4.3
CVSSv2

CVE-2009-1872

Published: 18/08/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 450
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe coldfusion 7.0

adobe coldfusion 6.0

adobe coldfusion 6.1

adobe coldfusion 8.1

adobe coldfusion

adobe coldfusion 7.2

adobe coldfusion 7.0.2

adobe coldfusion 7.0.1

adobe coldfusion 8.0

Exploits

Adobe Coldfusion 8 suffers from cross site scripting and cross site request forgery vulnerabilities ...
source: wwwsecurityfocuscom/bid/36046/info Adobe ColdFusion is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing ...
source: wwwsecurityfocuscom/bid/36046/info Adobe ColdFusion is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing the ...
source: wwwsecurityfocuscom/bid/36046/info Adobe ColdFusion is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing t ...
source: wwwsecurityfocuscom/bid/36046/info Adobe ColdFusion is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing the a ...