Description: Two vulnerabilities have been reported in ELOG, which can be exploited by malicious people to disclose sensitive information and compromise a vulnerable system.
1) An unspecified boundary error, can be exploited to cause a buffer overflow and execute arbitrary code.
2) A certain configuration file containing password information is not properly protected from being downloaded.
NOTE: Exploit code is publicly available.
The vulnerabilities have been reported in version 2.5.6 and prior.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.