Skip to content
Saturday, December 6, 2025
Medium Published: Feb 14, 2007 Modified: Apr 09, 2025

CVE-2006-5860

4.3 CVSS SCORE
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Share:

Description

Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVSS Vector Details

Attack Vector Network
Attack Complexity M
Confidentiality None
Integrity P
Availability None

Affected Software Configurations

  • a adobe coldfusion 6.1 * enterprise_server * * * * *
  • a adobe coldfusion 7.0 * enterprise_multi-server * * * * *
  • a adobe jrun 4.0 * * * * * * *
  • a adobe jrun 4.0 sp1 * * * * * *
  • a adobe jrun 4.0 sp1a * * * * * *
  • a adobe jrun 4.0_build_61650 * * * * * * *

Weaknesses (CWE)

  • CWE-79