This script is Copyright (C) 2012-2016 Tenable Network Security, Inc.
A cross-site scripting vulnerability in SQL Server could allow
elevation of privilege.
The remote host has a version of Microsoft SQL Server installed. This
version of SQL Server is running SQL Server Reporting Services (SRSS),
that is affected by a cross-site scripting (XSS) vulnerability that
could allow elevation of privileges. Successful exploitation could
allow an attacker to execute arbitrary commands on the SSRS site in
the context of the targeted user. An attacker would need to entice a
user to visit a specially crafted link in order to exploit the
See also :
Microsoft has released a set of patches for SQL Server 2000, 2005,
2008, 2008 R2, and 2012.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : true
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 62465 ()
Bugtraq ID: 55783
CVE ID: CVE-2012-2552
Upgrade to Nessus Professional today!
Start your free Nessus Cloud trial now!
Begin Free Trial
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.