CVE-2009-1877: XSS
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1877?
CVE-2009-1877 has been classified as a cross-site scripting vulnerability, which can allow remote attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2009-1877?
To fix CVE-2009-1877, update Adobe ColdFusion to version 8.0.2 or later as per Adobe's security bulletins.
Which Adobe ColdFusion versions are affected by CVE-2009-1877?
CVE-2009-1877 affects Adobe ColdFusion 8.0.1 and earlier, as well as earlier versions including 6.0 and 7.0.
Can CVE-2009-1877 be exploited without user interaction?
Yes, CVE-2009-1877 can potentially be exploited without user interaction through crafted URLs or forms.
Is CVE-2009-1877 related to any other vulnerabilities?
CVE-2009-1877 is a different vulnerability than CVE-2009-1875, although both involve cross-site scripting issues in Adobe ColdFusion.