Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
adobe coldfusion 7.0 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2010-1293
Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Adobe Coldfusion 7.0
Adobe Coldfusion 7.0.2
Adobe Coldfusion 4.5
Adobe Coldfusion
Adobe Coldfusion 7.0.1
Adobe Coldfusion 8.0
Adobe Coldfusion 8.0.1
Adobe Coldfusion 7.2
Adobe Coldfusion 6.0
Adobe Coldfusion 6.1
Adobe Coldfusion 5.0
2.1
CVSSv2
CVE-2010-1294
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.
Adobe Coldfusion 8.0
Adobe Coldfusion 6.0
Adobe Coldfusion 5.0
Adobe Coldfusion 8.0.1
Adobe Coldfusion 6.1
Adobe Coldfusion 4.5
Adobe Coldfusion
Adobe Coldfusion 7.0
Adobe Coldfusion 7.0.1
Adobe Coldfusion 7.0.2
Adobe Coldfusion 7.2
5
CVSSv2
CVE-2011-0737
Adobe ColdFusion 9.0.1 CHF1 and previous versions allows remote malicious users to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wid...
Adobe Coldfusion 7.0.2
Adobe Coldfusion 8.0
Adobe Coldfusion 9.0
Adobe Coldfusion 6.0
Adobe Coldfusion 7.0
Adobe Coldfusion 5.0
Adobe Coldfusion 6.1
Adobe Coldfusion 7.0.1
Adobe Coldfusion 8.0.1
Adobe Coldfusion
Adobe Coldfusion 8.1
Adobe Coldfusion 9.0.1
Adobe Coldfusion 4.5
4.3
CVSSv2
CVE-2011-0735
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion prior to 9.0.1 CHF1 allows remote malicious users to inject arbitrary web script or HTML via vectors involving a "tag script."
Adobe Coldfusion 9.0.1
Adobe Coldfusion 8.0
Adobe Coldfusion 7.0
Adobe Coldfusion 7.0.1
Adobe Coldfusion 7.0.2
Adobe Coldfusion 5.0
Adobe Coldfusion 4.5
Adobe Coldfusion
Adobe Coldfusion 8.0.1
Adobe Coldfusion 6.1
Adobe Coldfusion 6.0
Adobe Coldfusion 9.0
Adobe Coldfusion 8.1
4.3
CVSSv2
CVE-2011-0736
Adobe ColdFusion 9.0.1 CHF1 and previous versions, when a web application is configured to use a DBMS, allows remote malicious users to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significan...
Adobe Coldfusion 7.0.2
Adobe Coldfusion 8.0
Adobe Coldfusion 9.0
Adobe Coldfusion 6.0
Adobe Coldfusion 7.0
Adobe Coldfusion 5.0
Adobe Coldfusion 6.1
Adobe Coldfusion 7.0.1
Adobe Coldfusion 8.0.1
Adobe Coldfusion
Adobe Coldfusion 8.1
Adobe Coldfusion 9.0.1
Adobe Coldfusion 4.5
4.3
CVSSv2
CVE-2011-0734
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion prior to 9.0.1 CHF1 allows remote malicious users to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOT...
Adobe Coldfusion 7.0.2
Adobe Coldfusion 9.0
Adobe Coldfusion 9.0.1
Adobe Coldfusion
Adobe Coldfusion 6.1
Adobe Coldfusion 6.0
Adobe Coldfusion 8.1
Adobe Coldfusion 8.0
Adobe Coldfusion 7.0
Adobe Coldfusion 8.0.1
Adobe Coldfusion 7.0.1
Adobe Coldfusion 5.0
Adobe Coldfusion 4.5
6.8
CVSSv2
CVE-2007-5905
Adobe ColdFusion 8 and MX 7 allows remote malicious users to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerabilit...
Adobe Coldfusion 8.0
Adobe Coldfusion 7.0
7.5
CVSSv2
CVE-2008-1203
The administrator interface for Adobe ColdFusion 8 and ColdFusion MX7 does not log failed authentication attempts, which makes it easier for remote malicious users to conduct brute force attacks without detection.
Adobe Coldfusion 7.0
Adobe Coldfusion 8.0
4.6
CVSSv2
CVE-2006-4725
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
Adobe Coldfusion 7.0
Adobe Coldfusion 7.0.1
2.6
CVSSv2
CVE-2006-6483
Adobe ColdFusion MX 7.x prior to 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote malicious users to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "...
Adobe Coldfusion 7.0
Adobe Coldfusion 7.0.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »