{"api_version":"1","generated_at":"2026-07-23T05:40:30+00:00","cve":"CVE-2004-2497","urls":{"html":"https://cve.report/CVE-2004-2497","api":"https://cve.report/api/cve/CVE-2004-2497.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2497","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2497"},"summary":{"title":"CVE-2004-2497","description":"Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/10818","name":"http://www.securityfocus.com/bid/10818","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Hitachi Web Page Generator Cross-Site Scripting and Information Disclosure Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/12150","name":"http://secunia.com/advisories/12150","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Hitachi Web Page Generator Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16822","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16822","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.hitachi-support.com/security_e/vuls_e/HS04-003_e/index-e.html","name":"http://www.hitachi-support.com/security_e/vuls_e/HS04-003_e/index-e.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HITACHI : HS04-003 : Vulnerability Information","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/8264","name":"http://www.osvdb.org/8264","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2497","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2497","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator","cpe6":"01_00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator","cpe6":"01_01_c","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator","cpe6":"02_00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator","cpe6":"02_00_c","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"03_00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"03_02_c","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"03_03","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"03_03_c","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"03_03_d","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"04_00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"04_00_c","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"04_01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"web_page_generator_enterprise","cpe6":"04_01_b","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:29:13.677Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"10818","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10818"},{"name":"12150","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12150"},{"name":"8264","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/8264"},{"name":"web-page-generator-xss(16822)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16822"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.hitachi-support.com/security_e/vuls_e/HS04-003_e/index-e.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-07-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"10818","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10818"},{"name":"12150","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12150"},{"name":"8264","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/8264"},{"name":"web-page-generator-xss(16822)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16822"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.hitachi-support.com/security_e/vuls_e/HS04-003_e/index-e.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2497","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"10818","refsource":"BID","url":"http://www.securityfocus.com/bid/10818"},{"name":"12150","refsource":"SECUNIA","url":"http://secunia.com/advisories/12150"},{"name":"8264","refsource":"OSVDB","url":"http://www.osvdb.org/8264"},{"name":"web-page-generator-xss(16822)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16822"},{"name":"http://www.hitachi-support.com/security_e/vuls_e/HS04-003_e/index-e.html","refsource":"CONFIRM","url":"http://www.hitachi-support.com/security_e/vuls_e/HS04-003_e/index-e.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2497","datePublished":"2005-10-25T04:00:00.000Z","dateReserved":"2005-10-25T00:00:00.000Z","dateUpdated":"2024-08-08T01:29:13.677Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator:01_00:*:*:*:*:*:*:*","matchCriteriaId":"C09F98F2-D33A-4257-86EC-5DE0A9AF8D5E"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator:01_01_c:*:*:*:*:*:*:*","matchCriteriaId":"70CC5E83-D324-4659-85E6-7F77830817F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator:02_00:*:*:*:*:*:*:*","matchCriteriaId":"122CE2A2-646F-43D0-AE11-9533D0338F23"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator:02_00_c:*:*:*:*:*:*:*","matchCriteriaId":"26642E32-CFB8-42CD-BE5E-7A454F303440"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:03_00:*:*:*:*:*:*:*","matchCriteriaId":"21B3F6B6-A108-44E7-9007-40503A8273D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:03_02_c:*:*:*:*:*:*:*","matchCriteriaId":"98ACE5A9-3665-45B4-B5FF-AE0E8D6DE4FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:03_03:*:*:*:*:*:*:*","matchCriteriaId":"B56FE773-2894-4C58-A671-937308BBC8A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:03_03_c:*:*:*:*:*:*:*","matchCriteriaId":"F8E93487-85C4-4A82-84AF-E03D261E7A90"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:03_03_d:*:*:*:*:*:*:*","matchCriteriaId":"AF79AEA8-F780-48A2-BCEE-6EF0B1C4EDB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:04_00:*:*:*:*:*:*:*","matchCriteriaId":"4E907D7F-F545-4B19-82C8-D3FBD2985BF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:04_00_c:*:*:*:*:*:*:*","matchCriteriaId":"84FFC74E-3FD4-4E72-84CE-B84F1AB5A2F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:04_01:*:*:*:*:*:*:*","matchCriteriaId":"6B3C2E2D-FA85-406D-816C-CB668142C72A"},{"vulnerable":true,"criteria":"cpe:2.3:a:hitachi:web_page_generator_enterprise:04_01_b:*:*:*:*:*:*:*","matchCriteriaId":"28656ACA-6C42-439B-B172-697353530C89"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2497","Ordinal":"1","Title":"CVE-2004-2497","CVE":"CVE-2004-2497","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2497","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.","Type":"Description","Title":"CVE-2004-2497"},{"CveYear":"2004","CveId":"2497","Ordinal":"2","NoteData":"2005-10-25","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2497","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}