Description
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header in an id=- query to a .cfm file.
References
CVSS impact metrics
AV:N/AC:M/Au:N/C:N/I:P/A:N
4.3 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2011-02-01T18:00:03.843
14 years agoLast modified
2011-11-08T04:18:45.200
13 years ago