
CVE-2015-8052
https://notcve.org/view.php?id=CVE-2015-8052
18 Nov 2015 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8053. Vulnerabilidad de XSS en Adobe ColdFusion 10 en versiones anteriores a Update 18 y 11 en versiones anteriores a Update 7 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados, una vulnerabilidad diferente a ... • http://www.securityfocus.com/bid/77625 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-8053
https://notcve.org/view.php?id=CVE-2015-8053
18 Nov 2015 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8052. Vulnerabilidad de XSS en Adobe ColdFusion 10 en versiones anteriores a Update 18 y 11 en versiones anteriores a Update 7 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados, una vulnerabilidad diferente a ... • http://www.securityfocus.com/bid/77625 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-5255 – HP Security Bulletin HPSBST03568 1
https://notcve.org/view.php?id=CVE-2015-5255
18 Nov 2015 — Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue. Adobe BlazeDS, como se utiliza en ColdFusion 10 en versiones anteriores a Update 18 y 11 en versiones anteriores a ... • https://packetstorm.news/files/id/134506 • CWE-20: Improper Input Validation •

CVE-2015-0345
https://notcve.org/view.php?id=CVE-2015-0345
15 Apr 2015 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 16 and 11 before Update 5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Adobe ColdFusion 10 anterior a Update 16 y 11 anterior a Update 5 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • https://github.com/BishopFox/coldfusion-10-11-xss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-0570
https://notcve.org/view.php?id=CVE-2014-0570
15 Oct 2014 — Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Vulnerabilidad de CSRF en Adobe ColdFusion 9.0 anterior a Update 13, 9.0.1 anterior a Update 12, 9.0.2 anterior a Update 7, 10 anterior a Update 14, y 11 anterior a Update 2 permite a atacantes remotos secuestrar la autenticación de v... • http://helpx.adobe.com/security/products/coldfusion/apsb14-23.html • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-0571
https://notcve.org/view.php?id=CVE-2014-0571
15 Oct 2014 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Adobe ColdFusion 9.0 anterior a Update 13, 9.0.1 antterior a Update 12, 9.0.2 anterior a Update 7, 10 anterior a Update 14, y 11 anterior a Update 2 permite a atacantes remotos inyectar secuencias de comandos remotos a través... • http://helpx.adobe.com/security/products/coldfusion/apsb14-23.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-0572
https://notcve.org/view.php?id=CVE-2014-0572
15 Oct 2014 — Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows local users to bypass intended IP-based access restrictions via unspecified vectors. Adobe ColdFusion 9.0 anterior a Update 13, 9.0.1 anterior a Update 12, 9.0.2 anterior a Update 7, 10 anterior a Update 14, y 11 anterior a Update 2 permite a usuarios locales evadir las restricciones de acceso basadas en IP a través de vectores no especificados. • http://helpx.adobe.com/security/products/coldfusion/apsb14-23.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-5315
https://notcve.org/view.php?id=CVE-2014-5315
26 Sep 2014 — Cross-site scripting (XSS) vulnerability in the Help page in Adobe Acrobat 9.5.2 and earlier and ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en la página de ayuda en Adobe Acrobat 9.5.2 y anteriores y ColdFusion 8.0.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://jvn.jp/en/jp/JVN84376800/244523/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-5326
https://notcve.org/view.php?id=CVE-2013-5326
13 Nov 2013 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and 10 before Update 12, when the CFIDE directory is available, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the logviewer directory. Una vulnerabilidad de tipo cross-site scripting (XSS) en Adobe ColdFusion versión 9.0 anterior a Update 12, versión 9.0.1 anterior a Update 11, versión 9.0.2 anterior a Update 6 y versi... • http://www.adobe.com/support/security/bulletins/apsb13-27.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-5328
https://notcve.org/view.php?id=CVE-2013-5328
13 Nov 2013 — Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors. Adobe ColdFusion 10 anterior a Update 12 permite a atacantes remotos leer ficheros arbitrarios a través de vectores sin especificar • http://www.adobe.com/support/security/bulletins/apsb13-27.html • CWE-264: Permissions, Privileges, and Access Controls •