Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2009-1872
Disclosure Date: August 18, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
0
Attacker Value
Unknown
CVE-2009-1877
Disclosure Date: August 18, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.
0
Attacker Value
Unknown
CVE-2008-0643
Disclosure Date: March 12, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-0644
Disclosure Date: March 12, 2008 (last updated October 04, 2023)
Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism for applications via unspecified vectors related to the setEncoding function.
0
Attacker Value
Unknown
CVE-2006-5859
Disclosure Date: February 14, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.
0
Attacker Value
Unknown
CVE-2007-0817
Disclosure Date: February 07, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.
0
Attacker Value
Unknown
CVE-2006-6483
Disclosure Date: December 12, 2006 (last updated October 04, 2023)
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.
0
Attacker Value
Unknown
CVE-2006-3978
Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2006-4725
Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
0
Attacker Value
Unknown
CVE-2006-4724
Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.
0