vendor:
Oracle Reports Server
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Oracle Reports Server
Affected Version From: Oracle Reports Server 9.0.2 with patchset 2
Affected Version To: Other versions may be affected as well.
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Multiple Remote Cross-Site Scripting Vulnerabilities in Oracle Reports Server
Multiple remote cross-site scripting vulnerabilities affect Oracle Reports Server. An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Mitigation:
Ensure that user-supplied input is properly sanitized before being used in the generation of web pages.