First published: Tue Aug 18 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =6.0 | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =6.0 | |
Adobe ColdFusion | =7.0.2 | |
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =8.0 | |
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =6.0 | |
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =6.0 | |
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =7.2-unknown | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | <=8.0.1 | |
Adobe ColdFusion | =7.0.1 | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =8.1 | |
Adobe ColdFusion | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.