CVE-2006-5860

Severity
4.3MEDIUM
EPSS
2.0%
top 16.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDadobe/jrun4.0, 4.0_build_61650+1
NVDadobe/coldfusion6.1, 7.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mcgv-65qf-5x7r: Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 42022-05-01
CVEList
CVE-2006-5860: Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 42007-02-14
CVE-2006-5860 (MEDIUM CVSS 4.3) | Cross-site scripting (XSS) vulnerab | cvebase.io