Full Disclosure mailing list archives
DOINGSOFT-2008-03-10-001 - XSS issue in BOXiR2
From: Sebastien gioria <seb () gioria org>
Date: Sun, 13 Apr 2008 23:30:32 +0200
Identification : DOINGSOFT-2008-03-10-001 CVE-ID : pending Discovery date : 14/12/2007 Correcting Date : 03/04/2008 How to get the patch : http://support.businessobjects.com/downloads/critical_hot_fixes/default.asp choose "FixPack 3.5" Publishing date : 14/04/2008 Product : Business Object Infoview XI R2 Java version Affected Version : XI R2, XI R2 SP1, XI R2 SP2, XI R2 SP3 Immunes Versions : Business Object Infoview XI R2 .Net version Vulnerability : Cross Site Scripting (XSS) Description : BOxiR2 is vulnerable of XSS attacks on the login URL via the CMS variable. With malicious utilization an attacker could get login/password and datas or reports. Example : http://www.monserveurBO.com/businessobjects/enterprise115/desktoplaunch/InfoView/logon/logon.object;jsessionid=7E1EFA4F83461F81157B67D7EA471A12?qryStr=&cmsVisible=true&authenticationVisible=true&referer=&refererFormData=&isFromLogonPage=true&cms=
%22%27><img%20src%3d%22javascript:alert(%27XSS%20Test%20Successful
%27)%22>" _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- DOINGSOFT-2008-03-10-001 - XSS issue in BOXiR2 Sebastien gioria (Apr 13)