CVE-2007-6608 | OpenBiblio up to 0.5.2 Pre4 staff_del_confirm.php themeName cross site scripting (EDB-30948 / XFDB-39297)
A vulnerability was found in OpenBiblio up to 0.5.2 Pre4. It has been declared as problematic. This affects an unknown function of the file staff_del_confirm.php. Executing manipulation of the argument themeName can lead to cross site scripting.
This vulnerability is tracked as CVE-2007-6608. The attack can be launched remotely. Moreover, an exploit is present.