Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Business Objects Crystal Enterprise Report File Cross-Site Scripting Vulnerability

Business Objects Crystal Enterprise is prone to a cross-site scripting vulnerability.

An attacker could exploit this issue by enticing a user to following a malicious link to a Report (RPT) file. Malicious script embedded in the link could access properties of the vulnerable Crystal Enterprise site, allowing for various attacks such as theft of cookie-based authentication credentials.







 

Privacy Statement
Copyright 2009, SecurityFocus