CVE-2007-3569
Oliver Library Management System - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3569. PoCs published by A. R..
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in Oliver software by injecting arbitrary script code via unsanitized input parameters in the gateway.exe endpoint. The PoC includes example URLs with embedded JavaScript alerts to confirm vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML via the (1) updateform and (2) displayform parameter to (a) gateway/gateway.exe; the (3) TERMS, (4) database, (5) srchad, (6) SuggestedSearch, and (7) searchform parameters to the (b) "Basic Search page"; and (8) username parameter when (c) logging on.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in Oliver software by injecting arbitrary script code via unsanitized input parameters in the gateway.exe endpoint. The PoC includes example URLs with embedded JavaScript alerts to confirm vulnerability.