Cross-Site Scripting Vulnerability in Microsoft SQL Server Reporting Services
CVE-2012-2552
Currently unrated
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 9 October 2012
What is CVE-2012-2552?
A cross-site scripting (XSS) vulnerability exists in the SQL Server Report Manager of Microsoft SQL Server versions, which allows remote attackers to inject arbitrary web scripts or HTML through an unspecified parameter. This can potentially facilitate unauthorized access to sensitive information or user sessions, highlighting the critical importance of securing web applications against such vulnerabilities.