Vulnerabilities > CVE-2006-6483 - Unspecified vulnerability in Adobe Coldfusion 7.0/7.0.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN adobe
nessus
Summary
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | CGI abuses : XSS |
NASL id | COLDFUSION_XSS_PROTECTION_BYPASS.NASL |
description | The version of Adobe ColdFusion running on the remote host is affected by a cross-site scripting vulnerability due to a failure to completely sanitize user-supplied input before using it to generate dynamic content. A remote, unauthenticated attacker can leverage this issue to inject arbitrary HTML or script code into a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24279 |
published | 2007-02-06 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24279 |
title | ColdFusion MX Null Byte Tag XSS Protection Bypass |
code |
|
References
- http://secunia.com/advisories/23281
- http://secunia.com/advisories/23281
- http://securityreason.com/securityalert/2021
- http://securityreason.com/securityalert/2021
- http://securitytracker.com/id?1017361
- http://securitytracker.com/id?1017361
- http://www.adobe.com/support/security/bulletins/apsb07-06.html
- http://www.adobe.com/support/security/bulletins/apsb07-06.html
- http://www.securityfocus.com/archive/1/454046/100/0/threaded
- http://www.securityfocus.com/archive/1/454046/100/0/threaded
- http://www.securityfocus.com/bid/21532
- http://www.securityfocus.com/bid/21532
- http://www.vupen.com/english/advisories/2006/4949
- http://www.vupen.com/english/advisories/2006/4949
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30841
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30841