Microsoft SQL Server Reflected XSS Vulnerability
Last Update Date:
10 Oct 2012 15:45
Release Date:
10 Oct 2012
4503
Views
RISK: High Risk
TYPE: Servers - Database Servers
A reflected XSS vulnerability exists in SQL Server Report Manager that could allow an attacker to inject a client-side script into the user's instance of Internet Explorer. The script could spoof content, disclose information, or take any action that the user could take on the site on behalf of the targeted user.
Impact
- Elevation of Privilege
System / Technologies affected
- Microsoft SQL Server 2005
- Microsoft SQL Server 2008
- Microsoft SQL Server 2008 R2
- Microsoft SQL Server 2012
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/ms12-070
Vulnerability Identifier
Source
Related Link
Share with