Hitachi Products Multiple Cross-Site Scripting Vulnerabilities
BID:15498
Info
Hitachi Products Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 15498 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 2005 12:00AM |
| Updated: | Nov 18 2005 12:00AM |
| Credit: | The vendor disclosed these vulnerabilities. |
| Vulnerable: |
Hitachi Groupmax Collaboration Web FFS P-2746-E354 07-00 - 07-10-/A Hitachi Groupmax Collaboration Portal P-2646-6354 07-00 - 07-10-/B Hitachi Cosminexus Collaboration Portal P-2443-3D64 06-00 - 06-10-/B Hitachi Cosminexus Collaboration Portal FFS P-2443-3E64 06-00 - 06-10-/A |
| Not Vulnerable: |
Hitachi Groupmax Collaboration Web FFS P-2746-E354 07-00 - 07-10-/B Hitachi Groupmax Collaboration Portal P-2646-6354 07-00 - 07-10-/C Hitachi Cosminexus Collaboration Portal P-2443-3D64 06-00 - 06-10-/C Hitachi Cosminexus Collaboration Portal FFS P-2443-3E64 06-00 - 06-10-/B |
Discussion
Hitachi Products Multiple Cross-Site Scripting Vulnerabilities
Hitachi Collaboration Schedule and Collaboration Calendar are prone to multiple unspecified cross-site scripting vulnerabilities. These are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Hitachi Collaboration Schedule and Collaboration Calendar are prone to multiple unspecified cross-site scripting vulnerabilities. These are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
Hitachi Products Multiple Cross-Site Scripting Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Hitachi Products Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released fixes for these vulnerabilities; please contact your Hitachi representative for access to these fixes.
Solution:
The vendor has released fixes for these vulnerabilities; please contact your Hitachi representative for access to these fixes.
References
Hitachi Products Multiple Cross-Site Scripting Vulnerabilities
References:
References: