Release DateMay 13, 2010 |
Severitymedium |
ImpactSystem compromiseInformation disclosure |
DescriptionThis indicates an attack attempt against a cross-site scripting vulnerability in Adobe ColdFusion.The vulnerability exists in the ColdFusion Administrator page. An attacker may exploit this to execute arbitrary code. |
Affected ProductsColdFusion 8.0, 8.0.1, 9.0 and earlier versions |
Recommended ActionsApply the patch supplied by the vendor:http://www.adobe.com/support/security/bulletins/apsb10-11.html |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2010-1293 |
Reference/shttp://www.adobe.com/support/security/bulletins/apsb10-11.html |