CVE Vulnerabilities

CVE-2004-2497

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

Affected Software

NameVendorStart VersionEnd Version
Web_page_generatorHitachi01_00 (including)01_00 (including)
Web_page_generatorHitachi01_01_c (including)01_01_c (including)
Web_page_generatorHitachi02_00 (including)02_00 (including)
Web_page_generatorHitachi02_00_c (including)02_00_c (including)
Web_page_generator_enterpriseHitachi03_00 (including)03_00 (including)
Web_page_generator_enterpriseHitachi03_02_c (including)03_02_c (including)
Web_page_generator_enterpriseHitachi03_03 (including)03_03 (including)
Web_page_generator_enterpriseHitachi03_03_c (including)03_03_c (including)
Web_page_generator_enterpriseHitachi03_03_d (including)03_03_d (including)
Web_page_generator_enterpriseHitachi04_00 (including)04_00 (including)
Web_page_generator_enterpriseHitachi04_00_c (including)04_00_c (including)
Web_page_generator_enterpriseHitachi04_01 (including)04_01 (including)
Web_page_generator_enterpriseHitachi04_01_b (including)04_01_b (including)

References