Korean
<< Back
VID 22441
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The Adobe Macromedia ColdFusion software is vulnerable to a Cross-Site Scripting Protection Bypass vulnerability. Adobe ColdFusion MX versions 7.x prior to 7.0.2 are vulnerable to a cross-site scripting vulnerability, caused by an input validation error in the cross-site scripting protection module that does not filter hex-encoded null characters (%00). By creating a specially-crafted Web page containing a hexadecimal encoded NULL byte character (%00) in an HTML tag, a remote attacker could exploit this vulnerability to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.

* References:
http://www.adobe.com/support/security/bulletins/apsb07-06.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0203.html
http://www.frsirt.com/english/advisories/2006/4949
http://securitytracker.com/alerts/2006/Dec/1017361.html
http://secunia.com/advisories/23281

* Platforms Affected:
Adobe Systems Incorporated, ColdFusion MX versions 7.x prior to 7.0.2
Any operating system Any version
Recommendation Update to the latest version of ColdFusion MX 7.X (7.0.2 or later) or apply a patch for ColdFusion MX 7.X, as listed in Adobe Security bulletin APSB07-06 at http://www.adobe.com/support/security/bulletins/apsb07-06.html
Related URL CVE-2006-6483 (CVE)
Related URL 21532 (SecurityFocus)
Related URL 30841 (ISS)