VID |
22441 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
WWW |
Detailed Description |
The Adobe Macromedia ColdFusion software is vulnerable to a Cross-Site Scripting Protection Bypass vulnerability. Adobe ColdFusion MX versions 7.x prior to 7.0.2 are vulnerable to a cross-site scripting vulnerability, caused by an input validation error in the cross-site scripting protection module that does not filter hex-encoded null characters (%00). By creating a specially-crafted Web page containing a hexadecimal encoded NULL byte character (%00) in an HTML tag, a remote attacker could exploit this vulnerability to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
* References: http://www.adobe.com/support/security/bulletins/apsb07-06.html http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0203.html http://www.frsirt.com/english/advisories/2006/4949 http://securitytracker.com/alerts/2006/Dec/1017361.html http://secunia.com/advisories/23281
* Platforms Affected: Adobe Systems Incorporated, ColdFusion MX versions 7.x prior to 7.0.2 Any operating system Any version |
Recommendation |
Update to the latest version of ColdFusion MX 7.X (7.0.2 or later) or apply a patch for ColdFusion MX 7.X, as listed in Adobe Security bulletin APSB07-06 at http://www.adobe.com/support/security/bulletins/apsb07-06.html |
Related URL |
CVE-2006-6483 (CVE) |
Related URL |
21532 (SecurityFocus) |
Related URL |
30841 (ISS) |
|