CVE-2006-6483: XSS
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6483?
CVE-2006-6483 has a severity rating that indicates a medium risk due to potential cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2006-6483?
To fix CVE-2006-6483, upgrade Adobe ColdFusion to version 7.0.2 or later.
What are the affected software versions for CVE-2006-6483?
CVE-2006-6483 affects Adobe ColdFusion versions 7.0 and 7.0.1.
What type of attacks does CVE-2006-6483 allow?
CVE-2006-6483 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
Can CVE-2006-6483 be exploited remotely?
Yes, CVE-2006-6483 can be exploited remotely due to improper filtering of HTML tags.