what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Eclipse Birt Report Viewer 4.5.0 Cross Site Scripting

Eclipse Birt Report Viewer 4.5.0 Cross Site Scripting
Posted Jan 27, 2016

Eclipse Birt Report Viewer versions 4.5.0 and below suffer from a persistent cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 69a4754bb354b6494f39716677edb9890c7c5c0beb35f24950e1109deed68f22

Eclipse Birt Report Viewer 4.5.0 Cross Site Scripting

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

#Title: Eclipse Birt Report Viewer v4.5.0 and below Persistent XSS
#Vendor homepage: http://www.eclipse.org
#Exploit Author: Multiple parties reported to vendor. (first in 2008!)
#Vulnerability: Presistent XSS when viewing report with malicious code


Description:
When previewing a generated report in the document viewer, the report
viewer fails to sanitize the report data pulled from a database and will
execute javascript and other code. the vendor has been notified by
multiple parties, but there has been no activity on the issue.
Based on other similar bug tickets on the issue tracker. Please refer to
the eclipse bug tracker page tickets below for additional information.
this has been an issue since version 2.2.2 at least:
https://bugs.eclipse.org/bugs/show_bug.cgi?id=233219
https://bugs.eclipse.org/bugs/show_bug.cgi?id=484952
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJWo75oAAoJEGoTpzhfiAPx7HwP/1jrw7Pcy//Tj1YwRGhb6SZ4
/JyV4GBsTNzXFRgk3S8uvE8txJ0m/TlK7tnJ5HkXS5yGoEvxFjTwtauwrBF7ZGQN
gZDKW5i55sKRWW3PKuLC3yf9czD/u7fzcEecYFx9XiiMY0lvPFoNMsCT3tu9cKZj
Xt6jx1KBdBYtK7avBU8y/8FUnmwUX0GPOd5xij1uaxw5CWhRQ4hqy38D7VZSv1X5
iJfTzVVoOkEievtejA1sOnjfd9NAKYizjIaOB0utpKexY2X9xDQXPSZUSSiyBKpC
bF7i+5XkzKxxPpI6OpK15Na3lSkslHyzjacaPYabwMB1p8+YMnlC0JBw0lJpaK5Z
yyFbenCg/LSmHl5RYxtyScnQIT8wXNXw1sscIiFtdf2esFZcpAjfxvKOPCDkDuvK
EvNSUyBlYE92gjov9dChN4nIFT1kKczyynH6bFieNJm/VrshMJIElz+uHi+zIVTz
X03qnaEF4zLHGc28iFQ/t2QLtmhSch+UH5Wb5Gy5WrJ0XmvId8E88AdyGuVk2dQI
y6jwQUCnoSf44fYYQpthwDeG8X0byGuxeXQAXiUPMjQ8rC37k00kJArjIrVcYIfg
HC3z+UrxOpna1Ed7/Nq6qzMNPSnDBTn5oODMx64aSBCnC4dSluWRDWmiJ7DHPwPe
Rt3YDLY9syVRED/slOvd
=h200
-----END PGP SIGNATURE-----




Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    0 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close