Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

A. R

#51844of 53,632
4.3Total CVSS
Vulnerabilities · 1
PT-2007-4825
4.3
2007-07-05
Oclc · Oliver Library Management System · CVE-2007-3569
**Name of the Vulnerable Software and Affected Versions** Oliver Library Management System (affected versions not specified) **Description** The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via several parameters, including `updateform` and `displayform` to the "gateway/gateway.exe" endpoint, and `TERMS`, `database`, `srchad`, `SuggestedSearch`, and `searchform` parameters to the "Basic Search page". Additionally, the `username` parameter is vulnerable when logging on. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.