4.3

CVE-2007-4760

The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this is probably the same issue as CVE-2007-3503.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HitachiUcosminexus Application Server Enterprise Version07_00 Editionhpux_ipf
HitachiUcosminexus Application Server Enterprise Version07_00 Editionlinux
HitachiUcosminexus Application Server Enterprise Version07_00 Editionsolaris
HitachiUcosminexus Application Server Enterprise Version07_00 Editionwindows
HitachiUcosminexus Application Server Enterprise Version07_00_01 Editionlinux
HitachiUcosminexus Application Server Enterprise Version07_00_01 Editionsolaris
HitachiUcosminexus Application Server Enterprise Version07_00_01 Editionwindows
HitachiUcosminexus Application Server Enterprise Version07_00_02 Editionwindows
HitachiUcosminexus Application Server Enterprise Version07_00_03 Editionwindows
HitachiUcosminexus Application Server Enterprise Version07_10 Editionhpux
HitachiUcosminexus Application Server Enterprise Version07_10 Editionhpux_ipf
HitachiUcosminexus Application Server Enterprise Version07_10 Editionlinux
HitachiUcosminexus Application Server Enterprise Version07_10 Editionlinux_ipf
HitachiUcosminexus Application Server Enterprise Version07_10 Editionwindows
HitachiUcosminexus Application Server Enterprise Version07_10_01 Editionhpux_ipf
HitachiUcosminexus Application Server Enterprise Version07_10_01 Editionlinux_ipf
HitachiUcosminexus Application Server Enterprise Version07_10_01 Editionwindows
HitachiUcosminexus Application Server Enterprise Version7_20 Editionwindows
HitachiUcosminexus Application Server Enterprise Version7_20_01 Editionwindows
HitachiUcosminexus Application Server Standard Version07_00 Editionaix
HitachiUcosminexus Application Server Standard Version07_00 Editionhpux_ipf
HitachiUcosminexus Application Server Standard Version07_00 Editionlinux
HitachiUcosminexus Application Server Standard Version07_00 Editionsolaris
HitachiUcosminexus Application Server Standard Version07_00 Editionwindows
HitachiUcosminexus Application Server Standard Version07_00_01 Editionhpux_ipf
HitachiUcosminexus Application Server Standard Version07_00_01 Editionliniux
HitachiUcosminexus Application Server Standard Version07_00_01 Editionsolaris
HitachiUcosminexus Application Server Standard Version07_00_01 Editionwindows
HitachiUcosminexus Application Server Standard Version07_00_02 Editionwindows
HitachiUcosminexus Application Server Standard Version07_00_03 Editionwindows
HitachiUcosminexus Application Server Standard Version07_10 Editionaix
HitachiUcosminexus Application Server Standard Version07_10 Editionhpux
HitachiUcosminexus Application Server Standard Version07_10 Editionhpux_ipf
HitachiUcosminexus Application Server Standard Version07_10 Editionlinux
HitachiUcosminexus Application Server Standard Version07_10 Editionlinux_ipf
HitachiUcosminexus Application Server Standard Version07_10 Editionwindows
HitachiUcosminexus Application Server Standard Version7_10_01 Editionhpux_ipf
HitachiUcosminexus Application Server Standard Version7_10_01 Editionlinux_ipf
HitachiUcosminexus Application Server Standard Version7_10_01 Editionwindows
HitachiUcosminexus Application Server Standard Version7_20 Editionwindows
HitachiUcosminexus Application Server Standard Version7_20_01 Editionwindows
HitachiUcosminexus Developer Standard Version07_00 Editionwindows
HitachiUcosminexus Developer Standard Version07_00_01 Editionwindows
HitachiUcosminexus Developer Standard Version07_00_02 Editionwindows
HitachiUcosminexus Developer Standard Version07_00_03 Editionwindows
HitachiUcosminexus Developer Standard Version07_10 Editionwindows
HitachiUcosminexus Developer Standard Version07_10_01 Editionwindows
HitachiUcosminexus Developer Standard Version07_20 Editionwindows
HitachiUcosminexus Developer Standard Version07_20_01 Editionwindows
HitachiUcosminexus Developer Standard Version07_50 Editionwindows
HitachiUcosminexus Service Platform Version07_00 Editionlinux
HitachiUcosminexus Service Platform Version07_00 Editionwindows
HitachiUcosminexus Service Platform Version07_00_01 Editionlinux
HitachiUcosminexus Service Platform Version07_00_01 Editionwindows
HitachiUcosminexus Service Platform Version07_00_02 Editionwindows
HitachiUcosminexus Service Platform Version07_00_03 Editionwindows
HitachiUcosminexus Service Platform Version07_10 Editionlinux
HitachiUcosminexus Service Platform Version07_10 Editionlinux_ipf
HitachiUcosminexus Service Platform Version07_10 Editionwindows
HitachiUcosminexus Service Platform Version07_10_01 Editionlinux_ipf
HitachiUcosminexus Service Platform Version07_10_01 Editionwindows
HitachiUcosminexus Service Platform Version07_20 Editionwindows
HitachiUcosminexus Service Platform Version7_20_01 Editionwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.496
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.