JP1/HiCommand Series Products Cross-Site Scripting Vulnerability
BID:24797
Info
JP1/HiCommand Series Products Cross-Site Scripting Vulnerability
| Bugtraq ID: | 24797 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3623 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Hitachi JP1/HiCommand Tiered Storage Manager 5.5 Hitachi JP1/HiCommand Tiered Storage Manager 4.0 Hitachi JP1/HiCommand Replication Monitor 05-50 Hitachi JP1/HiCommand Replication Monitor 05-00 Hitachi JP1/HiCommand Replication Monitor 04-00 Hitachi JP1/HiCommand GlobalLink Availability Manager 05-00 Hitachi JP1/Hi Command Tiered Storage Manager (Solaris) 4.3 Hitachi JP1/Hi Command Device Manager 05.50 Hitachi JP1/Hi Command Device Manager 02.30 |
| Not Vulnerable: | |
Discussion
JP1/HiCommand Series Products Cross-Site Scripting Vulnerability
JP1/HiCommand Series Products are prone to a cross-site scripting vulnerability because the software fails to sufficiently sanitize user-supplied data.
A remote attacker may exploit this issue to execute arbitrary script code in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
JP1/HiCommand Series Products are prone to a cross-site scripting vulnerability because the software fails to sufficiently sanitize user-supplied data.
A remote attacker may exploit this issue to execute arbitrary script code in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
JP1/HiCommand Series Products Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
JP1/HiCommand Series Products Cross-Site Scripting Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
References
JP1/HiCommand Series Products Cross-Site Scripting Vulnerability
References:
References: