CVE-2014-3718
Summary
| CVE | CVE-2014-3718 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-30 20:15:00 UTC |
| Updated | 2020-02-03 21:59:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to inject arbitrary web script or HTML via the (1) find, (2) lib, or (3) sid parameter. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Exlibrisgroup | Aleph 500 | 18.1 | All | All | All |
| Application | Exlibrisgroup | Aleph 500 | 20.0 | All | All | All |
| Application | Exlibrisgroup | Aleph 500 | 18.1 | All | All | All |
| Application | Exlibrisgroup | Aleph 500 | 20.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: CVE-2014-3718] ALEPH500 (Integrated library management system) Cross Site Scripting Vulnerability | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Aleph 500 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.