Short Name |
HTTP:XSS:MS-REPORT-MANAGER |
---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft SQL Server Report Manager Cross Site Scripting |
Release Date |
2012/10/08 |
Update Number |
2191 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known flaw in Microsoft SQL Server Report Manager. An information disclosure vulnerability exists in the Microsoft Report Viewer control due to the improper validation of parameters within a data source. An attacker who successfully exploited this vulnerability could inject a client-side script in the user's browser, resulting in arbitrary code execution with the privileges of the user's browser session.