CVE-2011-1976
Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 20.81% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/report viewer · microsoft/visual studio
- Source
- secure@microsoft.com
References
- http://marc.info/?l=bugtraq&m=145326307707460&w=2Third Party Advisory
- http://www.securityfocus.com/bid/49033
- http://www.us-cert.gov/cas/techalerts/TA11-221A.htmlThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-067
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04945270Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12773
- http://marc.info/?l=bugtraq&m=145326307707460&w=2Third Party Advisory
- http://www.securityfocus.com/bid/49033
- http://www.us-cert.gov/cas/techalerts/TA11-221A.htmlThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-067
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04945270Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12773
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.