← Back

CVE-2008-1894

nvd nist
Published: Apr 18, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows remote attackers to inject arbitrary web script or HTML via the cms parameter.

Affected (7)

Infoview
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Businessobjects
Up to xi_r2
Up to xi_r2
Up to xi_r2
Up to xi_r2
Up to xi_r2
Version xi_r2 sp1
Version xi_r2 sp2

Timeline

No history available yet.