First published: Thu May 13 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =7.0.2 | |
Adobe ColdFusion | =8.0 | |
Adobe ColdFusion | =6.0 | |
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =5.0 | |
Adobe ColdFusion | <=9.0 | |
Adobe ColdFusion | =7.2-unknown | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =7.0.1 | |
Adobe ColdFusion | =8.0.1 | |
Adobe ColdFusion | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1293 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2010-1293, update Adobe ColdFusion to the latest version as recommended by Adobe's security bulletins.
CVE-2010-1293 affects Adobe ColdFusion versions 5.0 up to 9.0, including 7.0, 7.0.1, 7.2, 8.0, and 8.0.1.
CVE-2010-1293 allows remote attackers to execute arbitrary web scripts or HTML, potentially leading to stolen credentials or session hijacking.
CVE-2010-1293 is a cross-site scripting (XSS) vulnerability that can be exploited via the Administrator page in the affected versions of Adobe ColdFusion.