[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Reflected XSS vulnerability in SQL Server Report Manager

ID: oval:org.secpod.oval:def:7327Date: (C)2012-10-12   (M)2023-02-27
Class: VULNERABILITYFamily: windows




The host is installed with SQL Server 2000 Reporting Services Service or 2005 SP4 or 2008 SP2 or SP3 or 2008 R2 SP1 or 2012 and is prone to reflected XSS vulnerability. A flaw is present in the application, which fails to handle SQL Server Report Manager input parameters. Successful exploitation could allows an attacker to inject a client-side script into the user's instance of Internet Explorer.

Platform:
Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product:
Microsoft SQL Server 2000 Reporting Services
Microsoft SQL Server 2005
Microsoft SQL Server 2008
Microsoft SQL Server 2008 R2
Microsoft SQL Server 2012
Reference:
CVE-2012-2552
CVE    1
CVE-2012-2552
CPE    23
cpe:/a:microsoft:sql_server:2008:r2_sp1:itanium
cpe:/a:microsoft:sql_server:2005
cpe:/a:microsoft:sql_server:2008:sp2
cpe:/a:microsoft:sql_server:2008
...

© SecPod Technologies