CVE-2005-1555: XSS
Published May 10, 2005
·Updated
Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.
Affected Software
1 affected component
Macromedia ColdFusion=7.0
Remediation
Event History
May 10, 2005
CVE Published
04:00 AM
May 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1555?
CVE-2005-1555 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2005-1555?
To fix CVE-2005-1555, ensure that you update to a version of ColdFusion MX that is not affected by this vulnerability.
3
Who is affected by CVE-2005-1555?
CVE-2005-1555 affects users of Macromedia ColdFusion version 7.0.
4
What type of vulnerability is CVE-2005-1555?
CVE-2005-1555 is classified as a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2005-1555?
Attackers can inject arbitrary script or HTML into the URL, exploiting the vulnerability on the default 404 error page.