4.3
CVE-2004-2497
- EPSS 0.46%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Data is provided by the National Vulnerability Database (NVD)
Hitachi ≫ Web Page Generator Version01_00
Hitachi ≫ Web Page Generator Version01_01_c
Hitachi ≫ Web Page Generator Version02_00
Hitachi ≫ Web Page Generator Version02_00_c
Hitachi ≫ Web Page Generator Enterprise Version03_00
Hitachi ≫ Web Page Generator Enterprise Version03_02_c
Hitachi ≫ Web Page Generator Enterprise Version03_03
Hitachi ≫ Web Page Generator Enterprise Version03_03_c
Hitachi ≫ Web Page Generator Enterprise Version03_03_d
Hitachi ≫ Web Page Generator Enterprise Version04_00
Hitachi ≫ Web Page Generator Enterprise Version04_00_c
Hitachi ≫ Web Page Generator Enterprise Version04_01
Hitachi ≫ Web Page Generator Enterprise Version04_01_b
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.46% | 0.614 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|