Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown

CVE-2006-5859

Disclosure Date: February 14, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.
0
Attacker Value
Unknown

CVE-2007-0817

Disclosure Date: February 07, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.
0
Attacker Value
Unknown

CVE-2006-6482

Disclosure Date: December 12, 2006 (last updated October 04, 2023)
Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.
0
Attacker Value
Unknown

CVE-2006-6483

Disclosure Date: December 12, 2006 (last updated October 04, 2023)
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.
0
Attacker Value
Unknown

CVE-2006-3978

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2006-4725

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
0
Attacker Value
Unknown

CVE-2006-4724

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.
0
Attacker Value
Unknown

CVE-2006-4726

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
0
Attacker Value
Unknown

CVE-2006-3979

Disclosure Date: August 09, 2006 (last updated October 04, 2023)
The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Administrator.
0
Attacker Value
Unknown

CVE-2005-4345

Disclosure Date: December 19, 2005 (last updated February 22, 2025)
Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.
0