VYPR

Sierra

by Iii

CVEs (2)

  • CVE-2014-5137Sep 2, 2014
    risk 0.00cvss epss 0.00

    Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.

  • CVE-2014-5136Sep 2, 2014
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.