CVE-2011-0735: XSS
Published Feb 1, 2011
·Updated
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script."
Affected Software
13 affected components
Adobe ColdFusion=7.0.2
Adobe ColdFusion=8.0
Adobe ColdFusion=9.0
Adobe ColdFusion=6.0
Adobe ColdFusion=7.0
Adobe ColdFusion=5.0
Adobe ColdFusion=6.1
Adobe ColdFusion=7.0.1
Adobe ColdFusion=8.0.1
Adobe ColdFusion<=9.0.1
Adobe ColdFusion=8.1
Adobe ColdFusion=9.0.1
Adobe ColdFusion=4.5
Event History
Feb 1, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0735?
CVE-2011-0735 is classified as a medium severity vulnerability due to its potential for remote code execution through XSS attacks.
2
How do I fix CVE-2011-0735?
To fix CVE-2011-0735, update Adobe ColdFusion to version 9.0.1 CHF1 or later.
3
What kind of attacks can CVE-2011-0735 facilitate?
CVE-2011-0735 can facilitate cross-site scripting (XSS) attacks allowing attackers to inject arbitrary web scripts or HTML.
4
Which versions of Adobe ColdFusion are affected by CVE-2011-0735?
CVE-2011-0735 affects Adobe ColdFusion versions 5.0 through 9.0 inclusive.
5
Where can I find more information on CVE-2011-0735?
For more information on CVE-2011-0735, refer to detailed security bulletins or Adobe's official documentation.