CVE Database
/

CVE-2011-1660

Back to search

CVE-2011-1660

Published: Apr 10, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in the DataDynamics.Reports.Web class library in GrapeCity Data Dynamics Reports before 1.6.2084.14 allow remote attackers to inject arbitrary web script or HTML via (1) the reportName or (2) uniqueId parameter to CoreViewerInit.js, or the (3) uniqueId or (4) traceLevel parameter to CoreController.js, as reachable by CoreHandler.ashx.

VendorProductVersions

n/a

n/a

affected
n/a

References

43953
third-party-advisory
x_refsource_SECUNIA
71488
vdb-entry
x_refsource_OSVDB
8190
third-party-advisory
x_refsource_SREASON
ddr-corehandler-xss(66545)
vdb-entry
x_refsource_XF
47015
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now