CVE-2004-2497

UnknownEPSS 1.18%

Last modified

CVE-2004-2497 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.. EPSS estimates a 1.18% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

Metrics

EPSS Probability
1.18%

63.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HitachiWeb Page Generator01_00
HitachiWeb Page Generator01_01_c
HitachiWeb Page Generator02_00
HitachiWeb Page Generator02_00_c
HitachiWeb Page Generator Enterprise03_00
HitachiWeb Page Generator Enterprise03_02_c
HitachiWeb Page Generator Enterprise03_03
HitachiWeb Page Generator Enterprise03_03_c
HitachiWeb Page Generator Enterprise03_03_d
HitachiWeb Page Generator Enterprise04_00
HitachiWeb Page Generator Enterprise04_00_c
HitachiWeb Page Generator Enterprise04_01
HitachiWeb Page Generator Enterprise04_01_b

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-2497?
Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
How severe is CVE-2004-2497?
Severity scoring for CVE-2004-2497 is pending analysis. The EPSS model estimates a 1.18% probability of exploitation in the next 30 days.
How do I fix CVE-2004-2497?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-2497?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST