CVE-2008-0644: XSS
Published Mar 12, 2008
·Updated
Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism for applications via unspecified vectors related to the setEncoding function.
Affected Software
4 affected components
Adobe ColdFusion=7.0.2
Adobe ColdFusion=8.0
Adobe ColdFusion=7.0
Adobe ColdFusion=7.0.1
Remediation
Patch Available
Event History
Mar 12, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0644?
CVE-2008-0644 is classified as a moderate severity vulnerability due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2008-0644?
To fix CVE-2008-0644, update Adobe ColdFusion to the latest version or apply any available security patches.
3
What versions of ColdFusion are affected by CVE-2008-0644?
CVE-2008-0644 affects Adobe ColdFusion MX 7.0, 7.0.1, 7.0.2 and ColdFusion 8.0.
4
What is the main issue caused by CVE-2008-0644?
The main issue caused by CVE-2008-0644 is the ability for remote attackers to bypass cross-site scripting protections.
5
Can CVE-2008-0644 lead to data compromise?
Yes, CVE-2008-0644 can potentially lead to data compromise through effective cross-site scripting exploits.