CVE-2009-1872
medium · 4.3A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
4.3
CVSS
16.1%
EPSS (exploit prob.)
97th
EPSS percentile
2009-08-18
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | coldfusion | <= 8.0.1 |
| adobe | coldfusion | 6.0 |
| adobe | coldfusion | 6.0 |
| adobe | coldfusion | 6.0 |
| adobe | coldfusion | 6.0 |
| adobe | coldfusion | 6.0 |
| adobe | coldfusion | 6.1 |
| adobe | coldfusion | 6.1 |
| adobe | coldfusion | 6.1 |
| adobe | coldfusion | 6.1 |
| adobe | coldfusion | 6.1 |
| adobe | coldfusion | 7.0 |
| adobe | coldfusion | 7.0 |
| adobe | coldfusion | 7.0 |
| adobe | coldfusion | 7.0 |
| adobe | coldfusion | 7.0 |
| adobe | coldfusion | 7.0.1 |
| adobe | coldfusion | 7.0.2 |
| adobe | coldfusion | 7.2 |
| adobe | coldfusion | 8.0 |
| adobe | coldfusion | 8.1 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/57182
- http://osvdb.org/57183
- http://osvdb.org/57184
- http://osvdb.org/57185
- http://www.adobe.com/support/security/bulletins/apsb09-12.html
- http://www.dsecrg.com/pages/vul/show.php?id=122
- http://www.securityfocus.com/archive/1/505803/100/0/threaded
- http://osvdb.org/57182
- http://osvdb.org/57183
- http://osvdb.org/57184
- http://osvdb.org/57185
- http://www.adobe.com/support/security/bulletins/apsb09-12.html
- http://www.dsecrg.com/pages/vul/show.php?id=122
- http://www.securityfocus.com/archive/1/505803/100/0/threaded
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-1872