Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| 10g_reports_server | Oracle | 9.0.4.3.3 (including) | 9.0.4.3.3 (including) |