Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Internet_graphics_server | Sap | 6.40 (including) | 6.40 (including) |
Internet_graphics_server | Sap | 6.40_patch_11 (including) | 6.40_patch_11 (including) |
Internet_graphics_server | Sap | 6.40_patch_12 (including) | 6.40_patch_12 (including) |
Internet_graphics_server | Sap | 6.40_patch_13 (including) | 6.40_patch_13 (including) |
Internet_graphics_server | Sap | 6.40_patch_14 (including) | 6.40_patch_14 (including) |
Internet_graphics_server | Sap | 6.40_patch_15 (including) | 6.40_patch_15 (including) |
Internet_graphics_server | Sap | 7.00_patch_1 (including) | 7.00_patch_1 (including) |
Internet_graphics_server | Sap | 7.00_patch_2 (including) | 7.00_patch_2 (including) |
Internet_graphics_server | Sap | 7.00_patch_3 (including) | 7.00_patch_3 (including) |