First published: Tue Jun 05 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Collaboration - File Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus Collaboration Portal up to 06-30-/D, and uCosminexus Collaboration Portal - Forum/File Sharing up to 06-30-/C on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Groupmax Collaboration Web Client | =forum_file_share_7_30_c | |
Hitachi Groupmax collaboration | =7_30_d | |
Hitachi Groupmax collaboration | =7_20_e | |
Hitachi uCosminexus Collaboration Portal | =6_30_d | |
Hitachi Groupmax Collaboration Web Client | =forum_file_share_7_20_d | |
Hitachi uCosminexus Collaboration Portal | =forum_file_share_6_20_d | |
Hitachi uCosminexus Collaboration Portal | =6_20_e | |
Hitachi uCosminexus Collaboration Portal | =forum_file_share_6_30_c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3043 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2007-3043, update the affected Hitachi Groupmax Collaboration Portal and Web Client to the latest patched version.
CVE-2007-3043 affects Hitachi Groupmax Collaboration Portal versions up to 07-30-/D and Groupmax Collaboration Web Client versions up to 07-30-/C.
While not as common as others, CVE-2007-3043 is known to impact specific versions of Hitachi collaboration tools, and organizations using affected products should address it.
Yes, exploitation of CVE-2007-3043 could allow attackers to execute scripts in the context of users' sessions, potentially leading to data theft or session hijacking.