This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.
The remote Windows host contains a web control that could allow
The installed version of the Microsoft Report Viewer control fails to
properly validate parameters within a data source, which results in a
reflected (or non-persistent) cross-site scripting vulnerability.
If an attacker can trick a user into clicking on a link to a malicious
server, he could inject a client-side script in the user's browser
that in turn could be used to spoof content or disclose sensitive
See also :
Microsoft has released a set of patches for Microsoft Visual Studio
2005 SP1 and the Microsoft Report Viewer 2005 SP1 Redistributable
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.6
Public Exploit Available : true
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 55797 ()
Bugtraq ID: 49033
CVE ID: CVE-2011-1976
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.