ModLogAn Splitby Input Validation...

- AV AC AU C I A
发布: 2002-01-04
修订: 2025-04-13

ModLogAn is a freely available, open-source log file analyzer. It can process log files from a number of different services including webservers (Apache, MS IIS, Netscape), FTP servers (wu-ftpd, proftpd, etc.) and mail servers (sendmail, qmail), and a variety of other sources. ModLogAn can be run on many Unix and Linux variants, as well as Microsoft Windows NT/2000 systems. A vulnerability exists in the splitby option of the processor_web plugin, and should only affect systems which have this feature enabled. It may allow a local attacker to overwrite root-owned files via symlink attacks. The splitby function enables a user to split logfiles into seperate reports per each virtual host. Splitby does not adequately validate input. When attempting to parse a log entry that has a hostname that starts with dot-dot slash (../) sequences, it is possible that the ModLogAn output may end up in an unexpected directory of the attacker's choosing. Vulnerable versions of ModLogAn run as root. A...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息