CVE-2014-0571: XSS
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0571?
CVE-2014-0571 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts or HTML.
How do I fix CVE-2014-0571?
To fix CVE-2014-0571, you should update Adobe ColdFusion to the latest versions or specific updates as recommended by Adobe.
Which Adobe ColdFusion versions are affected by CVE-2014-0571?
CVE-2014-0571 affects Adobe ColdFusion versions 9.0, 9.0.1, 9.0.2, 10.0, and 11.0 prior to their respective updates.
What type of vulnerability is CVE-2014-0571?
CVE-2014-0571 is a cross-site scripting (XSS) vulnerability that can be exploited to inject malicious scripts into web pages.
Can CVE-2014-0571 be exploited remotely?
Yes, CVE-2014-0571 can be exploited by remote attackers who can target a vulnerable instance of Adobe ColdFusion.