Hitachi Web Page Generator Cross-Site Scripting and Information Disclosure Vulnerabilities
BID:10818
Info
Hitachi Web Page Generator Cross-Site Scripting and Information Disclosure Vulnerabilities
| Bugtraq ID: | 10818 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2004 12:00AM |
| Updated: | Jul 28 2004 12:00AM |
| Credit: | The vendor reported this vulnerability in an advisory. |
| Vulnerable: |
Hitachi Web Page Generator Enterprise 04-07-/A Hitachi Web Page Generator Enterprise 04-06-/C Hitachi Web Page Generator Enterprise 04-05 Hitachi Web Page Generator Enterprise 04-02-/L Hitachi Web Page Generator Enterprise 04-02-/K Hitachi Web Page Generator Enterprise 04-02 Hitachi Web Page Generator Enterprise 04-01-/B Hitachi Web Page Generator Enterprise 04-01 Hitachi Web Page Generator Enterprise 04-01 Hitachi Web Page Generator Enterprise 04-00-/C Hitachi Web Page Generator Enterprise 04-00 Hitachi Web Page Generator Enterprise 03-03-/D Hitachi Web Page Generator Enterprise 03-03-/C Hitachi Web Page Generator Enterprise 03-03 Hitachi Web Page Generator Enterprise 03-02-/C Hitachi Web Page Generator Enterprise 03-00 Hitachi Web Page Generator 02-00-/C Hitachi Web Page Generator 02-00 Hitachi Web Page Generator 01-00 Hitachi Web Page Generator 01-01-/C |
| Not Vulnerable: | |
Discussion
Hitachi Web Page Generator Cross-Site Scripting and Information Disclosure Vulnerabilities
It is reported that Web Page Generator contains a cross-site scripting vulnerability, and an information disclosure vulnerability.
The error transaction facility does not sufficiently sanitize user-supplied data, making it prone to cross-site scripting attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code. This would occur in the security context of the site hosting the software.
Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.
The error transaction facility, can also disclose information about an internal directory. This may assist an attacker with further compromise against the server.
These vulnerabilities are only present when the application is in debugging mode, (when 'DEBUG_MODE=on'), and the default error template is used.
It is reported that Web Page Generator contains a cross-site scripting vulnerability, and an information disclosure vulnerability.
The error transaction facility does not sufficiently sanitize user-supplied data, making it prone to cross-site scripting attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code. This would occur in the security context of the site hosting the software.
Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.
The error transaction facility, can also disclose information about an internal directory. This may assist an attacker with further compromise against the server.
These vulnerabilities are only present when the application is in debugging mode, (when 'DEBUG_MODE=on'), and the default error template is used.
Exploit / POC
Hitachi Web Page Generator Cross-Site Scripting and Information Disclosure Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Hitachi Web Page Generator Cross-Site Scripting and Information Disclosure Vulnerabilities
Solution:
The vendor has released a security advisory addressing these issues. Please see the referenced advisory for further information.
Solution:
The vendor has released a security advisory addressing these issues. Please see the referenced advisory for further information.
References
Hitachi Web Page Generator Cross-Site Scripting and Information Disclosure Vulnerabilities
References:
References: