Hitachi Multiple Products Unspecified Cross-Site Scripting Vulnerability
BID:38429
Info
Hitachi Multiple Products Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 38429 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2010 12:00AM |
| Updated: | Feb 26 2010 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Hitachi uCosminexus Portal Framework - Light 0 Hitachi uCosminexus Portal Framework 0 Hitachi uCosminexus Navigation Platform Authoring License 0 Hitachi uCosminexus Navigation Platform - User License 0 Hitachi uCosminexus Navigation Platform 0 Hitachi uCosminexus Navigation Developer 0 Hitachi uCosminexus Electronic Form Workflow QuickStart Ed 0 Hitachi uCosminexus Electronic Form Workflow HiRDB 0 Hitachi uCosminexus Content Manager 0 Hitachi uCosminexus Collaboration Portal Forum/File Share 0 Hitachi uCosminexus Collaboration Portal 0 Hitachi JP1/Integrated Management - Service Support 0 Hitachi Groupmax Collaboration Web Client Forum/File Share 0 Hitachi Groupmax Collaboration Web Client - Mail/Schedule 0 Hitachi Groupmax Collaboration Portal 0 Hitachi Electronic Form Workflow Set 0 Hitachi Electronic Form Workflow Developer Set 0 Hitachi Cosminexus Portal Framework - Light 0 Hitachi Cosminexus Portal Framework 0 Hitachi Cosminexus Collaboration Portal - Forum/File Share 0 Hitachi Cosminexus Collaboration Portal 0 |
| Not Vulnerable: | |
Discussion
Hitachi Multiple Products Unspecified Cross-Site Scripting Vulnerability
Multiple Hitachi products are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Multiple Hitachi products are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Hitachi Multiple Products Unspecified Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Hitachi Multiple Products Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the referenced advisory for details.
Solution:
The vendor has released an advisory and updates. Please see the referenced advisory for details.
References
Hitachi Multiple Products Unspecified Cross-Site Scripting Vulnerability
References:
References: