SAP Web Application Server Cross-Site Scripting Vulnerability - Advisories - Secunia

ripjyr2008-05-22

SAPのWeb Application Serverにおいて、クロスサイトスクリプティング脆弱性が存在するそうです。

Input passed via the URL to the sap/bc/gui/sap/its/webgui/ is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
The vulnerability is reported in the SAP software components SAP_BASIS 640, 700, 701, and 710.

screenshot