Page 13 of 175 results (0.019 seconds)

CVSS: 6.1EPSS: 59%CPEs: 13EXPL: 2

01 Feb 2011 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script." Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Adobe ColdFusion before v9.0.1 CHF1 permite a atacantes remotos ejecutar código web o HTML de su elección a través de vectores relacionados con una "secuencia de comandos de etiquetas" • http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0537.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 4%CPEs: 13EXPL: 3

01 Feb 2011 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOTE: this was originally reported as affecting 9.0.1 CHF1 and earlier. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Adobe ColdFusion v9.0.1 CHF1 y anteriores permite a atacantes remotos inyectar secuencias de comand... • http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0537.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 95%CPEs: 4EXPL: 3

11 Aug 2010 — Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/. Múltiples vulnerabilidades de salto de directorio en la consola del administrador en ColdFusion de Adobe versión 9.0.1 y anteriores, permiten a los... • https://packetstorm.news/files/id/181055 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 5.5EPSS: 0%CPEs: 11EXPL: 0

13 May 2010 — Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors. Vulnerabilidad no especificada en Adobe ColdFusion 8.0, 8.0.1 y 9.0 permite a usuarios locales obtener información sensible mediante vectores desconocidos. • http://secunia.com/advisories/39790 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 3%CPEs: 11EXPL: 0

13 May 2010 — Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la página de Administración en Adobe ColdFusion 8.0, 8.0.1 y 9.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante vectores no especificados . • http://secunia.com/advisories/39790 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 3%CPEs: 11EXPL: 0

13 May 2010 — Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en un método no especificado en Adobe ColdFusion 8.0, 8.0.1 y 9.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante vectores desconocidos. • http://secunia.com/advisories/39790 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 93%CPEs: 12EXPL: 4

15 Feb 2010 — Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents. Vulnerabilidad sin especificar en BlazeDS v3.2 y anteriores, tal como es utilizado en LiveCycle v8.0.1, v8.2.1 y v9.... • https://packetstorm.news/files/id/181095 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

03 Feb 2010 — The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL. La configuración por defecto en Adobe ColdFusion v9.0 no limita el acceso a las colecciones que han sido creadas mediante el servicio Solr, lo que permite a atacantes remotos conseguir información de los metadatos, de búsquedas, y datos del indi... • http://kb2.adobe.com/cps/807/cpsid_80719.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 6.1EPSS: 14%CPEs: 21EXPL: 5

18 Aug 2009 — Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Adobe ColdFusion Server 8.0.1 y anteriores permiten a... • https://www.exploit-db.com/exploits/33169 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 19%CPEs: 21EXPL: 0

18 Aug 2009 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Adobe ColdFusion 8.0.1 y versiones anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante vectores no especificados, una vulnerabilidad diferente que CVE-2009-1875. • http://osvdb.org/57190 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •