Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

A. R

#50887de 53,638
4.3CVSS total
Vulnerabilidades · 1
PT-2007-4825
4.3
2007-07-05
Oclc · Oliver Library Management System · CVE-2007-3569
**Name of the Vulnerable Software and Affected Versions** Oliver Library Management System (affected versions not specified) **Description** The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via several parameters, including `updateform` and `displayform` to the "gateway/gateway.exe" endpoint, and `TERMS`, `database`, `srchad`, `SuggestedSearch`, and `searchform` parameters to the "Basic Search page". Additionally, the `username` parameter is vulnerable when logging on. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.