PT-2004-3389 · Hitachi · Web Page Generator Enterprise+1

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2497

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Hitachi Web Page Generator and Web Page Generator Enterprise version 4.01 and earlier
Description: A cross-site scripting (XSS) issue exists in the error handler of the affected software. This occurs when the default error template is used and debug mode is set to ON, allowing remote attackers to inject arbitrary web script or HTML.
Recommendations: For Hitachi Web Page Generator and Web Page Generator Enterprise version 4.01 and earlier, consider disabling debug mode to minimize the risk of exploitation. As a temporary workaround, modify the error template to prevent the injection of malicious scripts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2497

Affected Products

Hitachi Web Page Generator
Web Page Generator Enterprise