Ex Libris ALEPH 500 CVE-2014-3718 Multiple HTML Injection Vulnerabilities
BID:67439
Info
Ex Libris ALEPH 500 CVE-2014-3718 Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 67439 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3718 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2014 12:00AM |
| Updated: | May 15 2014 12:00AM |
| Credit: | Shady.liu of DBAppSecurity Co.Ltd |
| Vulnerable: |
Ex Libris ALEPH 500 20 Ex Libris ALEPH 500 18.1 |
| Not Vulnerable: | |
Discussion
Ex Libris ALEPH 500 CVE-2014-3718 Multiple HTML Injection Vulnerabilities
ALEPH 500 is prone to multiple HTML-injection vulnerabilities because it fails to sanitize user-supplied input.
Attacker supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user; other attacks are also possible.
ALEPH 500 18.1 and 20 are vulnerable; other versions may also be affected.
ALEPH 500 is prone to multiple HTML-injection vulnerabilities because it fails to sanitize user-supplied input.
Attacker supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user; other attacks are also possible.
ALEPH 500 18.1 and 20 are vulnerable; other versions may also be affected.
Exploit / POC
Ex Libris ALEPH 500 CVE-2014-3718 Multiple HTML Injection Vulnerabilities
An attacker can exploit these issues using a web browser.
The following example URI is available:
http://www.example.com/cgi-bin/tag_m.cgi?find=%25D3%25C5%25BB%25AF_%3C/script%3E%3Cscript%3Ealert%28/xss/%29%3C/script%3E&lib=BGD01&sid=F7MX34RP19MRDEJ4XKE4A8IGNVS3Q9F7MXYQT832HS3SDKBULT-01466
An attacker can exploit these issues using a web browser.
The following example URI is available:
http://www.example.com/cgi-bin/tag_m.cgi?find=%25D3%25C5%25BB%25AF_%3C/script%3E%3Cscript%3Ealert%28/xss/%29%3C/script%3E&lib=BGD01&sid=F7MX34RP19MRDEJ4XKE4A8IGNVS3Q9F7MXYQT832HS3SDKBULT-01466
Solution / Fix
Ex Libris ALEPH 500 CVE-2014-3718 Multiple HTML Injection Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ex Libris ALEPH 500 CVE-2014-3718 Multiple HTML Injection Vulnerabilities
References:
References:
- CVE-2014-3718] ALEPH500 (Integrated library management system) Cross Site Script (SecLists.Org)
- Ex Libris Homepage (Ex Libris)