First published: Thu May 13 2010(Updated: )
Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =7.0.2 | |
Adobe ColdFusion | =8.0 | |
Adobe ColdFusion | =6.0 | |
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =5.0 | |
Adobe ColdFusion | <=9.0 | |
Adobe ColdFusion | =7.2-unknown | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =7.0.1 | |
Adobe ColdFusion | =8.0.1 | |
Adobe ColdFusion | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3467 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2009-3467, upgrade to a patched version of Adobe ColdFusion that addresses this XSS vulnerability.
CVE-2009-3467 affects Adobe ColdFusion versions 5.0 through 9.0, including 8.0 and 8.0.1.
CVE-2009-3467 allows remote attackers to inject arbitrary web scripts or HTML into vulnerable applications.
While the best option is to upgrade, implementing input validation and encoding can help mitigate the risks associated with CVE-2009-3467.