Forum Moderators: DixonJones

Message Too Old, No Replies

Analog Security warning

         

Son_House

4:53 pm on Mar 21, 2002 (gmt 0)

10+ Year Member



It is easy for an attacker to insert arbitrary strings into any web
server logfile. If these strings are then analysed by analog, they can
appear in the report. By this means an attacker can introduce
arbitrary Javascript code, for example, into an analog report produced
by someone else and read by a third person.

Stephen Turner recommends upgrading to version 5.22 immediately.

[analog.cx...]

Macguru

4:58 pm on Mar 21, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks for the heads up Son_House!

I am upgrading right away.

pshea

11:39 pm on Mar 22, 2002 (gmt 0)

10+ Year Member



Yes, thanks for that.

Son_House

4:04 am on Mar 23, 2002 (gmt 0)

10+ Year Member



Your both welcome :)