CVE-2009-4521
Eclipse BIRT < 2.3.2 - Cross-Site Scripting via __report Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4521. PoCs published by Michele Orru.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Eclipse BIRT by injecting an iframe with JavaScript via the '__report' parameter. The vulnerability arises from insufficient input sanitization, allowing arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Eclipse BIRT by injecting an iframe with JavaScript via the '__report' parameter. The vulnerability arises from insufficient input sanitization, allowing arbitrary script execution in the context of the affected site.