-0599

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.
0
Attacker Value
Unknown

CVE-2006-0598

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file.
0
Attacker Value
Unknown

CVE-2006-0600

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with the fail parameter set to 1, which redirects to the same request.
0
Attacker Value
Unknown

CVE-2006-0597

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of service (application crash) and possibly execute code via long "revision attributes".
0
Attacker Value
Unknown

CVE-2006-0347

Disclosure Date: January 21, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.
0