Vulnerabilities > CVE-2005-2480 - Cross-Site Scripting vulnerability in Macromedia Coldfusion Fusebox 4.1.0
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses : XSS |
NASL id | FUSEBOX_FUSEACTION_XSS.NASL |
description | The remote host is running Fusebox, a framework for building web-based applications in Cold Fusion and PHP. The installed web application appears to have been created using Fusebox in such a way that it fails to sanitize user-supplied input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19383 |
published | 2005-08-04 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19383 |
title | Fusebox index.cfm fuseaction Parameter XSS |