SAP Crystal Reports Server Multiple Cross Site Scripting Vulnerabilities
BID:46855
Info
SAP Crystal Reports Server Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 46855 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2011 12:00AM |
| Updated: | Mar 14 2011 12:00AM |
| Credit: | Dmitriy Chastuhin, Digital Security Research Group |
| Vulnerable: |
SAP Crystal Reports Server 2008 0 |
| Not Vulnerable: | |
Discussion
SAP Crystal Reports Server Multiple Cross Site Scripting Vulnerabilities
SAP Crystal Reports Server is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
SAP Crystal Reports Server 2008 is vulnerable.
SAP Crystal Reports Server is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
SAP Crystal Reports Server 2008 is vulnerable.
Exploit / POC
SAP Crystal Reports Server Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
SAP Crystal Reports Server Multiple Cross Site Scripting Vulnerabilities
Solution:
Vendor patches are available. Please see the references for more information.
Solution:
Vendor patches are available. Please see the references for more information.
References
SAP Crystal Reports Server Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Crystal Reports Server Homepage (SAP)
- SAP Crystal Solutions (SAP)
- [DSECRG-11-011] SAP Crystal Reports 2008 - Multiple XSS (Digital Security )
- Acknowledgments to Security Researchers (SAP NetWeaver)