CVE-2010-1293: XSS
Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1293?
CVE-2010-1293 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2010-1293?
To fix CVE-2010-1293, update Adobe ColdFusion to the latest version as recommended by Adobe's security bulletins.
Which versions of Adobe ColdFusion are affected by CVE-2010-1293?
CVE-2010-1293 affects Adobe ColdFusion versions 5.0 up to 9.0, including 7.0, 7.0.1, 7.2, 8.0, and 8.0.1.
What types of attacks can result from CVE-2010-1293?
CVE-2010-1293 allows remote attackers to execute arbitrary web scripts or HTML, potentially leading to stolen credentials or session hijacking.
What is the nature of the vulnerability CVE-2010-1293?
CVE-2010-1293 is a cross-site scripting (XSS) vulnerability that can be exploited via the Administrator page in the affected versions of Adobe ColdFusion.