CVE-2006-4726
2.6
CVSS SCORE
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N
Description
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
High
Confidentiality
None
Integrity
P
Availability
None
Affected Software Configurations
- a adobe coldfusion 6.1 * * * * * * *
- a adobe coldfusion 7.0 * linux * * * * *
- a adobe coldfusion 7.0.1 * * * * * * *
Weaknesses (CWE)
- NVD-CWE-Other
References & External Links
- http://secunia.com/advisories/21858
- http://securitytracker.com/id?1016833
- http://www.adobe.com/support/security/bulletins/apsb06-14.html
- http://www.securityfocus.com/bid/19982
- http://www.vupen.com/english/advisories/2006/3575
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28922
- http://secunia.com/advisories/21858
- http://securitytracker.com/id?1016833
- http://www.adobe.com/support/security/bulletins/apsb06-14.html
- http://www.securityfocus.com/bid/19982
- http://www.vupen.com/english/advisories/2006/3575
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28922