SAP Crystal Report Server 2008 'pubDBLogon.jsp' Cross Site Scripting Vulnerability
BID:49656
Info
SAP Crystal Report Server 2008 'pubDBLogon.jsp' Cross Site Scripting Vulnerability
| Bugtraq ID: | 49656 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4805 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2011 12:00AM |
| Updated: | Dec 15 2011 07:38PM |
| Credit: | Dmitriy Chastuchin, Digital Security Research Group |
| Vulnerable: |
SAP Crystal Reports Server 2008 0 |
| Not Vulnerable: | |
Discussion
SAP Crystal Report Server 2008 'pubDBLogon.jsp' Cross Site Scripting Vulnerability
SAP Crystal Report Server 2008 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker could leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.
SAP Crystal Report Server 2008 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker could leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
SAP Crystal Report Server 2008 'pubDBLogon.jsp' Cross Site Scripting Vulnerability
To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
SAP Crystal Report Server 2008 'pubDBLogon.jsp' Cross Site Scripting Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
SAP Crystal Report Server 2008 'pubDBLogon.jsp' Cross Site Scripting Vulnerability
References:
References:
- [DSECRG-11-033] SAP Crystal Report Server pubDBLogon - Linked ?SS vulnerability (Digital Security Research Group)
- SAP Crystal Reports Homepage (SAP)
- SAP Security Note 1562292 (SAP)