Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same parameter, which allows remote attackers to bypass parameter validation via unspecified vectors, possibly related to the Webpac Pro submodule.
References
Link | Resource |
---|---|
https://packetstormsecurity.com/files/128053/Sierra-Library-Services-Platform-1.2_3-XSS-Enumeration.html | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2020-01-14 16:15
Updated : 2024-02-04 20:39
NVD link : CVE-2014-5138
Mitre link : CVE-2014-5138
CVE.ORG link : CVE-2014-5138
JSON object : View
Products Affected
iii
- sierra
CWE