[analog-help] Help Understanding Bug Found

2002-03-25 Thread jenkins . mw
I am trying to decode what was meant by this: It is easy for an attacker to insert arbitrary strings into any web server logfile. If these strings are then analysed by analog, they can appear in the report. By this means an attacker can introduce arbitrary Javascript code,

Re: [analog-help] Help Understanding Bug Found

2002-03-25 Thread Jeremy Wadsack
[EMAIL PROTECTED] ([EMAIL PROTECTED]): I am trying to decode what was meant by this: It is easy for an attacker to insert arbitrary strings into any web server logfile. If these strings are then analysed by analog, they can appear in the report. By this means an attacker can

Re: [analog-help] Help Understanding Bug Found

2002-03-25 Thread jenkins . mw
To: [EMAIL PROTECTED] [EMAIL PROTECTED] Cc:(bcc: Mike Jenkins-MW/PGI) Subject: Re: [analog-help] Help Understanding Bug Found 03/25/2002 12:41