vendor:
LogAnalyzer
by:
Dolev Farhi
7,5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: LogAnalyzer
Affected Version From: <= 3.6.5
Affected Version To: 3.6.6
Patch Exists: YES
Related CWE: CVE-2014-6070
CPE: a:adiscon:loganalyzer:3.6.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: RHEL6.4
2014
Syslog LogAnalyzer 3.6.5 Stored XSS
It was found that an XSS injection is possible on a syslog server running LogAnalyzer version 3.6.5. by changing the hostname of any entity logging to syslog server with LogAnalyzer to <script>alert("xss")</script>, and sending an arbitrary syslog message, a client-side script injection execution is possible.
Mitigation:
The vulnerability can be mitigated by upgrading to LogAnalyzer version 3.6.6 or later.