Hitachi Groupmax World Wide Web Desktop Unspecified Cross Site Scripting Vulnerability
BID:41028
Info
Hitachi Groupmax World Wide Web Desktop Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 41028 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2010 12:00AM |
| Updated: | Jul 30 2010 06:15PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Hitachi Workflow Server Set Light 0 Hitachi WorkFlow Server Set 06-52-/R Hitachi WorkFlow Server Set 06-52-/Q Hitachi Scheduler Server Set 06-52-/S Hitachi Scheduler Server Set 06-52-/R Hitachi Scheduler Server Set 06-52 Hitachi Scheduler Server Set 0 Hitachi Mail Server Set 06-52-/R Hitachi Mail Server Set 06-52-/Q Hitachi Mail Server Set 06-52 Hitachi Groupware Server Set 06-52-/S Hitachi Groupware Server Set 0 Hitachi Groupmax World Wide Web Desktop Version 6 06-52-/L Hitachi Groupmax World Wide Web Desktop Version 6 06-52-/K Hitachi Groupmax World Wide Web Desktop Version 6 06-52 Hitachi Groupmax World Wide Web Desktop for Jichitai 06-52-/I Hitachi Groupmax World Wide Web Desktop for Jichitai 06-52-/H Hitachi Groupmax World Wide Web Desktop for Jichitai 06-52-/A Hitachi Groupmax World Wide Web Desktop for Jichitai 06-52 Hitachi Groupmax World Wide Web Desktop for Jichitai 06-51 Hitachi Groupmax World Wide Web Desktop 06-52-/F Hitachi Groupmax World Wide Web Desktop 06-52-/E Hitachi Groupmax World Wide Web Desktop 06-52-/C Hitachi Groupmax World Wide Web Desktop 06-52-/B Hitachi Groupmax World Wide Web Desktop 06-52 Hitachi Groupmax World Wide Web Desktop 06-51-/C Hitachi Groupmax World Wide Web Desktop 06-51-/B Hitachi Groupmax World Wide Web Desktop 06-51 Hitachi Groupmax World Wide Web Desktop 06-50-/C Hitachi Groupmax World Wide Web Desktop 06-50-/B Hitachi Groupmax World Wide Web Desktop 06-00 Hitachi Groupmax World Wide Web Desktop 05-11-/J Hitachi Groupmax World Wide Web Desktop 05-11-/I Hitachi Groupmax World Wide Web Desktop 05-11-/F Hitachi Groupmax World Wide Web Desktop 05-00 Hitachi Groupmax Workflow Web Client 07-00-/J Hitachi Groupmax Workflow Web Client 07-00-/I Hitachi Groupmax Workflow Web Client 07-00 Hitachi Groupmax Workflow Web Client 0 Hitachi Groupmax Workflow Client 07-60-/A Hitachi Groupmax Workflow Client 07-00-/M Hitachi Groupmax Workflow Client 07-00-/H Hitachi Groupmax Workflow Client 07-00 Hitachi Groupmax Workflow Client 0 Hitachi Groupmax Server Set 06-52-/T Hitachi Groupmax Server Set 06-52 Hitachi Groupmax Server Set 0 Hitachi Groupmax Groupware Web Client 07-60-/A Hitachi Groupmax Groupware Web Client 0 Hitachi Groupmax Groupware Client 07-62 Hitachi Groupmax Groupware Client 07-00-/O Hitachi Groupmax Groupware Client 07-00 Hitachi Groupmax Groupware Client 0 Hitachi Document Manager Server Set 06-52-/Q Hitachi Document Manager Server Set 06-52-/P Hitachi Document Manager Server Set 06-52 Hitachi Workflow Server Set 06-52 |
| Not Vulnerable: | |
Discussion
Hitachi Groupmax World Wide Web Desktop Unspecified Cross Site Scripting Vulnerability
Multiple Groupmax World Wide Web Desktop products are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Multiple Groupmax World Wide Web Desktop products are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Hitachi Groupmax World Wide Web Desktop Unspecified Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Solution / Fix
Hitachi Groupmax World Wide Web Desktop Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Hitachi Groupmax World Wide Web Desktop Unspecified Cross Site Scripting Vulnerability
References:
References: