Record summary

CVE-2018-16139 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site scripting (XSS) vulnerability in BIBLIOsoft BIBLIOpac 2008 allows remote attackers to inject arbitrary web script or HTML via the db or action parameter to to bin/wxis.exe/bibliopac/.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMBIBLIOsoft BIBLIOpac 2008 - Cross-Site ScriptingCVSS 6.1

BIBLIOsoft BIBLIOpac 2008 contains a cross-site scripting vulnerability via the db or action parameter to bin/wxis.exe/bibliopac/, which allows a remote attacker to inject arbitrary web script or HTML.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest patch or upgrade to a newer version of BIBLIOsoft BIBLIOpac 2008 that addresses the XSS vulnerability.

WeaknessesCWE-79
Authorsatomiczsec
Template tagscvecve2018xssbibliopacbibliosoftvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:bibliosoft:bibliopac:2008:*:*:*:*:*:*:*
Shodan: title:"Bibliopac"
Shodan: http.title:"bibliopac"
FOFA: title="bibliopac"
Google: intitle:"bibliopac"

Source: ProjectDiscovery

References

2