Cybertrion Systems

[2/5] Hitachi Cosminexus Products JavaDoc Cross-Site Scripting

September 3rd, 2007 by
[2/5] Hitachi Cosminexus Products JavaDoc Cross-Site Scripting

:A vulnerability has been reported in various Hitachi Cosminexus products, which can be exploited by malicious people to conduct cross-site scripting attacks.The vulnerability is caused due to an error within the javadoc command of the Cosminexus Developer’s Kit for Java component when generating HTML documentation pages and can potentially be exploited to conduct cross-site scripting attacks on a website that hosts the generated documentation.See the vendor’s advisory for a list of affected products.The vulnerability may be related to:SA25769Solution:Update to a fixed version. See the vendor’s advisory for details or contact a Hitachi support service representative.Provided and/or discovered by:Reported by the vendor. Reported in Sun JDK JavaDoc by Martin Straka.Original Advisory:http://www.hitachi-support.com/security_e/vuls_e/HS07-027_e/index-e.htmlOther References:SA25769:http://secunia.com/advisories/25769/

Original post by manisha

[2/5] Hitachi Cosminexus Products JavaDoc Cross-Site Scripting

Related Articles:
  • [4/5] Hitachi Cosminexus Products DoS and Buffer Overflow Vulnerabilities
  • [2/5] Hitachi Cosminexus Agent Unspecified Denial of Service Vulnerability
  • [2/5] Hitachi Products Cosminexus Component Container Improper Session Data Handling
  • [3/5] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service
  • [1/5] Hitachi Cosminexus Application Server Incorrect Handling of Group Permissions


  • Posted in Advisories - Exploits | | [2/5] Hitachi Cosminexus Products JavaDoc Cross-Site Scripting

    << [2/5] Debian update for id3lib3.8.3 | [3/5] Debian update for vim >>