First published: Wed Feb 14 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe JRun | =4.0 | |
Adobe ColdFusion | =6.1 | |
Adobe JRun | =4.0-sp1a | |
Adobe JRun | =4.0_build_61650 | |
Adobe JRun | =4.0-sp1 | |
Adobe ColdFusion | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-5860 is classified as high due to its potential for remote exploitation.
To fix CVE-2006-5860, upgrade Adobe JRun or ColdFusion to a patched version that addresses the XSS vulnerability.
CVE-2006-5860 affects users of Adobe JRun 4.0 and ColdFusion versions that utilize the vulnerable administrator console.
CVE-2006-5860 allows remote attackers to execute arbitrary web scripts or HTML via cross-site scripting (XSS) attacks.
The impact of CVE-2006-5860 can result in unauthorized access and exploitation of users' sessions and sensitive data.