Lucene search

K
exploitdbMacromediaEDB-ID:21548
HistoryJun 13, 2002 - 12:00 a.m.

ColdFusion MX - Missing Template Cross-Site Scripting

2002-06-1300:00:00
Macromedia
www.exploit-db.com
16

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/5011/info

ColdFusion MX is prone to cross site scripting attacks.

Attacker-supplied script code may be included in a malicious missing template URI generated by the default Missing Template handler of ColdFusion. The attacker-supplied script code will be executed in the browser of a web user who visits this link, in the security context of the host running ColdFusion. 

http://CF_MX_SERVER/<script>alert(document.cookie)</script>.cfm 

AI Score

7.4

Confidence

Low

Related for EDB-ID:21548