
CVE-2015-8052
https://notcve.org/view.php?id=CVE-2015-8052
18 Nov 2015 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8053. Vulnerabilidad de XSS en Adobe ColdFusion 10 en versiones anteriores a Update 18 y 11 en versiones anteriores a Update 7 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados, una vulnerabilidad diferente a ... • http://www.securityfocus.com/bid/77625 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-8053
https://notcve.org/view.php?id=CVE-2015-8053
18 Nov 2015 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8052. Vulnerabilidad de XSS en Adobe ColdFusion 10 en versiones anteriores a Update 18 y 11 en versiones anteriores a Update 7 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados, una vulnerabilidad diferente a ... • http://www.securityfocus.com/bid/77625 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-5255 – HP Security Bulletin HPSBST03568 1
https://notcve.org/view.php?id=CVE-2015-5255
18 Nov 2015 — Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue. Adobe BlazeDS, como se utiliza en ColdFusion 10 en versiones anteriores a Update 18 y 11 en versiones anteriores a ... • https://packetstorm.news/files/id/134506 • CWE-20: Improper Input Validation •

CVE-2015-0345
https://notcve.org/view.php?id=CVE-2015-0345
15 Apr 2015 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 16 and 11 before Update 5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Adobe ColdFusion 10 anterior a Update 16 y 11 anterior a Update 5 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • https://github.com/BishopFox/coldfusion-10-11-xss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-5326
https://notcve.org/view.php?id=CVE-2013-5326
13 Nov 2013 — Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and 10 before Update 12, when the CFIDE directory is available, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the logviewer directory. Una vulnerabilidad de tipo cross-site scripting (XSS) en Adobe ColdFusion versión 9.0 anterior a Update 12, versión 9.0.1 anterior a Update 11, versión 9.0.2 anterior a Update 6 y versi... • http://www.adobe.com/support/security/bulletins/apsb13-27.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-5328
https://notcve.org/view.php?id=CVE-2013-5328
13 Nov 2013 — Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors. Adobe ColdFusion 10 anterior a Update 12 permite a atacantes remotos leer ficheros arbitrarios a través de vectores sin especificar • http://www.adobe.com/support/security/bulletins/apsb13-27.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2010-5290
https://notcve.org/view.php?id=CVE-2010-5290
20 Sep 2013 — The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861. El proceso de autenticación en Adobe ColdFusion anteriores a v10 no requiere conocimiento de la contraseña en claro si el hash de la contraseña es conocido, lo cual facilita a atacan... • http://osvdb.org/97553 • CWE-255: Credentials Management Errors •

CVE-2012-2048
https://notcve.org/view.php?id=CVE-2012-2048
12 Sep 2012 — Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of service via unknown vectors. Vulnerabilidad no especificada en Adobe ColdFusion 10 y anteriores permite a atacantes provocar una denegación de servicio a través de vectores desconocidos. • http://osvdb.org/85317 •

CVE-2012-2041
https://notcve.org/view.php?id=CVE-2012-2041
13 Jun 2012 — CRLF injection vulnerability in the Component Browser in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. Vulnerabilidad de inyección CRLF en el navegador de componente de Adobe ColdFusion 8.0 hasta la versión 9.0.1. Permite a atacantes remotos inyectar cabeceras HTTP arbitrarias y realizar ataques de división de respuestas HTTP a través de vectores sin especificar. • http://www.adobe.com/support/security/bulletins/apsb12-15.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2012-0770
https://notcve.org/view.php?id=CVE-2012-0770
13 Mar 2012 — Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Adobe ColdFusion v8.0, v8.0.1, v9.0 y v9.0.1, calcula los valores hash de los parámetros del formulario sin restringir la capacidad de desencadenar colisiones de hash predecibles, lo que permite a atacantes remotos provocar una denegación de ... • http://helpx.adobe.com/coldfusion/kb/coldfusion-security-hotfix.html •