Hitachi GroupMax and UCosminexus Collaboration Portal Multiple Cross Site Scripting Vulnerabilities
BID:18830
CVE-2006-3574 |Info
Hitachi GroupMax and UCosminexus Collaboration Portal Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 18830 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2006 12:00AM |
| Updated: | Jul 05 2006 08:49PM |
| Credit: | These vulnerabilities were reported by the vendor. |
| Vulnerable: |
Hitachi uCosminexus Collaboration Portal 6.2 Hitachi Groupmax Collaboration Web Client 7.2 Hitachi Groupmax Collaboration Portal 7.2 |
| Not Vulnerable: | |
Discussion
Hitachi GroupMax and UCosminexus Collaboration Portal Multiple Cross Site Scripting Vulnerabilities
Hitachi Groupmax and uCosminexus Collaboration Portal Software are prone to multiple cross-site scripting vulnerabilities because they fail to sanitize input before displaying it to users.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Hitachi Groupmax and uCosminexus Collaboration Portal Software are prone to multiple cross-site scripting vulnerabilities because they fail to sanitize input before displaying it to users.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Hitachi GroupMax and UCosminexus Collaboration Portal Multiple Cross Site Scripting Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
Hitachi GroupMax and UCosminexus Collaboration Portal Multiple Cross Site Scripting Vulnerabilities
Solution:
Hitachi has released updates that address these issues. Please see the vendor advisory for additional information on affected versions and available updates.
Solution:
Hitachi has released updates that address these issues. Please see the vendor advisory for additional information on affected versions and available updates.
References
Hitachi GroupMax and UCosminexus Collaboration Portal Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Corrective Actions (Hitachi)
- Main Vendor Homepage (OWASP)
- Vendor Advisory (Hitachi)