PT-2005-2534 · Adobe · Coldfusion Mx
Published
2005-05-10
·
Updated
2017-07-11
·
CVE-2005-1555
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ColdFusion MX version 7.0
Description
A cross-site scripting issue exists due to improper quoting of the URL in the default 404 error page, allowing remote attackers to inject arbitrary script or HTML.
Recommendations
For ColdFusion MX version 7.0, ensure that URLs are properly quoted in the resulting default 404 error page to prevent arbitrary script or HTML injection.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coldfusion Mx