Page 8 of 52 results (0.011 seconds)

CVSS: 9.8EPSS: 51%CPEs: 18EXPL: 0

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11. Adobe ColdFusion tiene una vulnerabilidad de deserialización de datos no fiables. Esto afecta al Update 4 y a versiones anteriores para ColdFusion 2016 y al Update 12 y versiones anteriores para ColdFusion 11. • http://www.securityfocus.com/bid/100708 http://www.securitytracker.com/id/1039321 https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html • CWE-502: Deserialization of Untrusted Data •

CVSS: 6.1EPSS: 0%CPEs: 18EXPL: 0

Adobe ColdFusion has a cross-site scripting (XSS) vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11. Adobe ColdFusion tiene una vulnerabilidad de Cross-Site Scripting (XSS). Esto afecta al Update 4 y a versiones anteriores para ColdFusion 2016 y al Update 12 y versiones anteriores para ColdFusion 11. • http://www.securityfocus.com/bid/100711 http://www.securitytracker.com/id/1039321 https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 39EXPL: 0

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability. Adobe ColdFusion 2016 Update 3 y anteriores, ColdFusion 11 update 11 y anteriores, ColdFusion 10 Update 22 y versiones anteriores tienen una vulnerabilidad de cross-site scripting. • http://www.securityfocus.com/bid/98002 http://www.securitytracker.com/id/1038364 https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 88%CPEs: 39EXPL: 2

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution. Adobe ColdFusion 2016 Update 3 y anteriores, ColdFusion 11 update 11 y anteriores, ColdFusion 10 Update 22 y anteriores tienen una vulnerabilidad de deserialización de Java en la librería Apache BlazeDS. Una explotación exitosa podría conducir a la ejecución arbitraria de código. • https://www.exploit-db.com/exploits/43993 https://github.com/cucadili/CVE-2017-3066 http://www.securityfocus.com/bid/98003 http://www.securitytracker.com/id/1038364 https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html • CWE-502: Deserialization of Untrusted Data •

CVSS: 8.6EPSS: 78%CPEs: 2EXPL: 2

The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. La funcionalidad Office Open XML (OOXML) en Adobe ColdFusion 10 en versiones anteriores a Update 21 y 11 en versiones anteriores a Update 10 permite a atacantes remotos leer archivos arbitrarios o enviar peticiones TCP a servidores de intranet a través de una hoja de cálculo OOXML manipulada que contiene una declaración de entidad externa en conjunción con una referencia de entidad, relacionado con un problema XML External Entity (XXE). Adobe ColdFusion versions 11 and below suffer from an XML external entity (XXE) injection vulnerability. • https://www.exploit-db.com/exploits/40346 http://legalhackers.com/advisories/Adobe-ColdFusion-11-XXE-Exploit-CVE-2016-4264.txt http://www.securityfocus.com/archive/1/539374/100/0/threaded http://www.securityfocus.com/bid/92684 http://www.securitytracker.com/id/1036708 https://helpx.adobe.com/security/products/coldfusion/apsb16-30.html • CWE-611: Improper Restriction of XML External Entity Reference •