Multiple Ex Libris Products Keyword Searches Cross-Site Scripting Vulnerability
BID:24978
Info
Multiple Ex Libris Products Keyword Searches Cross-Site Scripting Vulnerability
| Bugtraq ID: | 24978 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3834 CVE-2007-3835 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2007 12:00AM |
| Updated: | Jul 24 2007 03:35AM |
| Credit: | Matthew Cook is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ex Libris MetaLib 3.13 Ex Libris Aleph 500 |
| Not Vulnerable: | |
Discussion
Multiple Ex Libris Products Keyword Searches Cross-Site Scripting Vulnerability
Multiple Ex Libris Products are prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.
Multiple Ex Libris Products are prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Multiple Ex Libris Products Keyword Searches Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Multiple Ex Libris Products Keyword Searches Cross-Site Scripting Vulnerability
Solution:
The vendor released an update to address this issue. Please contact the vendor for information on how to obtain and apply this update.
Solution:
The vendor released an update to address this issue. Please contact the vendor for information on how to obtain and apply this update.
References
Multiple Ex Libris Products Keyword Searches Cross-Site Scripting Vulnerability
References:
References:
- MetaLib Home Page (Ex Libris )
- ExLibris Aleph and Metalib Cross Site Scripting Attack (Matthew Cook)