Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-12-12 12:28
Updated : 2018-10-17 14:48
NVD link : CVE-2006-6483
Mitre link : CVE-2006-6483
JSON object : View
CWE
Products Affected
adobe
- coldfusion