38708vdb entry
http://osvdb.org/38708 CVE-2007-5993
VTLS Web Gateway 48.1 - 'Searchtype' Cross-Site Scripting
Record summary
CVE-2007-5993 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBVTLS Web Gateway 48.1 - 'Searchtype' Cross-Site ScriptingExploitDB exploitby Jesus Olmos GonzalezNot analyzed1 file
References
727661Third-party advisory
http://secunia.com/advisories/27661 3369Third-party advisory
http://securityreason.com/securityalert/3369 20071113 [ISecAuditors Security Advisories] VTLS.web.gateway cgi is vulnerable to XSSmailing list
http://www.securityfocus.com/archive/1/483622/100/0/threaded 26419vdb entry
http://www.securityfocus.com/bid/26419 vtls-webgateway-xss(38444)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38444 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-5993