Hitachi Cosminexus Javadoc Command Cross-Site Scripting Vulnerability
BID:25518
Info
Hitachi Cosminexus Javadoc Command Cross-Site Scripting Vulnerability
| Bugtraq ID: | 25518 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4760 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Hitachi uCosminexus Service Platform 07-50 (Windows) Hitachi uCosminexus Service Platform 07-20-01 (Windows) Hitachi uCosminexus Service Platform 07-20 (Windows) Hitachi uCosminexus Service Platform 07-10-01 (Windows) Hitachi uCosminexus Service Platform 07-10 (Windows) Hitachi uCosminexus Service Platform 07-10 (Linux) Hitachi uCosminexus Service Platform 07-00-03 (Windows) Hitachi uCosminexus Service Platform 07-00 (Windows) Hitachi uCosminexus Service Platform 07-00 (Linux) Hitachi uCosminexus Service Architect 07-50 (Windows) Hitachi uCosminexus Service Architect 07-20-01 (Windows) Hitachi uCosminexus Service Architect 07-20 (Windows) Hitachi uCosminexus Service Architect 07-10-01 (Windows) Hitachi uCosminexus Service Architect 07-10 (Windows) Hitachi uCosminexus Service Architect 07-00-03 (Windows) Hitachi uCosminexus Service Architect 07-00 (Windows) Hitachi uCosminexus Operator 07-50 (Windows) Hitachi uCosminexus Operator 07-20-01 (Windows) Hitachi uCosminexus Operator 07-20 (Windows) Hitachi uCosminexus Operator 07-10-01 (Windows) Hitachi uCosminexus Operator 07-10 (Windows) Hitachi uCosminexus Operator 07-00-03 (Windows) Hitachi uCosminexus Operator 07-00 (Windows) Hitachi uCosminexus Developer 07-50 (Windows) Hitachi uCosminexus Developer 07-20-01 (Windows) Hitachi uCosminexus Developer 07-20 (Windows) Hitachi uCosminexus Developer 07-10-01 (Windows) Hitachi uCosminexus Developer 07-10 (Windows) Hitachi uCosminexus Developer 07-00-03 (Windows) Hitachi uCosminexus Developer 07-00 (Windows) Hitachi uCosminexus Application Server 07-50 (Windows) Hitachi uCosminexus Application Server 07-20-01 (Windows) Hitachi uCosminexus Application Server 07-20 (Windows) Hitachi uCosminexus Application Server 07-10-01 (Windows) Hitachi uCosminexus Application Server 07-10-01 (Linux(IPF) Hitachi uCosminexus Application Server 07-10-01 (HP-UX(IPF) Hitachi uCosminexus Application Server 07-10 (Windows) Hitachi uCosminexus Application Server 07-10 (Linux) Hitachi uCosminexus Application Server 07-10 (Linux(IPF)) Hitachi uCosminexus Application Server 07-10 (HP-UX) Hitachi uCosminexus Application Server 07-10 (HP-UX(IPF)) Hitachi uCosminexus Application Server 07-00-03 (Windows) Hitachi uCosminexus Application Server 07-00-01 (Solaris) Hitachi uCosminexus Application Server 07-00-01 (Linux) Hitachi uCosminexus Application Server 07-00 (Windows) Hitachi uCosminexus Application Server 07-00 (Solaris) Hitachi uCosminexus Application Server 07-00 (Linux) Hitachi uCosminexus Application Server 07-00 (HP-UX(IPF)) Hitachi uCosminexus Application Server 07-00 (AIX) Hitachi Electronic Form Workflow 07-11-/A (Windows) Hitachi Electronic Form Workflow 07-11 (Windows) Hitachi Electronic Form Workflow 07-10-/A (Linux) Hitachi Electronic Form Workflow 07-10 (Windows) Hitachi Electronic Form Workflow 07-10 (Linux) Hitachi Electronic Form Workflow 07-00-12 (Linux) Hitachi Electronic Form Workflow 07-00-/B (Windows) Hitachi Electronic Form Workflow 07-00 (Windows) |
| Not Vulnerable: |
Hitachi uCosminexus Service Platform 07-50-01 (Windows) Hitachi uCosminexus Service Architect 07-50-01 (Windows) Hitachi uCosminexus Operator 07-50-01 (Windows) Hitachi uCosminexus Developer 07-50-01 (Windows) Hitachi uCosminexus Application Server 07-50-01 (Windows) Hitachi uCosminexus Application Server 07-00-03 (Linux) Hitachi uCosminexus Application Server 07-00-03 (AIX) Hitachi Electronic Form Workflow 07-00-03 (Linux) |
Discussion
Hitachi Cosminexus Javadoc Command Cross-Site Scripting Vulnerability
Hitachi Cosminexus is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Hitachi Cosminexus is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Hitachi Cosminexus Javadoc Command Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Hitachi Cosminexus Javadoc Command Cross-Site Scripting Vulnerability
Solution:
The vendor released updates to address this issue. Please see the referenced advisory for more information.
Solution:
The vendor released updates to address this issue. Please see the referenced advisory for more information.
References
Hitachi Cosminexus Javadoc Command Cross-Site Scripting Vulnerability
References:
References: