cbcvebase.
CVE-2006-5790
published 2006-11-07

CVE-2006-5790: Multiple format string vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute…

PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.06%
86.0th percentile
Multiple format string vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) an entry with an attachment whose name contains format string specifiers (el_submit function), and possibly other vectors in the (2) receive_config, (3) show_rss_feed, (4) show_elog_list, (5) show_logbook_node, and (6) server_loop functions.

Affected

1 ranges
VendorProductVersion rangeFixed in
stefan_rittelog_web_logbook<= 2.6.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.