CVE-2011-0583: XSS
Published Feb 10, 2011
·Updated
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via the cfform tag.
Affected Software
4 affected components
Adobe ColdFusion=8.0
Adobe ColdFusion=9.0
Adobe ColdFusion=8.0.1
Adobe ColdFusion=9.0.1
Remediation
Event History
Feb 10, 2011
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0583?
CVE-2011-0583 is rated as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2011-0583?
To resolve CVE-2011-0583, update Adobe ColdFusion to version 9.0.2 or later, as this version addresses the XSS vulnerabilities.
3
What software is affected by CVE-2011-0583?
CVE-2011-0583 affects Adobe ColdFusion versions 8.0, 8.0.1, 9.0, and 9.0.1.
4
What types of attacks can be performed using CVE-2011-0583?
An attacker can exploit CVE-2011-0583 to inject arbitrary web scripts or HTML into pages via the cfform tag.
5
Is there any workaround for CVE-2011-0583 until a patch is applied?
There are no known workarounds for CVE-2011-0583, so upgrading to a patched version is strongly recommended.