Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager before 20070528 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/35286 | vdb entry |
http://osvdb.org/37848 | vdb entry |
http://www.hitachi-support.com/security_e/vuls_e/HS07-017_e/index-e.html | patch |
http://www.vupen.com/english/advisories/2007/2457 | vdb entry |
http://www.securityfocus.com/bid/24797 | vdb entry |
http://secunia.com/advisories/25973 | third party advisory |
http://osvdb.org/37849 | vdb entry |