|
Eclipse BIRT <= 2.2.1 Reflected XSS
Vendor: Eclipse
Advisory: http://antisnatchor.com/2008/12/18/eclipse-birt-reflected-xss/
Author: Michele "euronymous" Orr=F9 (euronymous AT antisnatchor DOT com)
Quite a common problem in a lot of Java based applications: reflected
XSS in Java stack trace.
A Reflected XSS is present in the _report parameter: here below the modified
request (that is the BIRT 2.2.1 version included in Konakart 2.2.6)
GET
/birt-viewer/run?__report='">