Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown
CVE-2011-2091
Disclosure Date: June 16, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to cause a denial of service via unknown vectors.
0
Attacker Value
Unknown
CVE-2011-0580
Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-0582
Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allows attackers to obtain sensitive information via unknown vectors.
0
Attacker Value
Unknown
CVE-2011-0583
Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via the cfform tag.
0
Attacker Value
Unknown
CVE-2011-0584
Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Session fixation vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to hijack web sessions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-0581
Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Multiple CRLF injection vulnerabilities in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified tags.
0
Attacker Value
Unknown
CVE-2011-0735
Disclosure Date: February 01, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script."
0
Attacker Value
Unknown
CVE-2011-0734
Disclosure Date: February 01, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOTE: this was originally reported as affecting 9.0.1 CHF1 and earlier.
0
Attacker Value
Unknown
CVE-2011-0737
Disclosure Date: February 01, 2011 (last updated November 08, 2023)
Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure
0
Attacker Value
Unknown
CVE-2011-0736
Disclosure Date: February 01, 2011 (last updated November 08, 2023)
Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure
0