Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2007-0817
StatusCandidate
DescriptionCross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.
SeverityLow
CVSS score1,9
CVSS vector(AV:R/AC:H/Au:NR/C:N/I:P/A:N/B:N)
PhaseAssigned (07.02.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0817
ReferencesBID : 22401
 BUGTRAQ : 20070205 Cold Fusion Web Server XSS 0 day
 CONFIRM : http://www.adobe.com/support/security/bulletins/ap...
 FRSIRT : ADV-2007-0593
 SECTRACK : 1017645
 SECUNIA : 24115
SecurityVulns:ColdFusion crossite scripting

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server