First published: Thu Sep 14 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4726 has been classified as a medium severity vulnerability.
To fix CVE-2006-4726, upgrade Adobe ColdFusion to version 7.0.2 or higher.
CVE-2006-4726 allows remote attackers to perform cross-site scripting (XSS) attacks.
CVE-2006-4726 affects Adobe ColdFusion MX versions 6.1 through 7.0.1.
Exploiting CVE-2006-4726 can lead to unauthorized script execution in the user's browser.