Vulnerabilities > Adobe > Coldfusion > 8.1

DATE CVE VULNERABILITY TITLE RISK
2011-02-01 CVE-2011-0735 Cross-Site Scripting vulnerability in Adobe Coldfusion
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script."
network
adobe CWE-79
4.3
2011-02-01 CVE-2011-0734 Cross-Site Scripting vulnerability in Adobe Coldfusion
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack.
network
adobe CWE-79
4.3
2009-08-18 CVE-2009-1878 Improper Authentication vulnerability in Adobe Coldfusion
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
network
adobe CWE-287
5.8
2009-08-18 CVE-2009-1877 Cross-Site Scripting vulnerability in Adobe Coldfusion
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.
network
adobe CWE-79
4.3
2009-08-18 CVE-2009-1875 Cross-Site Scripting vulnerability in Adobe Coldfusion
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1877.
network
adobe CWE-79
4.3
2009-08-18 CVE-2009-1872 Cross-Site Scripting vulnerability in Adobe Coldfusion
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
network
adobe CWE-79
4.3
2008-04-09 CVE-2008-1656 Permissions, Privileges, and Access Controls vulnerability in Adobe Coldfusion 8.0/8.1
Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these methods via Flex 2 remoting, a different vulnerability than CVE-2006-4725.
network
low complexity
adobe CWE-264
7.5