CVE-2009-4521
Eclipse BIRT <2.5.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Michele Orru · textwebappsjava
https://www.exploit-db.com/exploits/33286
References (7)
Scores
EPSS
0.0371
EPSS Percentile
87.8%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
eclipse/birt
< 2.3.2
n/a/n/a
Timeline
Published
Dec 31, 2009
Tracked Since
Feb 18, 2026