PT-2004-3389 · Hitachi · Web Page Generator Enterprise+1
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2497
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Hitachi Web Page Generator and Web Page Generator Enterprise version 4.01 and earlier
Description:
A cross-site scripting (XSS) issue exists in the error handler of the affected software. This occurs when the default error template is used and debug mode is set to ON, allowing remote attackers to inject arbitrary web script or HTML.
Recommendations:
For Hitachi Web Page Generator and Web Page Generator Enterprise version 4.01 and earlier, consider disabling debug mode to minimize the risk of exploitation. As a temporary workaround, modify the error template to prevent the injection of malicious scripts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hitachi Web Page Generator
Web Page Generator Enterprise