Microsoft SQL Server Report Manager CVE-2012-2552 Cross Site Scripting Vulnerability
BID:55783
Info
Microsoft SQL Server Report Manager CVE-2012-2552 Cross Site Scripting Vulnerability
| Bugtraq ID: | 55783 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2552 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2012 12:00AM |
| Updated: | Sep 07 2017 01:13PM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft SQL Server 2012 for x64-based Systems 0 Microsoft SQL Server 2012 for 32-bit Systems 0 Microsoft SQL Server 2008 x64 SP3 Microsoft SQL Server 2008 x64 SP2 Microsoft SQL Server 2008 R2 for x64-based Systems SP1 0 Microsoft SQL Server 2008 R2 for Itanium-based Systems SP1 0 Microsoft SQL Server 2008 R2 for 32-bit Systems SP1 0 Microsoft SQL Server 2008 itanium SP3 Microsoft SQL Server 2008 itanium SP2 Microsoft SQL Server 2008 32bit SP3 Microsoft SQL Server 2008 32bit SP2 Microsoft SQL Server 2005 x64 Edition SP4 Microsoft SQL Server 2005 Itanium Edition SP4 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP4 Microsoft SQL Server 2005 32-bit SP4 0 Microsoft SQL Server 2000 SP2 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server Report Manager CVE-2012-2552 Cross Site Scripting Vulnerability
Microsoft SQL Server is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
Microsoft SQL Server is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
Exploit / POC
Microsoft SQL Server Report Manager CVE-2012-2552 Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Microsoft SQL Server Report Manager CVE-2012-2552 Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Microsoft SQL Server Report Manager CVE-2012-2552 Cross Site Scripting Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft SQL Server Homepage (Microsoft)
- Microsoft Security Bulletin MS12-070 (Microsoft)