CVE-2006-5859Cross-site Scripting in Adobe Coldfusion

Severity
4.3MEDIUMNVD
EPSS
2.4%
top 14.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDadobe/coldfusion7.0, 7.0.1+1

🔴Vulnerability Details

2
GHSA
GHSA-f654-xq37-47w4: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 72022-05-01
CVEList
CVE-2006-5859: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 72007-02-14
CVE-2006-5859 — Cross-site Scripting in Adobe | cvebase