Page 9 of 59 results (0.009 seconds)

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 0

Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/. Adobe ColdFusion MX 7 para Linux y Solaris utiliza permisos inseguros para ciertas secuencias de comandos y directorios, lo cual permite a usuarios locales ejecutar código de su elección u obtener información sensible mediante los ficheros (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, o (9) k2adminstart; o (10) ciertos ficheros en lib/wsconfig/. • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=510 http://osvdb.org/34930 http://secunia.com/advisories/24850 http://www.adobe.com/support/security/bulletins/apsb07-08.html http://www.securityfocus.com/bid/23405 http://www.securitytracker.com/id?1017899 http://www.vupen.com/english/advisories/2007/1341 https://exchange.xforce.ibmcloud.com/vulnerabilities/33571 •

CVSS: 4.3EPSS: 4%CPEs: 4EXPL: 0

Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root. Vulnerabilidad no especificada en el conector IIS en Adobe JRun 4.0 Updater 6, y ColdFusion MX 6.1 y 7.0 Enterprise, cuando se utiliza Microsoft IIS 6, permite a atacantes remotos provocar denegación de servicio a través de vectores no especificados, afectando a la respuesta de un archivo en la raiz web JRun. • http://osvdb.org/34039 http://secunia.com/advisories/24488 http://www.adobe.com/support/security/bulletins/apsb07-07.html http://www.securityfocus.com/bid/22958 http://www.securitytracker.com/id?1017752 http://www.vupen.com/english/advisories/2007/0932 https://exchange.xforce.ibmcloud.com/vulnerabilities/32994 •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la consola de administración de Adobe JRun 4.0, como el usado en ColdFusion, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante vectores desconocidos. • http://osvdb.org/32122 http://secunia.com/advisories/24093 http://www.adobe.com/support/security/bulletins/apsb07-05.html http://www.securityfocus.com/bid/22547 http://www.securitytracker.com/id?1017646 http://www.securitytracker.com/id?1017647 http://www.vupen.com/english/advisories/2007/0594 https://exchange.xforce.ibmcloud.com/vulnerabilities/32475 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Adobe ColdFusion MX 7 7.0 y 7.0.1, cuando la Protección Global de Secuencias de Comandos no está habilitada, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante vectores no especificados, posiblemente relacionados con Linkdirect.cfm, Topnav.cfm, y Welcomedoc.cfm. • http://osvdb.org/32121 http://secunia.com/advisories/24115 http://www.adobe.com/support/security/bulletins/apsb07-03.html http://www.securityfocus.com/bid/22544 http://www.securitytracker.com/id?1017644 http://www.vupen.com/english/advisories/2007/0592 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 1%CPEs: 3EXPL: 1

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Adobe ColdFusion web server permite a atacantes remotos inyectar scripts web o HTML de su elección mediante la cabecera HTTP User-Agent, que no se ha saneado previamente a ser mostrada en una página de error. • https://www.exploit-db.com/exploits/29567 http://osvdb.org/32120 http://secunia.com/advisories/24115 http://www.adobe.com/support/security/bulletins/apsb07-04.html http://www.securityfocus.com/archive/1/459178/100/0/threaded http://www.securityfocus.com/bid/22401 http://www.securitytracker.com/id?1017645 http://www.vupen.com/english/advisories/2007/0593 •