1 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter. Existe Cross-Site Scripting (XSS) en Ericsson Active Library Explorer (ALEX) 14.3 en múltiples parámetros en el servlet "/cgi-bin/alexserv", tal y como queda demostrado con los parámetros DB, FN, fn o id. Ericsson Active Library Explorer (ALEX) version 14.3 suffers from a cross site scripting vulnerability. • http://packetstormsecurity.com/files/151583/Ericsson-Active-Library-Explorer-ALEX-14.3-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2019/Feb/27 http://www.ericsson.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •