CVE-2008-1894
BusinessObjects InfoView XI <FixPack 3.5 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows remote attackers to inject arbitrary web script or HTML via the cms parameter.
References (7)
Scores
EPSS
0.0053
EPSS Percentile
66.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (7)
businessobjects/infoview
< xi_r2
businessobjects/infoview
< xi_r2
businessobjects/infoview
< xi_r2
businessobjects/infoview
< xi_r2
businessobjects/infoview
< xi_r2
businessobjects/infoview
businessobjects/infoview
Timeline
Published
Apr 18, 2008
Tracked Since
Feb 18, 2026