First published: Tue Dec 31 2002(Updated: )
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =6.0 | |
Microsoft Internet Information Services (IIS) | =5.0 | |
Microsoft Windows 2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1700 has a severity rating that indicates a significant risk of cross-site scripting attacks.
To fix CVE-2002-1700, ensure that the application properly validates and sanitizes input to prevent script injection in templates.
CVE-2002-1700 affects Macromedia ColdFusion 6.0 and Microsoft Internet Information Services 5.0 on Windows 2000.
CVE-2002-1700 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2002-1700 can be exploited remotely by attackers to execute arbitrary scripts on behalf of other users.