CVE-2014-3719

CRITICAL

Ex Libris ALEPH 500 18.1 and 20 - SQL Injection via find lib or sid Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to execute arbitrary SQL commands via the (1) find, (2) lib, or (3) sid parameter.

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/126635/Aleph-500-SQL-Injection.html
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2014/May/65

Scores

CVSS v3 9.8
EPSS 0.0199
EPSS Percentile 78.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
exlibrisgroup/aleph_500 18.1
exlibrisgroup/aleph_500 20.0
Published Jan 30, 2020
Tracked Since Feb 18, 2026