Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Cosminexus Application Server | All versions |
| Hitachi | Cosminexus Application Server Version 5 | All versions |
| Hitachi | Cosminexus Developer Light Version 6 | All versions |
| Hitachi | Cosminexus Developer Professional Version 6 | All versions |
| Hitachi | Cosminexus Developer Standard Version 6 | All versions |
| Hitachi | Cosminexus Developer Version 5 | All versions |
| Hitachi | Cosminexus Server - Enterprise Edition | All versions |
| Hitachi | Cosminexus Server - Standard Edition | All versions |
| Hitachi | Cosminexus Server - Standard Edition Version 4 | All versions |
| Hitachi | Cosminexus Server - Web Edition | All versions |
| Hitachi | Cosminexus Server - Web Edition Version 4 | All versions |
| Hitachi | Hitachi Web Server | All versions |
| Hitachi | Ucosminexus Application Server Enterprise | All versions |
| Hitachi | Ucosminexus Application Server Smart Edition | All versions |
| Hitachi | Ucosminexus Application Server Standard | All versions |
| Hitachi | Ucosminexus Developer Light | All versions |
| Hitachi | Ucosminexus Developer Standard | All versions |
| Hitachi | Ucosminexus Service Architect | All versions |
| Hitachi | Ucosminexus Service Platform | All versions |
References
- http://osvdb.org/32997
- http://osvdb.org/32998
- http://secunia.com/advisories/23843
- http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.htmlPatchVendor Advisory
- http://www.vupen.com/english/advisories/2007/0326
- http://osvdb.org/32997
- http://osvdb.org/32998
- http://secunia.com/advisories/23843
- http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.htmlPatchVendor Advisory
- http://www.vupen.com/english/advisories/2007/0326
FAQ
What is CVE-2007-0514?
CVE-2007-0514 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML v...
How severe is CVE-2007-0514?
CVE-2007-0514 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0514?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Cosminexus Application Server, Hitachi Cosminexus Application Server Version 5, Hitachi Cosminexus Developer Light Version 6, Hitachi Cosminexus Developer Professional Version 6, Hitachi Cosminexus Developer Standard Version 6.