Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
XSS code injection
ToK
Hi there,
I have a question regarding BIRT Viewer 4.2.2. There is a possibility to inject Code via the URL.
http://my.birtserver.local/birt-viewer/frameset?__report=./report/MyReport/new_report.rptdesign&__locale=de"><iframe
src="
http://malicious_server.com/malware.html"
; style="width:500px;height:200px">xss</iframe>
Any ideas how to cure this? The parameter __local is probably not checked.
Thank you & best regards
ToK
Find more posts tagged with
Comments
There are no comments yet