Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Groupmax Collaboration Portal and Web Client before 07-20-/D, and uCosminexus Collaboration Portal and Forum/File Sharing before 06-20-/C, allow remote attackers to "execute malicious scripts" via unknown vectors (aka HS06-014-01).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Cosminexus Collaboration Portal | <= 06_10_b |
| Hitachi | Groupmax Collaboration Portal | <= 07_10_b |
| Hitachi | Groupmax Collaboration Web Client | <= 07_10_a |
References
- http://secunia.com/advisories/20926PatchVendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS06-014_e/01-e.htmlPatch
- http://www.hitachi-support.com/security_e/vuls_e/HS06-014_e/index-e.htmlPatch
- http://www.securityfocus.com/bid/18830Patch
- http://www.vupen.com/english/advisories/2006/2665
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27605
- http://secunia.com/advisories/20926PatchVendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS06-014_e/01-e.htmlPatch
- http://www.hitachi-support.com/security_e/vuls_e/HS06-014_e/index-e.htmlPatch
- http://www.securityfocus.com/bid/18830Patch
- http://www.vupen.com/english/advisories/2006/2665
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27605
FAQ
What is CVE-2006-3574?
CVE-2006-3574 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Groupmax Collaboration Portal and Web Client before 07-20-/D, and uCosminexus Collaboration Portal and Forum/File Sharing before 06-20-/C...
How severe is CVE-2006-3574?
CVE-2006-3574 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3574?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Cosminexus Collaboration Portal, Hitachi Groupmax Collaboration Portal, Hitachi Groupmax Collaboration Web Client.