CVE-2007-0817
4.3
CVSS SCORE
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Description
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
P
Availability
None
Affected Software Configurations
- a adobe coldfusion 6.1 * * * * * * *
- a adobe coldfusion 7.0.1 * * * * * * *
- a adobe coldfusion 7.0.2 * * * * * * *
Weaknesses (CWE)
- NVD-CWE-Other
References & External Links
- http://osvdb.org/32120
- http://secunia.com/advisories/24115
- http://www.adobe.com/support/security/bulletins/apsb07-04.html
- http://www.securityfocus.com/archive/1/459178/100/0/threaded
- http://www.securityfocus.com/bid/22401
- http://www.securitytracker.com/id?1017645
- http://www.vupen.com/english/advisories/2007/0593
- http://osvdb.org/32120
- http://secunia.com/advisories/24115
- http://www.adobe.com/support/security/bulletins/apsb07-04.html
- http://www.securityfocus.com/archive/1/459178/100/0/threaded
- http://www.securityfocus.com/bid/22401
- http://www.securitytracker.com/id?1017645
- http://www.vupen.com/english/advisories/2007/0593