Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:XSS:COLDFUSION-MX7

Severity

Medium

Recommended

No

Category

HTTP

Keywords

ColdFusion MX7 XSS

Release Date

2007/02/01

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: ColdFusion MX7 XSS


This signature detects attempts to exploit a known vulnerability against ColdFusion MX7. A successful attack can lead to cross-site scripting inside of the client Web browser.

Extended Description

Adobe ColdFusion is prone to multiple input-validation vulnerabilities, including two information-disclosure issues and one cross-site scripting issue. An attacker can exploit these issues to gain sensitive information, including cookie-based authentication credentials, which can aid in further attacks. Adobe ColdFusion MX7 is vulnerable; MX6 may also be affected.

Affected Products

  • Adobe ColdFusion MX 7.00
  • Adobe ColdFusion MX 7.01
  • Adobe ColdFusion MX 7.02

References

  • BugTraq: 21532
  • CVE: CVE-2006-6483
  • URL: http://www.frsirt.com/english/advisories/2006/4949

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out