VendorsStefan Rittelog_web_logbook2.6.1
Vulnerabilities

Stefan Ritt Elog Web Logbook 2.6.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2006-5063
Cross-site scripting (XSS) vulnerability in Elog 2.6.1 allows remote attackers to inject arbitrary web script or HTML by editing log entries in HTML mode.
Published 2006-09-28 · Modified
5.1EPSS 0.014
CVE-2006-6318
The show_elog_list function in elogd.c in elog 2.6.2 and earlier allows remote authenticated users to cause a denial of service (daemon crash) by attempting to access a logbook whose name begins with "global," which results in a NULL pointer dereference. NOTE: some of these details are obtained from third party information.
Published 2006-12-28 · Modified
5.0EPSS 0.034
CVE-2008-7206
Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS).
Published 2009-09-11 · Modified
4.3EPSS 0.009