cross-site scripting (XSS) nel visualizzatore di report in Crystal Enterprise 8.5, 9, e 10 consente agli aggressori remoti di inserire lo script Web arbitrario o HTML tramite script nella URL di un file di report (RPT). |
http://www.securityfocus.com/bid/12107 http://support.businessobjects.com/library/kbase/articles/c2016559.asp http://www.osvdb.org/12596 http://securitytracker.com/id?1012703 http://secunia.com/advisories/13644 https://exchange.xforce.ibmcloud.com/vulnerabilities/18684 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2742 |
Vulnerabilità: CVE-2004-2742
