CVE-2006-4726: XSS
Published Sep 14, 2006
·Updated
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
Affected Software
3 affected components
Adobe ColdFusion=7.0
Adobe ColdFusion=6.1
Adobe ColdFusion=7.0.1
Remediation
Patch Available
Patch Available
Event History
Sep 14, 2006
CVE Published
12:07 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4726?
CVE-2006-4726 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2006-4726?
To fix CVE-2006-4726, upgrade Adobe ColdFusion to version 7.0.2 or higher.
3
What types of attacks does CVE-2006-4726 allow?
CVE-2006-4726 allows remote attackers to perform cross-site scripting (XSS) attacks.
4
Which versions of Adobe ColdFusion are affected by CVE-2006-4726?
CVE-2006-4726 affects Adobe ColdFusion MX versions 6.1 through 7.0.1.
5
What is the impact of exploiting CVE-2006-4726?
Exploiting CVE-2006-4726 can lead to unauthorized script execution in the user's browser.