CVE-2011-1976
Summary
| CVE | CVE-2011-1976 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-08-10 21:55:00 UTC |
| Updated | 2018-10-12 22:01:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability." |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Report Viewer | 2005 | sp1 | All | All |
| Application | Microsoft | Report Viewer | 2005 | sp1 | redistributable_package | All |
| Application | Microsoft | Report Viewer | 2005 | sp1 | All | All |
| Application | Microsoft | Report Viewer | 2005 | sp1 | redistributable_package | All |
| Application | Microsoft | Visual Studio | 2005 | sp1 | All | All |
| Application | Microsoft | Visual Studio | 2005 | sp1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Document Display | HPE Support Center | CONFIRM | h20566.www2.hpe.com | Third Party Advisory |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| '[security bulletin] HPSBGN03534 rev.1 - HPE Performance Center using Microsoft Report Viewer, Remote' - MARC | HP | marc.info | Third Party Advisory |
| US-CERT Technical Cyber Security Alert TA11-221A -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Microsoft Security Bulletin MS11-067 - Important | Microsoft Docs | MS | docs.microsoft.com | |
| Microsoft Visual Studio Report Viewer Control Multiple Cross Site Scripting Vulnerabilities | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.